lego Commands Reference

Single-binary ACME client written in Go with 200+ DNS providers. Examples target lego v5 (unified run, redesigned CLI).

📦 Installation

Homebrew

brew install lego

Go install

go install github.com/go-acme/lego/v5/cmd/lego@latest

Docker

docker run --rm goacme/lego -h

⚠️ Migrating from v4

Run this once before any other v5 command. Do not hand-edit the storage directory — layout and JSON format changed.

lego migrate
lego migrate --path /path/to/lego/storage
  • renew removed — use run
  • Flags belong on the subcommand: lego run --dns … -d …
  • list / revoke → certificates list / certificates revoke
  • --run-hook / --renew-hook → --deploy-hook

🚀 Issue & renew

HTTP-01

lego run --email [email protected] --http -d example.com

Obtains a cert if missing, renews when due. Port 80 must be reachable by the CA.

DNS-01 (Cloudflare)

CLOUDFLARE_DNS_API_TOKEN=... \
  lego run --email [email protected] --dns cloudflare \
    -d '*.example.com' -d example.com

Token needs Zone:Read and DNS:Edit. Prefer API tokens over Global API keys.

Deploy hook

lego run --email [email protected] --http -d example.com --deploy-hook='./deploy.sh'

📋 Manage certificates

lego certificates list
lego certificates revoke -d example.com
lego accounts list

🔗 See Also

Docs: go-acme.github.io/lego