Use the smallest safe fix for the cause. For production-like tests, repair the certificate chain or install the correct internal root CA. For a disposable local certificate, set Playwright’s ignoreHTTPSErrors: true only on the test context that needs it. If an intercepting proxy breaks Playwright browser downloads, set NODE_EXTRA_CA_CERTS before npx playwright install. A client certificate is a different feature: it authenticates your test to a server but does not make an invalid server certificate trusted.
What ERR_CERT_AUTHORITY_INVALID means
The browser used by Playwright cannot build a trusted certificate-authority (CA) chain for the HTTPS URL. The endpoint may use a self-signed development certificate, an internal CA that is absent from the test environment, a server certificate missing an intermediate, or a certificate whose hostname does not match the URL. A corporate or debugging proxy can also re-sign traffic with its own CA.
Start by inspecting the certificate actually served to the Playwright process and the network path it takes. Test the exact hostname and port in the failing URL; a certificate valid for api.example.test does not validate localhost or an IP address unless those names are present in its subject alternative names.
Choose the fix that matches your situation
| Situation | Preferred action | Security posture |
|---|---|---|
| Production-like or security-sensitive test | Serve the leaf certificate with all required intermediates and a matching hostname; install the organization root CA in the environment running Playwright. | Keep certificate validation enabled. |
| Disposable local self-signed certificate | Use ignoreHTTPSErrors: true in the narrowest browser context, or replace the certificate with one trusted by the test environment. |
Acceptable only when TLS validation is outside the test’s purpose. |
| Playwright browsers fail to download behind an intercepting proxy | Set NODE_EXTRA_CA_CERTS to the proxy’s custom root certificate before installing browsers. |
Node trusts the proxy CA for that command. |
| The server requests a client certificate | Configure clientCertificates for the exact origin with the matching certificate and private key (or PFX). |
Authenticates the client; it does not trust an invalid server chain. |
Fix the certificate chain first
Check the served chain and hostname
- Open the failing HTTPS URL with the same hostname Playwright uses. Record the leaf certificate’s subject-alternative names, issuer, expiry, and whether an intermediate certificate is supplied.
- Check the server configuration to ensure it sends the leaf certificate followed by every required intermediate. Supplying only the leaf often causes authority errors even when the root CA is installed.
- Verify that the URL hostname matches a name in the certificate. Do not “fix” a hostname mismatch with a CA setting; issue a certificate for the name used by the test.
- Repeat the inspection from the machine, container, or CI worker that runs Playwright. A root CA installed on your laptop is not automatically present in a container or hosted runner.
Install an internal root CA where the browser runs
If your organization intentionally signs the endpoint with a private CA, install that CA’s root certificate in the operating-system or browser environment used by the test, according to your platform’s certificate-management procedure. Distribute the root through your approved CI image or secret-management process; do not commit private keys or trust files to the repository. Keep ignoreHTTPSErrors set to its default while validating this setup so the test still detects broken chains.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
Use ignoreHTTPSErrors for a deliberately local bypass
Playwright documents ignoreHTTPSErrors as controlling whether HTTPS errors are ignored when sending network requests; its default is false. Setting it to true disables the browser’s HTTPS-error enforcement for that context. It does not repair the certificate, encrypt traffic differently, or make the endpoint safe for production.
Playwright Test configuration
import { defineConfig } from '@playwright/test';
export default defineConfig({
use: {
ignoreHTTPSErrors: true
}
});
This applies to tests using that configuration. Prefer a project or narrowly scoped configuration for a local-only suite rather than changing a shared base configuration used for staging or production checks.
One browser context only
import { chromium } from 'playwright';
const browser = await chromium.launch();
const context = await browser.newContext({
ignoreHTTPSErrors: true
});
const page = await context.newPage();
await page.goto('https://localhost:8443', { waitUntil: 'domcontentloaded' });
console.log(await page.title());
await browser.close();
Scoping the option to one context prevents unrelated contexts in the same process from silently accepting bad certificates. Add an explicit test comment explaining why the bypass is intentional, and avoid using it in a test whose purpose is certificate validation.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
Do not confuse navigation failures with request failures
The setting belongs on the browser context (or the Playwright Test use configuration), not as a page URL parameter. If your test also makes direct API calls with another HTTP client, configure that client separately; a browser-context option does not change Node.js TLS behavior for unrelated libraries.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Fix browser installation through an intercepting proxy
A proxy that inspects HTTPS downloads can present a certificate signed by a private CA. Playwright’s browser guide documents NODE_EXTRA_CA_CERTS for this case. Set it before the install command, using the PEM file containing the proxy’s custom root certificate:
export NODE_EXTRA_CA_CERTS="/path/to/cert.pem"
npx playwright install
On Windows, set the equivalent environment variable in PowerShell or Command Prompt before running npx playwright install. Confirm that the path is readable by the account running the command and that the file contains the root CA, not merely a server leaf certificate. This remedy is for Node’s trust during browser downloads; it does not replace installing the CA for page navigation in the browser context.
