Skip to content

Caddy

Powerful, enterprise-ready open-source web server with automatic HTTPS.

Self-hostedNot yet verified
Report issueDemo online
Apache-2.0★ 60000

Open the official app on caddyserver.com

This tool is hosted by its maintainers. Click below to open caddyserver.com in a new tab — it's their official demo.

Browse developer tools →

What's next with Caddy?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Caddy?

Caddy is an open-source web server designed to simplify secure, reliable, and scalable website hosting. Its primary purpose is to automate the deployment of HTTPS with automatic TLS certificate management, eliminating the need for manual configuration of security protocols. Developers, DevOps engineers, and SaaS companies use Caddy to streamline their infrastructure, ensuring websites are encrypted by default without compromising performance. The tool solves the persistent challenge of maintaining valid TLS certificates, which is critical for modern web security. By integrating with the ACME protocol (via Let's Encrypt and other providers), Caddy reduces the complexity of securing custom domains, making HTTPS accessible even for non-experts. Its lightweight architecture and extensibility allow it to handle high-traffic sites while supporting advanced features like reverse proxying and load balancing.

How it works

Caddy is a fast, multi-platform HTTP/1-2-3 web server that prioritizes security through automatic HTTPS. It is built on Go (Golang) and runs on Linux, macOS, and Windows, offering a modern alternative to traditional servers like Nginx or Apache. The tool’s core purpose is to eliminate the complexity of managing TLS certificates. By default, it automatically provisions, renews, and revokes SSL/TLS certificates for all hosted domains, ensuring end-to-end encryption without manual intervention. Caddy’s On-Demand TLS feature allows it to dynamically obtain certificates during TLS handshakes, making it ideal for customer-owned domains. It scales efficiently, handling hundreds of thousands of sites or thousands of instances without performance degradation.

How to use it

  1. 1Install Caddy via package managers (e.g., `sudo apt install caddy` on Debian) or download binaries from the official repository. 2. Create a `Caddyfile` in the config directory, specifying domains and root directories. 3. Run `caddy run` to start the server, which will automatically provision HTTPS certificates. 4. Verify the setup using `curl -I https://yourdomain.com` to confirm HTTPS is active. Practical tips: Use the `Caddyfile` syntax to define routes, middleware, and TLS settings. For production, run Caddy as a service with `systemctl enable caddy` and monitor logs via `journalctl -u caddy` for troubleshooting.

What it can do

  • web server

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/caddyserver/caddy
  • license: Apache-2.0 — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Limited advanced HTTP/2 tuning options compared to Nginx or Apache
  • Smaller community and ecosystem compared to established servers like Nginx
  • Depends on external ACME clients for certificate issuance in some edge cases
  • Steeper learning curve for complex configurations requiring custom middleware
  • Lacks built-in load balancing without third-party plugins

Understanding the result

Powerful, enterprise-ready open-source web server with automatic HTTPS.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (Apache-2.0).
Built with
(caddyserver/caddy)
License
Apache-2.0
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with caddyserver/caddy. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
Apache-2.0
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is Caddy and how does it differ from traditional web servers?

Caddy is an open-source web server focused on automating HTTPS with automatic TLS certificate management. Unlike traditional servers like Nginx or Apache, it prioritizes simplicity and security by default, eliminating the need for manual certificate configuration. While Nginx and Apache require manual setup for HTTPS, Caddy integrates ACME protocol support out-of-the-box, making it ideal for developers seeking streamlined secure deployments.

How does Caddy handle TLS certificate issuance and renewal?

Caddy uses the ACME protocol (via Let's Encrypt or other providers) to automatically obtain and renew TLS certificates. When a domain is first served, Caddy initiates a challenge-response process to verify domain ownership. Once validated, it downloads the certificate and stores it securely. Renewals occur periodically, ensuring certificates remain valid without user intervention. This process is transparent and requires no manual steps for most use cases.

How do I configure Caddy to serve a static website with HTTPS?

Create a `Caddyfile` in the config directory with the following content: `example.com { root * /var/www/html tls }`. Replace `example.com` with your domain and `/var/www/html` with your site’s root directory. Run `caddy run` to start the server. Caddy will automatically generate and renew HTTPS certificates, serving your site securely. Test with `curl -k https://example.com` to confirm HTTPS is active.

How does Caddy compare to Nginx or Apache for HTTPS deployment?

Caddy simplifies HTTPS deployment by automating certificate management, whereas Nginx and Apache require manual configuration of TLS settings and certificate renewal. Nginx offers more granular control over HTTP/2 and advanced proxying, but Caddy’s built-in ACME integration reduces operational overhead. For developers prioritizing ease of use, Caddy is superior, while Nginx remains preferred for complex, high-performance requirements.

What should I do if Caddy fails to obtain a TLS certificate?

Common issues include incorrect domain DNS settings or firewall restrictions. Verify the domain’s A record points to your server’s IP, and ensure port 80/443 is open. Check the Caddy logs (`caddy logs`) for error details. If ACME challenges fail, temporarily disable firewall rules or use a different challenge type (e.g., DNS-01) via plugins. Ensure the server’s clock is synchronized to prevent validation failures due to time drift.

Spotted something wrong with Caddy, or want to maintain it? See how to help.