Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set the WebDriver capability before creating the Chrome session. In Ruby Selenium, use Selenium::WebDriver::Options.chrome, set options.accept_insecure_certs = true, and pass that options object to Selenium::WebDriver.for. The setting applies to the whole WebDriver session, so navigations in that session can trust invalid or expired TLS certificates.

The direct Selenium Ruby solution

For a standalone Selenium session, this is the current Ruby pattern:

require "selenium-webdriver"

options = Selenium::WebDriver::Options.chrome
options.accept_insecure_certs = true

# Headless Chrome is optional; remove this line for a visible browser.
options.add_argument("--headless=new")

driver = Selenium::WebDriver.for(:chrome, options: options)

begin
  driver.navigate.to("https://your-internal-host.example")
  puts driver.title
ensure
  driver.quit
end

accept_insecure_certs is Selenium’s Ruby mapping of the WebDriver acceptInsecureCerts capability. With the value set to true, the browser trusts invalid certificates encountered during navigation. With the value set to false (the normal default), an insecure-certificate error is returned instead. This is a session capability, not a switch that applies only to one URL.

Use it for a deliberately controlled environment such as a local HTTPS server, a staging site with a private certificate authority, or an integration-test appliance. Do not use it to hide a certificate problem on a production site: the browser will no longer provide the normal certificate warning for that session.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the capability changes—and what it does not

Setting Layer Effect Use it when
acceptInsecureCerts = true WebDriver session capability Chrome trusts invalid or expired TLS certificates during navigation for the entire session. Your test intentionally targets a host whose certificate is not publicly trusted.
--ignore-certificate-errors Chrome command-line argument A browser startup switch that changes Chrome’s certificate-error handling. Only after validating the switch with the Chrome and ChromeDriver versions used by your project.

The command-line argument is not another spelling of the WebDriver capability. Selenium’s Ruby material shows it as supplementary Chrome configuration, while the capability is the direct WebDriver API for this behavior. Prefer the capability when your intent is to configure the WebDriver session, and keep the argument as a fallback for a specific, tested browser setup.

Headless Chrome details

Use the same capability in visible and headless modes

Headless mode changes how Chrome renders its window; it does not require a different certificate capability. Add a headless argument to the same options object:

options = Selenium::WebDriver::Options.chrome
options.accept_insecure_certs = true
options.add_argument("--headless=new")
options.add_argument("--window-size=1440,1000")

driver = Selenium::WebDriver.for(:chrome, options: options)

Some older Chrome installations use the legacy --headless argument rather than --headless=new. Select the form supported by the Chrome binary in your test image, and keep Chrome, ChromeDriver (or Selenium Manager), and the Ruby gem compatible.

Run a visible session while diagnosing

If a headless test fails, temporarily remove the headless argument. A visible browser makes it easier to see whether the failure is a certificate interstitial, a DNS problem, an authentication page, or an application error. Re-enable headless mode after the underlying problem is understood.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Certificate errors are not every HTTPS failure

The capability addresses certificate validation. It does not repair DNS, connection refusal, a server that never responds, an application-level 401 or 500 response, a proxy that blocks the request, or a page whose JavaScript crashes after it loads. Capture the browser log, the current URL, and the exception text so those failures are not mistaken for certificate errors.

Rank #2
Sale
HTML and CSS: Design and Build Websites
  • HTML CSS Design and Build Web Sites
  • Comes with secure packaging
  • It can be a gift option

Rails system tests

Rails system tests select a Selenium driver with driven_by. Rails exposes the driver configuration block so you can place Chrome options and capabilities at the same layer that creates the system-test session.