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
Keep installation and test runtime consistent
If installation succeeds but navigation still reports ERR_CERT_AUTHORITY_INVALID, treat those as two separate trust paths. Configure the browser/OS trust store used by the test or apply the deliberately scoped ignoreHTTPSErrors setting for local development. Conversely, setting the context option cannot help an npx playwright install download that fails before a browser launches.
Configure client certificates only for mutual TLS
Some servers require mutual TLS (mTLS): the server proves its identity to the client, and the client must present a certificate of its own. Playwright’s clientCertificates option supplies that client credential for an exact origin. It does not make an untrusted server certificate chain valid.
import { chromium } from 'playwright';
const browser = await chromium.launch();
const context = await browser.newContext({
clientCertificates: [{
origin: 'https://mtls.internal.example',
certPath: '/secure/test-client.crt',
keyPath: '/secure/test-client.key'
}]
});
const page = await context.newPage();
await page.goto('https://mtls.internal.example');
await browser.close();
Use a PFX/PKCS#12 file and its password when that is how your test credentials are issued, instead of certPath/keyPath. The origin must match the server origin exactly. Keep the private key outside source control and make its permissions restrictive.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
Diagnose the common failure modes
The bypass appears to do nothing
- Confirm the option is on the context actually creating the page. A new context without the option will still reject the certificate.
- Check that the failing URL is HTTPS and that the error is certificate validation, not a DNS, connection, timeout, or proxy-authentication failure.
- Restart the test process after changing configuration so an old context is not reused.
Only CI fails
- Inspect the CI image’s trust store; it may not contain the internal root installed on developer machines.
- Verify the proxy and certificate files are available at the paths used by the CI account.
- Compare the URL hostname in CI with local runs; environment variables sometimes redirect tests to a different host whose certificate is not covered.
A proxy still reports an authority error during install
- Set
NODE_EXTRA_CA_CERTSbefore, not after,npx playwright install. - Use the proxy’s root CA in PEM format and check that the variable points to the complete file path.
- If your organization rotates proxy CAs, refresh the CI image or secret rather than bypassing TLS verification globally.
Adding a client certificate did not solve it
Check the server’s own chain independently. A client certificate proves who the test client is after a trusted server connection is established; it cannot authorize the server’s self-signed or incomplete certificate.
The page loads but assertions are unreliable
A bypass can make navigation proceed while the application still fails because API calls, WebSockets, or subresources use another hostname with a different certificate. Inspect every origin requested by the page and fix or scope trust for each one. Do not assume that accepting the top-level page validates all dependencies.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Reliability and security practices
- Use a valid chain and an installed internal root for staging-like tests. This catches expiry, missing intermediates, hostname errors, and trust-store regressions.
- Put
ignoreHTTPSErrors: truein a clearly named local project or fixture, not in a shared global preset. - Keep test certificates short-lived and separate from production credentials. Protect private keys and redact certificate paths and secrets from logs.
- Run one small trust-validation test with the bypass disabled, even if most UI tests use a local self-signed endpoint.
- When a proxy is present, document which CA is trusted and provision it reproducibly for both browser installation and test execution.
Or skip the browser setup
If your goal is a clean image or PDF rather than browser automation, ScreenshotNeo provides a website screenshot API. Its request accepts a URL and returns PNG, JPEG, WebP, or PDF. Before capture it accepts cookie/consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks/CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and whether it was billed.
ScreenshotNeo also offers an MCP server for Claude, Cursor, and other MCP clients, with take_screenshot, get_page_info, and capture_pdf tools. Features include full-page capture with lazy images loaded, CSS-selector element capture, dark mode, device presets and custom viewports, retina scale, PDF paper/margins/landscape/page ranges, custom CSS and JavaScript, pre-capture clicks, waits, request/resource blocking, headers, cookies, user agent, Authorization, timezone, geolocation, transparent backgrounds, resizing, chosen-TTL caching, signed image links, asynchronous jobs with signed webhooks, bulk capture of up to 100 URLs per call, a usage API, and an OpenAPI specification. Familiar parameter names from other screenshot APIs are accepted to ease migration.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo documentation for all options, authentication details, and response headers.
The Free plan includes 1,000 shots per month with no card. Paid plans start at $5 for 3,000 shots; yearly billing gives two months free, and every feature is included on every plan. Create a free ScreenshotNeo account to get started.
FAQ
What is the default value of ignoreHTTPSErrors?
It is false, so Playwright validates HTTPS certificates unless you explicitly change the setting.
Can NODE_EXTRA_CA_CERTS fix a page’s certificate error?
It is the documented remedy for a custom proxy CA involved in Playwright browser downloads. Page navigation may require trust-store configuration for the browser environment or a narrowly scoped context setting.
Should I use ignoreHTTPSErrors in production tests?
Usually no. It removes the very validation that production-like tests should verify. Repair the chain or install the intended internal root instead.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

