Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fix a Python Requests SSLError by identifying what failed before changing TLS settings. For CERTIFICATE_VERIFY_FAILED, check whether the server certificate chains to a CA your client trusts; for a hostname mismatch, check that the URL and presented certificate identify the same host; for mutual TLS, configure the client certificate separately. Keep certificate verification enabled for real traffic: verify=False disables important protections rather than repairing the connection.

What a Requests SSLError means

Requests verifies HTTPS server certificates by default. If it cannot verify a certificate, it raises an SSLError. The exact exception text matters: a trust-chain failure, hostname mismatch, TLS handshake problem, and failure to load a local client certificate point to different causes. The traceback and environment are needed to determine which one applies; there is no single safe setting that fixes every SSLError. See the Requests advanced usage documentation and its FAQ.

  • Certificate verification failure: The client could not establish trust in the server’s certificate chain. A private or enterprise CA may be missing from the CA bundle Requests is using.
  • Hostname mismatch: The certificate presented for the HTTPS connection does not match the hostname Requests believes it is contacting. A wrong URL host, server certificate configuration, or an intervening proxy or TLS inspection device may be involved.
  • Client-certificate or handshake failure: The endpoint may require mutual TLS, or the TLS negotiation may fail for another reason. A client certificate is not a replacement for the CA bundle used to verify the server.

Requests documents that verification is enabled by default and that it raises an SSLError when it cannot verify the certificate. Its warning about verify=False is explicit: this accepts any TLS certificate and ignores hostname mismatches and expired certificates, leaving the application vulnerable to man-in-the-middle attacks.

Diagnose the error before changing configuration

  1. Read the full traceback. Record the URL host, the complete exception text, and whether the error says CERTIFICATE_VERIFY_FAILED, a hostname mismatch, a TLS protocol or handshake failure, or an error loading a local certificate. Avoid reducing every failure to the word “SSL.”
  2. Check the exact URL hostname. Confirm spelling, subdomain, and whether the client is connecting to the intended host. For a mismatch, the certificate presented for that connection must identify the host in the URL. Requests’ FAQ describes this class of error as a mismatch between the returned certificate and the hostname Requests believes it is contacting.
  3. Check whether the connection passes through a proxy or TLS inspection. Some corporate networks intercept HTTPS and present a certificate issued by an organization’s private CA. In that case the endpoint may be functioning, but the client still needs the approved CA certificate or bundle to trust the certificate it actually receives.
  4. Determine whether the server uses a private CA or requires mutual TLS. A private CA is configured as a server-trust bundle via verify or a CA-bundle environment variable. Mutual TLS instead requires a client credential via cert. Use the server or network administrator’s instructions to establish which is needed.
  5. Check the request path. A normal requests.get() call and a manually prepared request sent through a Session can handle environment configuration differently. If you rely on CA environment variables in a prepared-request flow, consult the merge step below.

Fix an untrusted private or enterprise CA

Obtain the CA certificate or bundle from the server owner or your organization’s trusted distribution process. Do not download a certificate from an unverified connection and blindly trust it. Once you have the approved bundle, pass its filesystem path to Requests:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Elebase USB to USB C Adapter for iPhone 18 Pro Max,USBC Car Charger Adapter
  • Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
  • Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
  • Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
  • Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
  • 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
import requests

url = "https://internal.example.com/"
ca_bundle = "/path/to/approved-ca-bundle.pem"

response = requests.get(url, verify=ca_bundle, timeout=30)
response.raise_for_status()
print(response.status_code)

Replace the example hostname and path with the endpoint and bundle location for your environment. The CA bundle is used to authenticate the server. A path that does not exist, cannot be read, or does not contain the appropriate CA will not solve the trust failure.

Set a CA bundle on one request or a Session

Use the per-request verify argument when only one call needs the private CA. For repeated requests to the same service, set the Session property instead:

import requests

session = requests.Session()
session.verify = "/path/to/approved-ca-bundle.pem"

response = session.get("https://internal.example.com/", timeout=30)
response.raise_for_status()

Requests also supports setting REQUESTS_CA_BUNDLE to the CA bundle path for a process. For example, in a Unix-like shell:

Rank #2
Anker USB-C Hub, 5-in-1 USB Hub for Laptops, 4K HDMI Multiport Adapter
  • 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
  • 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
  • Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
  • 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
  • What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
export REQUESTS_CA_BUNDLE=/path/to/approved-ca-bundle.pem
python app.py

Requests documents CURL_CA_BUNDLE as a fallback if REQUESTS_CA_BUNDLE is not set. Use the variable that matches how your application is launched, and ensure the process inherits it. The supported settings and their scope are described in the Requests advanced usage documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fix a hostname mismatch without disabling verification

A hostname mismatch is an identity problem, not simply a missing CA. Adding a CA bundle does not make a certificate valid for a different hostname. Check the URL’s hostname and have the server owner verify that the certificate presented for that host identifies it correctly. If traffic passes through a corporate proxy or TLS inspection system, ask the network administrator to check the certificate that system presents for the requested host.

Do not use verify=False to silence the mismatch. Requests says that this option ignores hostname mismatches and expired certificates as well as accepting any presented TLS certificate. That removes the checks intended to prevent a connection to an impersonating server. Keep verification enabled and correct the URL, server certificate, or approved proxy configuration.