Typical ApplicationSystemTestCase placement

# test/application_system_test_case.rb
require "test_helper"

class ApplicationSystemTestCase < ActionDispatch::SystemTestCase
  driven_by :selenium,
            using: :headless_chrome,
            screen_size: [1400, 1400] do |options|
    options.accept_insecure_certs = true
  end
end

The exact block argument and option methods depend on the Rails and selenium-webdriver versions in your Gemfile and lockfile. Rails 8.0 documents the driven_by approach, but there is no single snippet that is guaranteed for every Rails, Capybara, and Selenium combination. If your version supplies a driver configuration object rather than Chrome options directly, set accept_insecure_certs on that options object before the driver is instantiated.

Use the driver that the test actually selects

A common diagnostic mistake is configuring one driver while the test runs another. Check the driven_by declaration, any per-test driver override, and environment-specific setup. A capability placed in a standalone Selenium initializer has no effect if Rails creates a separate session with different options.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep the exception scoped to the test environment

Put this capability in the system-test configuration used by local or staging tests, not in shared production browser code. If your application runs tests against both trusted and untrusted endpoints, create separate driver configurations and choose the permissive one only for the tests that need it.

Capybara with a registered Selenium Chrome driver

Capybara can register a Selenium driver with a custom name. Put the capability on the Chrome options object passed to that driver, then select the same name in your tests.

# test/support/capybara.rb or spec/support/capybara.rb
require "capybara/rails"
require "selenium-webdriver"

Capybara.register_driver :selenium_headless_insecure do |app|
  options = Selenium::WebDriver::Options.chrome
  options.accept_insecure_certs = true
  options.add_argument("--headless=new")
  options.add_argument("--window-size=1440,1000")

  Capybara::Selenium::Driver.new(
    app,
    browser: :chrome,
    options: options
  )
end

Capybara.javascript_driver = :selenium_headless_insecure

In RSpec, load this file from the support directory and ensure support files are required. In a test that needs the custom driver explicitly, use the driver name that you registered. Capybara's integration supports several driver paths, so configuring an unused registration will not alter the session created by the test.

Per-test selection

RSpec.describe "an internal HTTPS page", type: :feature, js: true do
  before do
    Capybara.current_driver = :selenium_headless_insecure
  end

  after do
    Capybara.use_default_driver
  end

  it "loads the page" do
    visit "https://your-internal-host.example"
    expect(page).to have_content("Welcome")
  end
end

If your suite uses a different Capybara driver for JavaScript tests, set that driver's options instead. The capability must be present in the session that performs visit; setting it on a driver that is never selected cannot affect navigation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Capability versus Chrome switch: choosing the right level

  • Prefer the capability when you want a documented, WebDriver-level session behavior that is visible in your Selenium configuration.
  • Use a Chrome argument only deliberately. The argument is browser-specific, may vary with Chrome/ChromeDriver releases, and should be validated in the exact CI image you deploy.
  • Do not combine them to guess at a fix. Configure one approach, reproduce the failure, and inspect the resulting session before adding another setting.
  • Do not copy legacy DesiredCapabilities examples blindly. Current Selenium Ruby code uses the browser options object; older examples may use APIs that are no longer the preferred interface.

Security and operational considerations

Limit trust to non-production targets

Accepting an invalid certificate removes an important authenticity check. A test could connect to the wrong host and still proceed if the endpoint presents an untrusted certificate. Restrict the setting to local, test, or explicitly controlled staging hosts, and keep it out of a shared production smoke-test profile.

Make the setting visible in CI

Name the custom driver clearly, such as selenium_headless_insecure, and document why it exists. This prevents a future maintainer from treating the permissive behavior as a general browser default. Record the Chrome version, Selenium gem version, driver selection, current URL, and the first certificate-related exception when a job fails.

Expect a session-wide effect

Because the capability applies to the whole WebDriver session, every navigation made by that driver inherits the behavior. Create a separate session or driver configuration when only a subset of tests should accept untrusted certificates.

Rank #4
Sale
Web Design with HTML, CSS, JavaScript and jQuery Set
  • Brand: Wiley
  • Set of 2 Volumes
  • A handy two-book set that uniquely combines related technologies Highly visual format and accessible language makes these books highly effective learning tools Perfect for beginning web designers and front-end developers

Performance

The capability itself does not add a per-navigation wait or a second request. Overall test time is more often determined by Chrome startup, page load, JavaScript, network access, and CI resources. Reusing a session can reduce startup cost, but it also broadens the set of navigations affected by the capability; isolate sessions when safety is more important than startup speed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Troubleshooting checklist

Chrome still shows a certificate error

  • Confirm that options.accept_insecure_certs = true runs before Selenium::WebDriver.for.
  • Confirm that the driver receives options: options, rather than a newly created options object.
  • Check that the test is using the configured Rails or Capybara driver, not a default driver.
  • Verify Chrome, the driver, and the Selenium gem versions in the failing environment.

The setting works locally but not in CI

  • Compare the browser and driver versions and the selected headless argument.
  • Check proxy, DNS, firewall, and container network settings; those are not certificate-validation problems.
  • Run once in visible mode or save a screenshot and browser log to distinguish an interstitial from an application response.

Rails rejects the configuration block

Rails and Selenium have changed option plumbing across versions. Consult the API shape exposed by the Rails version in your lockfile, then pass the capability through the driver-options object that version supplies. Do not assume a block parameter shown for one Rails release has the same methods in another.

Capybara ignores the capability

  • Check that the custom driver registration file is loaded.
  • Check Capybara.current_driver and Capybara.javascript_driver.
  • Ensure the Selenium driver receives the same options object on which the capability was set.

The page loads but the test still fails

Inspect the HTTP response, page content, and application logs. A trusted-invalid certificate only gets Chrome past certificate validation; it does not authenticate the user, satisfy a client-certificate requirement, fix a broken redirect, or make an unavailable service respond.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your goal is a clean image or PDF rather than an interactive browser test, ScreenshotNeo provides a single screenshot API request. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Only clean shots are billed: bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and response headers identify the page verdict and billing result. Its MCP server exposes take_screenshot, get_page_info, and capture_pdf to Claude, Cursor, and other MCP clients.

See the ScreenshotNeo API documentation for parameters. A direct cURL request is:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

The same call in Python:

import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)

And in Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot failed: ${res.status}`);
const fs = await import('node:fs/promises');
await fs.writeFile('shot.webp', Buffer.from(await res.arrayBuffer()));

ScreenshotNeo includes full-page and element capture, device and viewport controls, retina scale, dark mode, PDF output, custom CSS and JavaScript, waits, request blocking, headers and cookies, geolocation and timezone, caching, signed links, asynchronous webhooks, bulk capture, and a usage API. Every feature is on every plan. The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots, with yearly billing providing two months free. Sign up for the free plan to try it without a card.

FAQ

Does this capability install or trust a certificate on the operating system?

No. It changes certificate handling inside the WebDriver browser session. It does not add a root certificate to the host, container, or operating-system trust store.

Can I use it for an HTTP URL?

The capability matters when Chrome encounters an invalid or expired TLS certificate during HTTPS navigation. Plain HTTP has no TLS certificate to validate, so this setting does not change HTTP behavior.

What is the safest way to prove the setting was applied?

Run a deliberately controlled test endpoint with a known invalid certificate, verify that the session reaches the page instead of stopping at the certificate interstitial, and then remove the permissive driver from tests that do not require it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Does this capability install or trust a certificate on the operating system?

No. It changes certificate handling inside the WebDriver browser session and does not modify the host, container, or operating-system trust store.

Can I use it for an HTTP URL?

It applies to invalid or expired TLS certificates during HTTPS navigation. Plain HTTP has no TLS certificate to validate.

How can I verify that the setting was applied?

Use a controlled endpoint with a deliberately invalid certificate, confirm the session reaches the page rather than the certificate interstitial, and keep the permissive driver limited to tests that need it.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.