certifi
Python package for providing Mozilla's CA Bundle.
Decision gist · record as of 2026-08-14
Yes. Certifi is a foundational, zero-friction dependency for any Python application making HTTPS connections. It is actively maintained, carries no security vulnerabilities, has no runtime dependencies, and is already a transitive dependency of most popular HTTP libraries. Installing it explicitly ensures you have explicit control over certificate validation behavior.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low install friction with no runtime dependencies.
- Actively maintained with a recent release (23 days old) and steady upstream updates to the CA bundle.
License · maintenance · safety
MPL-2.0 (copyleft) — Licensed under MPL-2.0 (copyleft). You may use and modify the package freely, but any modifications must be distributed under the same license if you redistribute the modified version.
last release 2026-07-22 (23 days) · last repo commit 2026-08-03 · 988 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,861,401,883 downloads/mo, #4 on PyPI
Alternatives
Verify before relying
pip install certifi
import certifi
ca_bundle_path = certifi.where()
print(ca_bundle_path)- Whether the bundled CA certificates are automatically updated on the system or require manual package updates to stay current.
What it is and what it does
Certifi is a Python package that bundles Mozilla's carefully maintained collection of root SSL certificates. It solves the problem of providing a reliable, portable certificate store for Python applications to use when validating TLS connections, eliminating the need to rely on system-specific certificate locations that may vary across operating systems and deployments.
The package exposes a simple API: calling `certifi.where()` returns the filesystem path to the bundled CA certificate bundle (cacert.pem), which can then be passed to any HTTP client or TLS library that needs to verify server certificates. It has no runtime dependencies and supports Python 3.7 through 3.14, making it a foundational dependency for most Python projects that make HTTPS requests.
Use it for
- Provide a consistent CA bundle path to requests or urllib3 for HTTPS connections across different operating systems.
- Configure SSL certificate verification in web scraping or API client libraries that need a reliable root certificate store.
- Ensure Docker containers and cloud deployments have a portable, version-controlled certificate authority bundle.
- Validate TLS certificates in custom networking code without depending on system certificate locations.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Certifi is a foundational, zero-friction dependency for any Python application making HTTPS connections. It is actively maintained, carries no security vulnerabilities, has no runtime dependencies, and is already a transitive dependency of most popular HTTP libraries. Installing it explicitly ensures you have explicit control over certificate validation behavior.
Install
certifi on PyPI
Before you install
Low install friction with no runtime dependencies. Actively maintained with a recent release (23 days old) and steady upstream updates to the CA bundle.
License in practice
Licensed under MPL-2.0 (copyleft). You may use and modify the package freely, but any modifications must be distributed under the same license if you redistribute the modified version.
Quickstart
pip install certifi
import certifi
ca_bundle_path = certifi.where()
print(ca_bundle_path)
Verify before relying
- Whether the bundled CA certificates are automatically updated on the system or require manual package updates to stay current.
Package facts
| License | MPL-2.0 copyleft |
| Python support | Supports the current Python release >=3.7 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 23 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 1,861,401,883 / month, #4 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: Mozilla Public License 2.0 (MPL 2.0)Natural Language :: EnglishProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: certifi-2026.7.22-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “tls certificate authority”
- certifiCertifi provides Mozilla's curated collection of root SSL…
- trustmetrustme generates fake TLS certificates and certificate authorities…
- secure-smtplibProvides secure SMTP subclasses with TLS/SSL certificate validation…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
Keyring provides safe password and credential storage by interfacing with the system's native credential manager (macOS Keychain, Windows Credential Locker, Freedesktop Secret Service, or KDE KWallet).
Install it if your application needs to store or retrieve passwords securely without managing encryption yourself.
See also aia · django-sslserver · mscerts · secure-smtplib · certipy · wassima · certifi-linux · trustme · python-certifi-win32 · wincertstore