Free DV certs
Wildcards + multi-SAN
Auto-renewal
Chinese UI
$0
Fully free
4
Free CAs
10
SAN / cert
90s
P95 issue time

Free SSL certificatesIssue / renew / revoke in one panel

Covers Let's Encrypt / ZeroSSL / Buypass / Google Trust Services — four free ACME CAs. DNS-01 automated validation, auto-renewal, private keys encrypted at rest with KMS.

Sign in to apply, no credit card needed; single domain / multi-SAN / wildcard supported.

Where idcd fits

From a single small site to dozens of internal subdomains — managed in one place.

Indie hackers & side projects

Running acme.sh / certbot across multiple blogs, side projects, and demos is brittle. Manage every domain in one place with renewal reminders and automated rollover.

“Blog + tools site + project demo — 8 domains total, one Cloudflare API token, idcd handles the rest.”

SMB SRE

Domains spread across Aliyun / DNSPod / Cloudflare? Authorize each DNS API once and every CA renews automatically.

“30+ internal subdomains, all on wildcards + auto-renewal — never woken by a midnight expiration alert.”

China-based developers

Aliyun / Tencent free SSL caps at 20 / year with clunky renewal; English CA dashboards are hard to navigate. idcd ships a Chinese UI reachable from mainland China.

“Used to bounce between Aliyun and Tencent every year. idcd consolidates it all — and stays fast in China.”

4 free CAs, automatic routing

Defaults to Let's Encrypt; if quotas tighten, falls over to backup CAs automatically.

Let's Encrypt
Free / default

The most widely deployed free CA. ACMEv2, no EAB, issuance < 60s.

ZeroSSL
Free / backup

EAB auto-configured. Takes over when LE quotas are tight.

Buypass
Free / fallback

Norwegian CA with broad root trust. Second-line fallback.

Google Trust Services
Planned

Native GCP support — requires a GCP account + EAB.

Apply to renew in 4 steps

First cert in 3 minutes after sign-in. idcd takes it from there.

1

Sign in + enter domain

Single domain / multi-SAN (≤ 10) / wildcard *.example.com. CAA pre-check runs before submission.

2

DNS-01 validation

Authorize Cloudflare / Aliyun DNS / DNSPod / Route53 etc. — TXT records added automatically. Manual mode also supported.

3

CA issuance

Issued immediately after CA validation. Defaults to LE; falls over to ZeroSSL / Buypass when quotas tighten.

4

Download + auto-renewal

Download links expire after 5 minutes. Renewal triggers 30 days before expiry with email + in-app notifications.

Why not just use acme.sh / certbot?

Private keys behind KMS

ECDSA P-256 generated locally. Stored with AES-GCM + KMS encryption. Download links expire in 5 minutes.

Auto-renewal 30 days early

Cron + retry queue handle multiple attempts. DNS-01 reuses the original provider — email + in-app notifications.

Multi-CA routing

Defaults to Let's Encrypt; auto-switches to ZeroSSL / Buypass when quotas tighten. CA failure also has a fallback.

CAA pre-check

Validates CAA records before submission with an explicit “why the CA might reject this” diagnosis — no guessing during the 60s countdown.

Revocation + abuse control

One-click revoke for mis-issued certs / key compromise — CA + local state sync. Rapid multi-domain issuance is rate-limited.

Frequently asked

Still have questions? Email support@idcd.com — we read every message.

Are the certificates really free?

Yes. idcd doesn't run its own CA — we're a client wrapper for the public free CAs (Let's Encrypt, ZeroSSL, Buypass), and issuance from those CAs is always free. idcd doesn't charge per certificate either — sign in and you're set.

Do you support wildcards / multi-SAN?

Yes. Up to 10 domains per certificate, including wildcards (*.example.com). Upstream CAs cap SAN counts (LE allows 100); idcd uniformly caps at 10 during S1 to control abuse risk.

How long does issuance take?

DNS-01 automated mode (Cloudflare / Aliyun DNS / etc.) lands within P95 90 seconds. Manual DNS mode depends on how fast you add the TXT record.

How are private keys stored? I'm worried about security.

Keys are generated locally with ECDSA P-256 (never sent to upstream CAs), encrypted with AES-GCM + KMS keyring before storage. Download links are minted per-request and expire in 5 minutes. idcd internal audits cannot see plaintext.

How is this different from Aliyun / Tencent free certs?

1) No per-cert quota (subject only to CA-side rate limits, rarely hit in practice); 2) Chinese UI reachable from mainland China; 3) Multi-CA routing + auto-renewal; 4) No credit card; sign in and apply.

Chrome flags HTTP sites by default — HTTPS is no longer optional.

90 seconds to a free certificate — faster than brewing a coffee.

Fully free, no credit card. Sign in, pick single / multi-SAN / wildcard, choose your CA.

Issue your first free cert