trustme
#1 quality TLS certs while you wait, for the discerning tester
Decision gist · record as of 2026-08-14
Yes. trustme is a focused, well-maintained tool for a common testing need: validating TLS code without real certificates. Low install friction, permissive license, no known vulnerabilities, and active maintenance make it a safe choice for test suites. Install it if you test any code that makes HTTPS connections.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later.
- Low install friction: pure Python wheel with only two runtime dependencies (cryptography and idna).
- Actively maintained with a recent release on 2025-01-02 and ongoing repository activity.
License · maintenance · safety
MIT OR Apache-2.0 (permissive) — Dual-licensed under MIT or Apache 2.0 (your choice), both permissive. You can use this freely in commercial or proprietary projects with minimal restrictions.
last release 2025-01-02 (589 days) · last repo commit 2026-08-05 · 604 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,063,092 downloads/mo, #4,419 on PyPI
Alternatives
Verify before relying
pip install trustme
import trustme
ca = trustme.CA()
server_cert = ca.issue_cert("test-host.example.org")
ca.configure_trust(ssl_context)
server_cert.configure_cert(ssl_context)- Whether the package works with both standard library ssl and PyOpenSSL contexts as claimed in the description.
- Performance characteristics when generating many certificates in a single test suite.
- Exact certificate format and standards compliance of generated certificates.
What it is and what it does
trustme is a lightweight Python package that creates fake certificate authorities and issues TLS certificates signed by them, specifically for testing network code. Instead of disabling certificate validation in tests (which masks production bugs), you use trustme to generate realistic test certificates that your test suite can trust, letting you validate the full TLS handshake without real certificates.
The package works both programmatically (creating CA and cert objects in Python) and from the command line (generating PEM files for use in non-Python test suites). It depends on cryptography for the underlying certificate operations and idna for domain name handling. The generated certificates are real certificates, just signed by your test CA rather than a trusted root authority.
Use it for
- Test a Python web client or server that makes HTTPS connections without disabling certificate validation.
- Generate test certificates for use in non-Python test suites (e.g., shell scripts, Docker containers) via command-line or PEM files.
- Validate that your application correctly handles certificate chains and trust validation logic.
- Create temporary certificate files for libraries that require cert paths rather than SSL context objects.
- Test TLS error handling by issuing certs for different hostnames than the server is configured for.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
trustme is a focused, well-maintained tool for a common testing need: validating TLS code without real certificates. Low install friction, permissive license, no known vulnerabilities, and active maintenance make it a safe choice for test suites. Install it if you test any code that makes HTTPS connections.
Install
trustme on PyPI
Before you install
Low install friction: pure Python wheel with only two runtime dependencies (cryptography and idna). Actively maintained with a recent release on 2025-01-02 and ongoing repository activity.
Requires Python 3.9 or later.
License in practice
Dual-licensed under MIT or Apache 2.0 (your choice), both permissive. You can use this freely in commercial or proprietary projects with minimal restrictions.
Quickstart
pip install trustme
import trustme
ca = trustme.CA()
server_cert = ca.issue_cert("test-host.example.org")
ca.configure_trust(ssl_context)
server_cert.configure_cert(ssl_context)
Verify before relying
- Whether the package works with both standard library ssl and PyOpenSSL contexts as claimed in the description.
- Performance characteristics when generating many certificates in a single test suite.
- Exact certificate format and standards compliance of generated certificates.
Package facts
| License | MIT OR Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagescryptographyidna |
| Maintenance | Actively maintained 589 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 1,063,092 / month, #4,419 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseLicense :: OSI Approved :: MIT LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Security :: CryptographyTopic :: Software Development :: TestingTopic :: System :: Networking |
Evidence: trustme-1.2.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “test TLS certificates”
- trustmetrustme generates fake TLS certificates and certificate authorities…
- pulumi-tlsPulumi resource provider for creating and managing TLS keys and…
- certifiCertifi provides Mozilla's curated collection of root SSL…
Give your agent the search over MCP, or paste the wish link into any chat.
More Testing packages
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
virtualenv creates isolated Python environments where packages can be installed independently without affecting the system Python or other projects.
Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.
Install it if you want to measure test completeness or enforce coverage thresholds in your project.
pytest-asyncio is a pytest plugin that enables writing and running async test functions using the asyncio library, allowing developers to await code directly within test cases.
Install it if you write tests for any asyncio-based code.
A pytest plugin that generates test reports in Common Test Report Format (CTRF) as JSON, compatible with pytest-xdist and pytest-playwright for distributed and browser-based testing.
Install it if you need CTRF-formatted test output for CI/CD integration or cross-tool reporting.
See also certifi-linux · certipy · django-sslserver · certifi · wincertstore · python-certifi-win32 · pem · acme · secure-smtplib · stcrestclient