How to Set Up TLS/SSL for the ComfyUI Server: A Complete Guide

TLDR: Launch ComfyUI with both --tls-keyfile and --tls-certfile arguments to enable HTTPS; the server creates an ssl.SSLContext using ssl.PROTOCOL_TLS_SERVER and binds the encrypted listener via web.TCPSite.

ComfyUI, the open-source node-based interface for Stable Diffusion, includes built-in TLS/SSL support through its aiohttp web server. According to the Comfy-Org/ComfyUI source code, you can encrypt traffic to the GUI and API endpoints by supplying certificate files via command-line arguments—no reverse proxy required for basic HTTPS operation.

How ComfyUI Implements TLS/SSL

The TLS implementation resides in two critical files. First, argument definitions live in comfy/cli_args.py (lines 40‑42), which registers --tls-keyfile and --tls-certfile as optional CLI flags. Second, the SSL context construction happens in server.py (lines 1191‑1197).

When both arguments are present, the server executes the following logic:

  1. Creates an ssl.SSLContext using ssl.PROTOCOL_TLS_SERVER
  2. Loads the certificate chain from --tls-certfile and the private key from --tls-keyfile
  3. Sets verification mode to ssl.CERT_NONE (server authenticates to clients, but client certificates are not required)
  4. Passes the context to web.TCPSite when binding the HTTP listener

If either TLS argument is omitted, the server defaults to plain HTTP on the specified port.

Prerequisites for Enabling HTTPS

Before launching ComfyUI with encryption, ensure you have:

  • A valid PEM-encoded private key file (.key or .pem)
  • A matching PEM-encoded certificate file (.crt or .pem), which may include intermediate CA certificates concatenated at the end
  • OpenSSL installed (for generating self-signed certificates during testing)

Step-by-Step TLS Setup

Generate Self-Signed Certificates (Local Testing)

For development or LAN access without a public domain, create a self-signed certificate pair:

openssl req -newkey rsa:2048 -nodes -keyout comfyui.key \
    -x509 -days 365 -out comfyui.crt -subj "/CN=localhost"
  • comfyui.key — your private key
  • comfyui.crt — your self-signed certificate

Browsers will display a security warning for these certificates; accept the exception for local testing only.

Launch ComfyUI with TLS Arguments

Run the server with absolute paths to your key and certificate files:

python main.py \
    --listen 0.0.0.0 \
    --port 8188 \
    --tls-keyfile /full/path/to/comfyui.key \
    --tls-certfile /full/path/to/comfyui.crt

The console will indicate the secure endpoint:


Starting server
To see the GUI go to: https://[::]:8188

Navigate to https://<your-host>:8188. The connection is now encrypted, though self-signed certificates will trigger browser warnings until you add a security exception.

Deploy with Trusted Certificates (Production)

For public-facing instances, replace the self-signed files with certificates issued by a trusted Certificate Authority (Let’s Encrypt, corporate PKI, or commercial CA). The command remains identical:

python main.py \
    --tls-keyfile /etc/letsencrypt/live/yourdomain.com/privkey.pem \
    --tls-certfile /etc/letsencrypt/live/yourdomain.com/fullchain.pem

Because the context uses ssl.PROTOCOL_TLS_SERVER, the server negotiates the highest TLS version supported by both client and server (typically TLS 1.2 or TLS 1.3).

Alternative: Reverse Proxy TLS Termination

If you require advanced TLS features—such as OCSP stapling, client certificate authentication, or HTTP Strict Transport Security (HSTS)—terminate TLS at a reverse proxy instead of using ComfyUI’s built-in support.

Run ComfyUI on localhost without TLS:

python main.py --listen 127.0.0.1 --port 8188

Then configure Nginx to handle HTTPS:

server {
    listen 443 ssl;
    server_name yourdomain.com;

    ssl_certificate /etc/ssl/certs/comfyui.crt;
    ssl_certificate_key /etc/ssl/private/comfyui.key;
    ssl_protocols TLSv1.2 TLSv1.3;

    location / {
        proxy_pass http://127.0.0.1:8188;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

This approach keeps the Python process unprivileged while the proxy manages cipher suites, certificate rotation, and security headers.

Summary

  • Core mechanism: ComfyUI’s server.py constructs an ssl.SSLContext when both --tls-keyfile and --tls-certfile are provided, attaching it to the aiohttp web.TCPSite listener.
  • File locations: Argument parsing occurs in comfy/cli_args.py (lines 40‑42); SSL context creation occurs in server.py (lines 1191‑1197).
  • Verification mode: The server uses ssl.CERT_NONE, meaning it presents its certificate to clients but does not validate client certificates.
  • Flexibility: Works with self-signed certificates for testing and CA-signed certificates for production, or can be disabled entirely when using a reverse proxy.

Frequently Asked Questions

Does ComfyUI support mutual TLS (mTLS) authentication?

No. As implemented in server.py, the SSL context sets ssl.CERT_NONE, which disables client certificate verification. The server authenticates itself to clients but does not require clients to present certificates. For mTLS, you must terminate TLS at a reverse proxy (such as Nginx or Traefik) that supports client certificate validation.

Which TLS protocol versions does ComfyUI support?

ComfyUI uses Python’s ssl.PROTOCOL_TLS_SERVER, which automatically negotiates the highest protocol version available (TLS 1.2 or TLS 1.3) based on the Python version and OpenSSL library linked to the interpreter. You do not need to manually specify protocol versions in the ComfyUI configuration.

Can I use Let's Encrypt certificates with ComfyUI directly?

Yes. As long as the files are PEM-encoded and readable by the ComfyUI process, you can point --tls-keyfile to the private key (e.g., privkey.pem) and --tls-certfile to the full chain (e.g., fullchain.pem). Ensure the certificate files are renewed before expiration, as ComfyUI does not support hot-reloading of TLS certificates while running.

Why does my browser show a "Not Secure" warning even with TLS enabled?

This occurs when using self-signed certificates or certificates issued by a private CA that your system does not trust. Because ssl.CERT_NONE only affects server-side verification (not client-side trust stores), you must either add your private CA to the client’s trust store, use a publicly trusted CA like Let’s Encrypt, or accept the browser warning for local development environments only.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →