▄▄ ▄▄ ▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄ ▄▄▄▄ ▄▄▄▄▄ ▄▄▄▄▄▄▄▄ ▄▄ ▄▄ ██ ██ ▀▀▀██▀▀▀ ▀▀▀██▀▀▀ ██▀▀▀▀█▄ ▄█▀▀▀▀█ ██▀▀▀██ ██▀▀▀▀▀▀ ▀██ ██▀ ██ ██ ██ ██ ██ ██ ██▄ ██ ██ ██ ██ ██ ████████ ██ ██ ██████▀ ▀████▄ ██ ██ ███████ ██ ██ ██ ██ ██ ██ ██ ▀██ ██ ██ ██ ████ ██ ██ ██ ██ ██ █▄▄▄▄▄█▀ ██▄▄▄██ ██▄▄▄▄▄▄ ████ ▀▀ ▀▀ ▀▀ ▀▀ ▀▀ ▀▀▀▀▀ ▀▀▀▀▀ ▀▀▀▀▀▀▀▀ ▀▀▀▀
Localhost with a
working padlock.
Point it at a port. Get a green padlock.
Every framework has its own broken HTTPS story. Some ship self-signed certs that trip the browser. Some hide it behind an HTTPS=true env var. Some just don't.httpsdev sits in front of any dev server and gives it a real, browser-trusted cert.
Vite, Next, Rails, Django, plain HTTP — if it speaks HTTP, this wraps it. WebSockets and SSE pass through untouched. HMR keeps working. No plugins, no configs, no --insecure.
Install
go install github.com/ArpitRajputGithub/httpsdev@latestNeeds mkcert once — brew install mkcert && mkcert -install. That's the only setup.
mkcert · valid 30d
The pitch, in four lines.
No self-signed drama
Certs come from mkcert — the same local CA Chrome and Safari already trust. Zero warnings. Zero “Advanced → Proceed anyway” clicking.
No framework-specific config
No --https flag to remember. No HTTPS=true env var. No experimental Next config. Point at a port and go.
HMR still works
WebSocket upgrades and SSE forward untouched. Your Vite HMR, Next dev overlay, Rails Turbo streams — everything keeps working.
One binary, no runtime
10 MB static Go binary. No node_modules. No Python venv. No Docker. go install and you're done.
Two commands, then you're done.
Once, ever: get mkcert and trust its local CA.
brew install mkcert mkcert -installGrab httpsdev.
go install github.com/ArpitRajputGithub/httpsdev@latestOr grab a prebuilt binary fromreleases.
Point it at a port. Open the browser.
# in one terminal npm run dev # or vite, next dev, rails s, python -m http.server 5173, … # in another httpsdev 5173 # https://localhost:3443 → http://localhost:5173