Free SSL certificates
Issue / renew / revoke in one panel
Covers Let's Encrypt / ZeroSSL / Buypass / Google Trust Services — four free ACME CAs. DNS-01 automated validation, auto-renewal, private keys encrypted at rest with KMS.
Sign in to apply, no credit card needed; single domain / multi-SAN / wildcard supported.
Where idcd fits
From a single small site to dozens of internal subdomains — managed in one place.
Indie hackers & side projects
Running acme.sh / certbot across multiple blogs, side projects, and demos is brittle. Manage every domain in one place with renewal reminders and automated rollover.
“Blog + tools site + project demo — 8 domains total, one Cloudflare API token, idcd handles the rest.”
SMB SRE
Domains spread across Aliyun / DNSPod / Cloudflare? Authorize each DNS API once and every CA renews automatically.
“30+ internal subdomains, all on wildcards + auto-renewal — never woken by a midnight expiration alert.”
China-based developers
Aliyun / Tencent free SSL caps at 20 / year with clunky renewal; English CA dashboards are hard to navigate. idcd ships a Chinese UI reachable from mainland China.
“Used to bounce between Aliyun and Tencent every year. idcd consolidates it all — and stays fast in China.”
4 free CAs, automatic routing
Defaults to Let's Encrypt; if quotas tighten, falls over to backup CAs automatically.
The most widely deployed free CA. ACMEv2, no EAB, issuance < 60s.
EAB auto-configured. Takes over when LE quotas are tight.
Norwegian CA with broad root trust. Second-line fallback.
Native GCP support — requires a GCP account + EAB.
Apply to renew in 4 steps
First cert in 3 minutes after sign-in. idcd takes it from there.
Sign in + enter domain
Single domain / multi-SAN (≤ 10) / wildcard *.example.com. CAA pre-check runs before submission.
DNS-01 validation
Authorize Cloudflare / Aliyun DNS / DNSPod / Route53 etc. — TXT records added automatically. Manual mode also supported.
CA issuance
Issued immediately after CA validation. Defaults to LE; falls over to ZeroSSL / Buypass when quotas tighten.
Download + auto-renewal
Download links expire after 5 minutes. Renewal triggers 30 days before expiry with email + in-app notifications.
Why not just use acme.sh / certbot?
Private keys behind KMS
ECDSA P-256 generated locally. Stored with AES-GCM + KMS encryption. Download links expire in 5 minutes.
Auto-renewal 30 days early
Cron + retry queue handle multiple attempts. DNS-01 reuses the original provider — email + in-app notifications.
Multi-CA routing
Defaults to Let's Encrypt; auto-switches to ZeroSSL / Buypass when quotas tighten. CA failure also has a fallback.
CAA pre-check
Validates CAA records before submission with an explicit “why the CA might reject this” diagnosis — no guessing during the 60s countdown.
Revocation + abuse control
One-click revoke for mis-issued certs / key compromise — CA + local state sync. Rapid multi-domain issuance is rate-limited.
Frequently asked
Still have questions? Email support@idcd.com — we read every message.
Are the certificates really free?
Yes. idcd doesn't run its own CA — we're a client wrapper for the public free CAs (Let's Encrypt, ZeroSSL, Buypass), and issuance from those CAs is always free. idcd doesn't charge per certificate either — sign in and you're set.
Do you support wildcards / multi-SAN?
Yes. Up to 10 domains per certificate, including wildcards (*.example.com). Upstream CAs cap SAN counts (LE allows 100); idcd uniformly caps at 10 during S1 to control abuse risk.
How long does issuance take?
DNS-01 automated mode (Cloudflare / Aliyun DNS / etc.) lands within P95 90 seconds. Manual DNS mode depends on how fast you add the TXT record.
How are private keys stored? I'm worried about security.
Keys are generated locally with ECDSA P-256 (never sent to upstream CAs), encrypted with AES-GCM + KMS keyring before storage. Download links are minted per-request and expire in 5 minutes. idcd internal audits cannot see plaintext.
How is this different from Aliyun / Tencent free certs?
1) No per-cert quota (subject only to CA-side rate limits, rarely hit in practice); 2) Chinese UI reachable from mainland China; 3) Multi-CA routing + auto-renewal; 4) No credit card; sign in and apply.
90 seconds to a free certificate — faster than brewing a coffee.
Fully free, no credit card. Sign in, pick single / multi-SAN / wildcard, choose your CA.
Issue your first free cert