go-acme/lego

Let's Encrypt/ACME client and library written in Go

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 59 minutes ago
Added to GitGenius on September 6th, 2026
Created on June 8th, 2015
Open Issues & Pull Requests: 106 (+0)
GitHub issues: Enabled
Number of forks: 1,165
Total Stargazers: 9,862 (+0)
Total Subscribers: 95 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 0.6 hours
Mean response time: 115.4 days
90th percentile: 76.1 days
Tracked items: 454

How this project is maintained

Around half of the issues opened in the past year never receive a reply. 96% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. Only 6% of issues opened in the past year have been closed. Three people close 92% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 51
New in 7 days: 7
Closed in 7 days: 8
Avg open age: 948 days
Stale 30+ days: 42
Stale 90+ days: 34

Recent activity

Opened in 7 days: 7
Closed in 7 days: 8
Comments in 7 days: 2
Events in 7 days: 9

Top labels

  • area/dnsprovider (216)
  • enhancement (189)
  • new-provider (125)
  • question (110)
  • bug (70)
  • area/cli (62)
  • waiting-for/contrib-feedback (29)
  • declined (22)

Detailed Description

Lego is an ACME client and library written in Go that automates certificate issuance and renewal with Let's Encrypt and other ACME-compatible certificate authorities.

The tool solves the problem of obtaining and managing TLS certificates by implementing the ACME protocol, which allows automated interaction with certificate authorities. It supports multiple challenge types—HTTP, DNS, and TLS ALPN—to prove domain ownership, with DNS validation backed by integrations with over two hundred DNS providers. The library can obtain certificates from scratch or from an existing certificate signing request, renew expiring certificates, and revoke certificates when needed. It handles SAN certificates and includes CNAME support for delegated validation.

Lego suits projects that need programmatic certificate management in Go applications or require a command-line tool for certificate automation in deployment pipelines. It works well for infrastructure that already uses Let's Encrypt or other ACME CAs and needs flexible challenge solving. The tool is particularly valuable when DNS-based validation is preferred, given the breadth of supported DNS providers. Developers can also write custom challenge solvers to integrate with proprietary systems.

The project maintains active engagement with ACME specification evolution, implementing support for multiple RFCs including those covering TLS ALPN challenges, IP address certificates, renewal information extensions, and emerging draft specifications for profiles and persistent DNS validation. The maintainers respond to requests for new DNS provider integrations through a structured issue template, indicating systematic onboarding of additional integrations.