# How to Configure SSL/HTTPS for Production Deployments of AnythingLLM

> Secure your AnythingLLM production deployment with SSL HTTPS. Learn to configure native Node.js TLS or use an Nginx reverse proxy for robust security.

- Repository: [Mintplex Labs/anything-llm](https://github.com/Mintplex-Labs/anything-llm)
- Tags: how-to-guide
- Published: 2026-03-07

---

**AnythingLLM supports HTTPS through native Node.js TLS termination—enabled via the `ENABLE_HTTPS` environment variable—or by terminating TLS at an external reverse proxy such as Nginx, with reverse-proxy deployment recommended for production environments.**

To secure your self-hosted AI workspace, you must configure SSL/HTTPS for production deployments of AnythingLLM. The open-source application (maintained by Mintplex-Labs) offers flexible TLS deployment options—either native HTTPS support within the Node.js server or delegation to a reverse proxy—allowing administrators to align security implementation with their infrastructure standards.

## Native HTTPS Configuration in AnythingLLM

AnythingLLM can terminate TLS directly within its Node.js server when provided with valid certificate files, eliminating the need for external proxy layers in simpler deployments.

### Enabling Built-in TLS

According to the source code in [`server/index.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/index.js) (lines 59-61), the application evaluates `process.env.ENABLE_HTTPS` to determine whether to invoke the secure boot path. When **`ENABLE_HTTPS`** is set to `"true"`, the server imports `bootSSL` from [`server/utils/boot/index.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/utils/boot/index.js) (lines 19-31), which creates an HTTPS server using the certificate and private key specified by the environment variables **`HTTPS_CERT_PATH`** and **`HTTPS_KEY_PATH`**.

The `bootSSL` function also configures WebSocket support via `express-ws` (lines 44-45 in [`server/utils/boot/index.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/utils/boot/index.js)) to ensure real-time agent streams function over secure WebSocket (`wss://`) connections. If certificate loading fails, the implementation gracefully falls back to plain HTTP and logs the specific error for troubleshooting (lines 46-56), preventing application crashes while alerting administrators to configuration issues.

### Required Environment Variables

Configure these variables in your `server/.env` file, following the template in `server/.env.example` (lines 49-53):

```dotenv
ENABLE_HTTPS="true"
HTTPS_CERT_PATH="/app/server/ssl/fullchain.pem"
HTTPS_KEY_PATH="/app/server/ssl/privkey.pem"

```

### Docker Deployment with TLS Certificates

When running AnythingLLM via Docker, bind-mount your certificate directory as a read-only volume and pass the environment variables through [`docker-compose.yml`](https://github.com/Mintplex-Labs/anything-llm/blob/main/docker-compose.yml):

```yaml
services:
  anything-llm:
    build:
      context: ../.
      dockerfile: ./docker/Dockerfile
    ports:
      - "3001:3001"
    volumes:
      - "./.env:/app/server/.env"
      - "/opt/anything-llm/ssl:/app/server/ssl:ro"
      - "../server/storage:/app/server/storage"
      - "../collector/hotdir/:/app/collector/hotdir"
      - "../collector/outputs/:/app/collector/outputs"
    environment:
      - ENABLE_HTTPS=true
      - HTTPS_CERT_PATH=/app/server/ssl/fullchain.pem
      - HTTPS_KEY_PATH=/app/server/ssl/privkey.pem

```

## Reverse Proxy TLS Termination (Recommended)

For production deployments, terminating TLS at a reverse proxy provides centralized certificate management, automated Let's Encrypt integration, and additional security hardening through HTTP/2 and HSTS enforcement.

