How to Set Up TLS/SSL for the ComfyUI Server: A Complete Guide
TLDR: Launch ComfyUI with both --tls-keyfile and --tls-certfile arguments to enable HTTPS; the server creates an ssl.SSLContext using ssl.PROTOCOL_TLS_SERVER and binds the encrypted listener via web.TCPSite.
ComfyUI, the open-source node-based interface for Stable Diffusion, includes built-in TLS/SSL support through its aiohttp web server. According to the Comfy-Org/ComfyUI source code, you can encrypt traffic to the GUI and API endpoints by supplying certificate files via command-line arguments—no reverse proxy required for basic HTTPS operation.
How ComfyUI Implements TLS/SSL
The TLS implementation resides in two critical files. First, argument definitions live in comfy/cli_args.py (lines 40‑42), which registers --tls-keyfile and --tls-certfile as optional CLI flags. Second, the SSL context construction happens in server.py (lines 1191‑1197).
When both arguments are present, the server executes the following logic:
- Creates an
ssl.SSLContextusingssl.PROTOCOL_TLS_SERVER - Loads the certificate chain from
--tls-certfileand the private key from--tls-keyfile - Sets verification mode to
ssl.CERT_NONE(server authenticates to clients, but client certificates are not required) - Passes the context to
web.TCPSitewhen binding the HTTP listener
If either TLS argument is omitted, the server defaults to plain HTTP on the specified port.
Prerequisites for Enabling HTTPS
Before launching ComfyUI with encryption, ensure you have:
- A valid PEM-encoded private key file (
.keyor.pem) - A matching PEM-encoded certificate file (
.crtor.pem), which may include intermediate CA certificates concatenated at the end - OpenSSL installed (for generating self-signed certificates during testing)
Step-by-Step TLS Setup
Generate Self-Signed Certificates (Local Testing)
For development or LAN access without a public domain, create a self-signed certificate pair:
openssl req -newkey rsa:2048 -nodes -keyout comfyui.key \
-x509 -days 365 -out comfyui.crt -subj "/CN=localhost"
comfyui.key— your private keycomfyui.crt— your self-signed certificate
Browsers will display a security warning for these certificates; accept the exception for local testing only.
Launch ComfyUI with TLS Arguments
Run the server with absolute paths to your key and certificate files:
python main.py \
--listen 0.0.0.0 \
--port 8188 \
--tls-keyfile /full/path/to/comfyui.key \
--tls-certfile /full/path/to/comfyui.crt
The console will indicate the secure endpoint:
Starting server
To see the GUI go to: https://[::]:8188
Navigate to https://<your-host>:8188. The connection is now encrypted, though self-signed certificates will trigger browser warnings until you add a security exception.
Deploy with Trusted Certificates (Production)
For public-facing instances, replace the self-signed files with certificates issued by a trusted Certificate Authority (Let’s Encrypt, corporate PKI, or commercial CA). The command remains identical:
python main.py \
--tls-keyfile /etc/letsencrypt/live/yourdomain.com/privkey.pem \
--tls-certfile /etc/letsencrypt/live/yourdomain.com/fullchain.pem
Because the context uses ssl.PROTOCOL_TLS_SERVER, the server negotiates the highest TLS version supported by both client and server (typically TLS 1.2 or TLS 1.3).
Alternative: Reverse Proxy TLS Termination
If you require advanced TLS features—such as OCSP stapling, client certificate authentication, or HTTP Strict Transport Security (HSTS)—terminate TLS at a reverse proxy instead of using ComfyUI’s built-in support.
Run ComfyUI on localhost without TLS:
python main.py --listen 127.0.0.1 --port 8188
Then configure Nginx to handle HTTPS:
server {
listen 443 ssl;
server_name yourdomain.com;
ssl_certificate /etc/ssl/certs/comfyui.crt;
ssl_certificate_key /etc/ssl/private/comfyui.key;
ssl_protocols TLSv1.2 TLSv1.3;
location / {
proxy_pass http://127.0.0.1:8188;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
This approach keeps the Python process unprivileged while the proxy manages cipher suites, certificate rotation, and security headers.
Summary
- Core mechanism: ComfyUI’s
server.pyconstructs anssl.SSLContextwhen both--tls-keyfileand--tls-certfileare provided, attaching it to the aiohttpweb.TCPSitelistener. - File locations: Argument parsing occurs in
comfy/cli_args.py(lines 40‑42); SSL context creation occurs inserver.py(lines 1191‑1197). - Verification mode: The server uses
ssl.CERT_NONE, meaning it presents its certificate to clients but does not validate client certificates. - Flexibility: Works with self-signed certificates for testing and CA-signed certificates for production, or can be disabled entirely when using a reverse proxy.
Frequently Asked Questions
Does ComfyUI support mutual TLS (mTLS) authentication?
No. As implemented in server.py, the SSL context sets ssl.CERT_NONE, which disables client certificate verification. The server authenticates itself to clients but does not require clients to present certificates. For mTLS, you must terminate TLS at a reverse proxy (such as Nginx or Traefik) that supports client certificate validation.
Which TLS protocol versions does ComfyUI support?
ComfyUI uses Python’s ssl.PROTOCOL_TLS_SERVER, which automatically negotiates the highest protocol version available (TLS 1.2 or TLS 1.3) based on the Python version and OpenSSL library linked to the interpreter. You do not need to manually specify protocol versions in the ComfyUI configuration.
Can I use Let's Encrypt certificates with ComfyUI directly?
Yes. As long as the files are PEM-encoded and readable by the ComfyUI process, you can point --tls-keyfile to the private key (e.g., privkey.pem) and --tls-certfile to the full chain (e.g., fullchain.pem). Ensure the certificate files are renewed before expiration, as ComfyUI does not support hot-reloading of TLS certificates while running.
Why does my browser show a "Not Secure" warning even with TLS enabled?
This occurs when using self-signed certificates or certificates issued by a private CA that your system does not trust. Because ssl.CERT_NONE only affects server-side verification (not client-side trust stores), you must either add your private CA to the client’s trust store, use a publicly trusted CA like Let’s Encrypt, or accept the browser warning for local development environments only.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →