HTTPS on every app
Every app and every address is served over HTTPS, with certificates renewed for you.
Built on Caddy and Let's Encrypt
Plans: Every plan, including the free app
What you get
- HTTPS on every app, on every plan, including the free app
- Every address covered: whisk.page, previews, custom domains and business domains
- Certificates issued and renewed automatically
- Plain HTTP redirected to HTTPS
- HSTS on every response
- TLS 1.2 or newer only
How it works
Every address Whisk serves uses HTTPS, with no setting to turn on and no plan that leaves it out. That includes the free app, every preview, every custom domain and every business-wide domain. Requests to a plain HTTP address are redirected to HTTPS.
Certificates come from Let's Encrypt, the free and open certificate authority. Caddy, the open-source web server in front of every app, obtains and renews them. Addresses on whisk.page use wildcard certificates, and a custom domain gets its own certificate as soon as its DNS records are verified.
Every response carries an HSTS header, which tells browsers to use HTTPS only for that address. Connections must use TLS 1.2 or newer. App cookies are marked Secure, so browsers send them only over HTTPS.
Example
An HVAC contractor's service app is used by technicians on their phones over public mobile and hotel networks. Job notes and customer addresses are encrypted from the first page. Nobody at the company has ever had to buy, install or renew a certificate.
For your coding agent
whisk deploy # ends with the app's https:// address whisk domains list # each address with its certificate status
There is nothing to configure for HTTPS. Use relative links, since the app's address can change; the app rules cover this.