# How to Set Up TLS/SSL for the ComfyUI Server: A Complete Guide

> Secure your ComfyUI server with TLS/SSL. This guide shows how to enable HTTPS by specifying keyfile and certfile arguments for encrypted connections. Learn essential steps easily.

- Repository: [Comfy Org/ComfyUI](https://github.com/Comfy-Org/ComfyUI)
- Tags: how-to-guide
- Published: 2026-02-26

---

**TLDR:** Launch ComfyUI with both `--tls-keyfile` and `--tls-certfile` arguments to enable HTTPS; the server creates an `ssl.SSLContext` using `ssl.PROTOCOL_TLS_SERVER` and binds the encrypted listener via `web.TCPSite`.

ComfyUI, the open-source node-based interface for Stable Diffusion, includes built-in TLS/SSL support through its **aiohttp** web server. According to the Comfy-Org/ComfyUI source code, you can encrypt traffic to the GUI and API endpoints by supplying certificate files via command-line arguments—no reverse proxy required for basic HTTPS operation.

## How ComfyUI Implements TLS/SSL

The TLS implementation resides in two critical files. First, argument definitions live in [`comfy/cli_args.py`](https://github.com/Comfy-Org/ComfyUI/blob/main/comfy/cli_args.py) (lines 40‑42), which registers `--tls-keyfile` and `--tls-certfile` as optional CLI flags. Second, the SSL context construction happens in [`server.py`](https://github.com/Comfy-Org/ComfyUI/blob/main/server.py) (lines 1191‑1197).

When both arguments are present, the server executes the following logic:

1. Creates an **`ssl.SSLContext`** using `ssl.PROTOCOL_TLS_SERVER`
2. Loads the certificate chain from `--tls-certfile` and the private key from `--tls-keyfile`
3. Sets verification mode to **`ssl.CERT_NONE`** (server authenticates to clients, but client certificates are not required)
4. Passes the context to `web.TCPSite` when binding the HTTP listener

If either TLS argument is omitted, the server defaults to plain HTTP on the specified port.

## Prerequisites for Enabling HTTPS

Before launching ComfyUI with encryption, ensure you have:

- A valid **PEM-encoded private key** file (`.key` or `.pem`)
- A matching **PEM-encoded certificate** file (`.crt` or `.pem`), which may include intermediate CA certificates concatenated at the end
- OpenSSL installed (for generating self-signed certificates during testing)

## Step-by-Step TLS Setup

### Generate Self-Signed Certificates (Local Testing)

For development or LAN access without a public domain, create a self-signed certificate pair:

```bash
openssl req -newkey rsa:2048 -nodes -keyout comfyui.key \
    -x509 -days 365 -out comfyui.crt -subj "/CN=localhost"

```

- `comfyui.key` — your private key
- `comfyui.crt` — your self-signed certificate

Browsers will display a security warning for these certificates; accept the exception for local testing only.

### Launch ComfyUI with TLS Arguments

Run the server with absolute paths to your key and certificate files:

```bash
python main.py \
    --listen 0.0.0.0 \
    --port 8188 \
    --tls-keyfile /full/path/to/comfyui.key \
    --tls-certfile /full/path/to/comfyui.crt

```

The console will indicate the secure endpoint:

```

Starting server
To see the GUI go to: https://[::]:8188

```

Navigate to `https://<your-host>:8188`. The connection is now encrypted, though self-signed certificates will trigger browser warnings until you add a security exception.

### Deploy with Trusted Certificates (Production)

For public-facing instances, replace the self-signed files with certificates issued by a trusted Certificate Authority (Let’s Encrypt, corporate PKI, or commercial CA). The command remains identical:

```bash
python main.py \
    --tls-keyfile /etc/letsencrypt/live/yourdomain.com/privkey.pem \
    --tls-certfile /etc/letsencrypt/live/yourdomain.com/fullchain.pem

```

Because the context uses `ssl.PROTOCOL_TLS_SERVER`, the server negotiates the highest TLS version supported by both client and server (typically TLS 1.2 or TLS 1.3).

## Alternative: Reverse Proxy TLS Termination

If you require advanced TLS features—such as **OCSP stapling**, **client certificate authentication**, or **HTTP Strict Transport Security (HSTS)**—terminate TLS at a reverse proxy instead of using ComfyUI’s built-in support.

Run ComfyUI on localhost without TLS:

```bash
python main.py --listen 127.0.0.1 --port 8188

```

Then configure Nginx to handle HTTPS:

```nginx
server {
    listen 443 ssl;
    server_name yourdomain.com;

    ssl_certificate /etc/ssl/certs/comfyui.crt;
    ssl_certificate_key /etc/ssl/private/comfyui.key;
    ssl_protocols TLSv1.2 TLSv1.3;

    location / {
        proxy_pass http://127.0.0.1:8188;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

```

This approach keeps the Python process unprivileged while the proxy manages cipher suites, certificate rotation, and security headers.

## Summary

- **Core mechanism**: ComfyUI’s [`server.py`](https://github.com/Comfy-Org/ComfyUI/blob/main/server.py) constructs an `ssl.SSLContext` when both `--tls-keyfile` and `--tls-certfile` are provided, attaching it to the aiohttp `web.TCPSite` listener.
- **File locations**: Argument parsing occurs in [`comfy/cli_args.py`](https://github.com/Comfy-Org/ComfyUI/blob/main/comfy/cli_args.py) (lines 40‑42); SSL context creation occurs in [`server.py`](https://github.com/Comfy-Org/ComfyUI/blob/main/server.py) (lines 1191‑1197).
- **Verification mode**: The server uses `ssl.CERT_NONE`, meaning it presents its certificate to clients but does not validate client certificates.
- **Flexibility**: Works with self-signed certificates for testing and CA-signed certificates for production, or can be disabled entirely when using a reverse proxy.

## Frequently Asked Questions

### Does ComfyUI support mutual TLS (mTLS) authentication?

No. As implemented in [`server.py`](https://github.com/Comfy-Org/ComfyUI/blob/main/server.py), the SSL context sets `ssl.CERT_NONE`, which disables client certificate verification. The server authenticates itself to clients but does not require clients to present certificates. For mTLS, you must terminate TLS at a reverse proxy (such as Nginx or Traefik) that supports client certificate validation.

### Which TLS protocol versions does ComfyUI support?

ComfyUI uses Python’s `ssl.PROTOCOL_TLS_SERVER`, which automatically negotiates the highest protocol version available (TLS 1.2 or TLS 1.3) based on the Python version and OpenSSL library linked to the interpreter. You do not need to manually specify protocol versions in the ComfyUI configuration.

### Can I use Let's Encrypt certificates with ComfyUI directly?

Yes. As long as the files are PEM-encoded and readable by the ComfyUI process, you can point `--tls-keyfile` to the private key (e.g., `privkey.pem`) and `--tls-certfile` to the full chain (e.g., `fullchain.pem`). Ensure the certificate files are renewed before expiration, as ComfyUI does not support hot-reloading of TLS certificates while running.

### Why does my browser show a "Not Secure" warning even with TLS enabled?

This occurs when using self-signed certificates or certificates issued by a private CA that your system does not trust. Because `ssl.CERT_NONE` only affects server-side verification (not client-side trust stores), you must either add your private CA to the client’s trust store, use a publicly trusted CA like Let’s Encrypt, or accept the browser warning for local development environments only.