### Nginx Configuration Example

The official bare-metal documentation in [`BARE_METAL.md`](https://github.com/Mintplex-Labs/anything-llm/blob/main/BARE_METAL.md) (lines 15-28) provides an Nginx configuration that proxies both HTTP API routes and WebSocket connections. This approach allows the upstream Node process to run on plain HTTP internally while presenting HTTPS externally:

```nginx
server {
    listen 443 ssl;
    server_name chat.example.com;

    ssl_certificate     /etc/ssl/certs/fullchain.pem;
    ssl_certificate_key /etc/ssl/private/privkey.pem;
    ssl_protocols       TLSv1.2 TLSv1.3;

    location / {
        proxy_pass http://localhost:3001;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }

    # WebSocket support for agent streams

    location ~* ^/api/agent-invocation/(.*) {
        proxy_pass http://localhost:3001;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "Upgrade";
    }

    proxy_connect_timeout 600s;
    proxy_send_timeout    600s;
    proxy_read_timeout    600s;
}

```

## Generating Self-Signed Certificates for Testing

For internal testing before deploying production certificates from a trusted CA:

```bash
mkdir -p sslcert
openssl req -newkey rsa:2048 -nodes -keyout sslcert/key.pem \
  -x509 -days 365 -out sslcert/cert.pem -subj "/CN=anything.local"

```

Self-signed certificates are suitable for development environments; production deployments should use certificates from a trusted certificate authority.

## Summary

- **Native TLS termination**: Set `ENABLE_HTTPS=true` with valid `HTTPS_CERT_PATH` and `HTTPS_KEY_PATH` values to enable direct HTTPS serving via the `bootSSL` function in [`server/utils/boot/index.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/utils/boot/index.js), with automatic WebSocket (`wss://`) support.
- **Reverse proxy deployment**: Deploy Nginx, Traefik, or similar in front of AnythingLLM to handle TLS termination and certificate rotation, allowing the application to run on plain HTTP internally while presenting HTTPS externally.
- **Certificate fallback behavior**: If native HTTPS is enabled but certificate files are missing or invalid, the server falls back to HTTP (as implemented in lines 46-56 of [`server/utils/boot/index.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/utils/boot/index.js)) and logs the error rather than crashing.
- **WebSocket compatibility**: Ensure proxy configurations include `Upgrade` and `Connection` headers for `/api/agent-invocation/` routes to maintain real-time agent functionality over TLS.

## Frequently Asked Questions

### Can AnythingLLM automatically redirect HTTP to HTTPS?

No, the current implementation in [`server/utils/boot/index.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/utils/boot/index.js) starts either an HTTPS server or an HTTP server based on the `ENABLE_HTTPS` flag, but does not include a redirect mechanism. To enforce HTTPS, deploy a reverse proxy that handles 301 redirects from port 80 to 443, or configure the HTTP instance solely for redirection while the HTTPS instance serves the application on a separate port.

### What happens if the SSL certificate files are missing or invalid?

If the `bootSSL` function cannot load the certificate or key files specified in `HTTPS_CERT_PATH` or `HTTPS_KEY_PATH`, the server logs the specific filesystem error and falls back to running on plain HTTP (lines 46-56 in [`server/utils/boot/index.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/utils/boot/index.js)). This prevents the application from crashing but leaves the deployment insecure, so verify file paths, permissions, and certificate validity before production deployment.

### Does AnythingLLM support Let's Encrypt or automated certificate rotation?

Not natively within the application code. For automated certificate management, use a reverse proxy such as Nginx with Certbot, or Traefik with built-in ACME support. These tools handle Let's Encrypt challenges, automatic renewal, and configuration reloading without requiring changes to the `ENABLE_HTTPS` configuration or container restarts.

### How do I secure WebSocket connections for agent features?

When using native HTTPS, the `bootSSL` function automatically configures `express-ws` to serve WebSocket connections over `wss://` (secure WebSocket) as shown in lines 44-45 of [`server/utils/boot/index.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/utils/boot/index.js). When using a reverse proxy, include the `Upgrade $http_upgrade` and `Connection "Upgrade"` headers in your proxy configuration for routes matching `/api/agent-invocation/` to ensure agent streams and real-time features function correctly over TLS.