Rank #3
Sale
Anker USB C Hub, 7in1 Multi-Port USB Adapter, 4K@60Hz USBC to HDMI Splitter
  • Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
  • Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
  • Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
  • Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
  • What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.

Configure a client certificate for mutual TLS

The cert argument supplies a client certificate when a server requires client authentication. It is separate from verify, which controls how Requests trusts the server’s certificate. Requests accepts a certificate path or a certificate-and-key tuple, as documented in its Developer Interface.

import requests

url = "https://mtls.example.com/"
client_certificate = ("/path/client.crt", "/path/client.key")
server_ca_bundle = "/path/to/approved-ca-bundle.pem"

response = requests.get(
    url,
    cert=client_certificate,
    verify=server_ca_bundle,
    timeout=30,
)
response.raise_for_status()

If the server does not require a separate private CA, use the appropriate server-verification configuration for your environment; do not assume cert makes the server trusted. If Requests reports that it cannot load a client certificate, check that the configured paths exist and are readable, that the certificate and key are the intended pair, and that the server’s mutual-TLS requirements match the credentials supplied.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Account for environment settings with prepared requests

For ordinary calls, Requests can use its environment configuration. In a flow that creates a PreparedRequest and sends it with a Session, the Requests documentation notes that environment settings may need to be merged explicitly. Otherwise, CA environment variables may not be applied as expected. A typical pattern is:

Rank #4
Sale
UGREEN USB to USB C Adapter Combo 4-Pack, 10Gbps USB C Converter Space Gray
  • Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
  • Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
  • Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
  • Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
  • Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
import requests

url = "https://internal.example.com/"
session = requests.Session()
request = requests.Request("GET", url)
prepared = session.prepare_request(request)
settings = session.merge_environment_settings(
    prepared.url,
    proxies={},
    stream=None,
    verify=None,
    cert=None,
)
response = session.send(prepared, timeout=30, **settings)
response.raise_for_status()

This is relevant when you have deliberately chosen the prepared-request/session send flow, particularly if the CA bundle is supplied through environment configuration. See the prepared-request environment-settings example in the Requests documentation PDF. Do not add this complexity to a normal requests.get() call without a reason.

Common failures and practical fixes

Symptom Likely issue What to check or change
CERTIFICATE_VERIFY_FAILED The certificate chain could not be validated with the CA bundle in use. Confirm whether the endpoint uses a private or enterprise CA. Obtain its approved bundle and configure verify, Session.verify, or REQUESTS_CA_BUNDLE.
Hostname mismatch The certificate presented does not identify the requested hostname. Check the URL host and ask the server or network administrator to inspect the certificate presented for that host, including any proxy or TLS inspection layer.
Error loading a local client certificate The configured client credential cannot be found, read, or used as specified. Check the cert file path or certificate/key tuple, file access, and the server’s mutual-TLS requirements.
The CA environment setting seems ignored in a prepared-request flow Environment settings may not have been merged before the Session sends the prepared request. Use session.merge_environment_settings() and pass the returned settings to session.send().
Adding a CA bundle does not fix the error The issue may be hostname identity, a wrong bundle, or a different handshake/client-certificate problem. Return to the complete traceback and identify which failure it names. A CA bundle does not correct a hostname mismatch or supply a required client certificate.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Performance, reliability, and security considerations

Correctly configuring the CA bundle or client certificate addresses trust or authentication while retaining HTTPS verification. In production, keep verification enabled and distribute private CA material through the organization’s approved process. Avoid making a global, permanent verification bypass to accommodate one endpoint: it changes the security behavior for requests that use that setting, rather than fixing the endpoint’s identity or trust chain. If the endpoint or network path changes, reassess which certificate the client receives instead of assuming an earlier CA configuration still applies.

Requests also supports timeouts as shown in the examples; set a timeout appropriate to your application so a network problem does not leave a request waiting indefinitely. A timeout is not a certificate fix, and changing it will not make an invalid certificate trusted.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Anker USB C Hub, 5-in-1 USBC to HDMI Splitter with 4K Display
  • 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
  • Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
  • Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
  • HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
  • What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.

Or skip the browser setup

If your actual task is capturing a webpage rather than repairing a Python HTTPS connection, ScreenshotNeo is a website screenshot API and MCP server. Its one-call API can return a screenshot or PDF; it is not a remedy for Requests certificate errors. For example, this Python call saves a WebP response:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

See the ScreenshotNeo API documentation for setup and options. It removes cookie banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, and failed loads are never billed. Its MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card, and paid plans start at $5 for 3,000. Sign up for free.

FAQ

Can I use a self-signed certificate with Requests?

Use a CA bundle that contains the certificate authority you have deliberately chosen to trust, obtained and verified through a trusted process. Configure its path with verify or the documented CA-bundle settings. Do not trust a certificate merely because it was downloaded from the connection that failed verification.

Does cert= fix CERTIFICATE_VERIFY_FAILED?

Not usually. cert= supplies a client certificate for mutual TLS; verify= configures trust in the server certificate. They solve different sides of TLS authentication.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is verify=False safe for production?

No. It disables certificate verification, including hostname and expiration checks, and Requests warns that it makes applications vulnerable to man-in-the-middle attacks. Correct the trust configuration or endpoint instead.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.