Skip to content
Niftyhelp 2026.10.1-beta.1 Support

Beta This is the help for Nifty 2026.10.1-beta.1, which isn't released yet. Help for the current release

HTTPS

Serve Nifty over HTTPS with your own certificate or a free one from Let's Encrypt.

On this page

Nifty can serve HTTPS itself, one way at a time. Pick the one that fits:

Way Use it when
Let's Encrypt The internet reaches this machine at your domain
Let's Encrypt over Cloudflare DNS It doesn't (a home or office server), and the domain's DNS is on Cloudflare
Certificate files You already have a certificate, from certbot or elsewhere
Tailscale Only your own devices need to reach it
Behind a proxy Caddy, nginx or similar already handles HTTPS

install.sh sets up any of these for you (Install on Linux). The settings below go in /etc/nifty.env; restart Nifty after changing them (sudo systemctl restart nifty).

Note:

Plain http:// works off this machine, but your password then crosses the network unencrypted, and Nifty warns in its log as it starts.

Let's Encrypt

NIFTY_ORIGIN=https://notes.example.com
NIFTY_LISTEN=:443
NIFTY_ACME=tls
[email protected]    # optional
  • The domain's DNS points at this machine, and the internet reaches it on port 443 or 80.
  • Nifty gets the certificate on the first visit, so that one takes a few seconds. It renews 30 days before expiry.
  • It redirects http:// on port 80 to HTTPS.

Let's Encrypt over Cloudflare DNS

For a machine the internet can't reach, such as a home server or one on your tailnet. Nifty proves the domain is yours by adding a DNS record through Cloudflare's API.

  1. In Cloudflare, open My Profile → API Tokens and create a token with Zone → DNS → Edit on this domain's zone only.

  2. Point the domain at this machine's local or tailnet address, so your devices find it.

  3. Add the settings, then restart Nifty:

    NIFTY_ORIGIN=https://notes.example.com
    NIFTY_LISTEN=:443
    NIFTY_ACME=cloudflare
    NIFTY_CLOUDFLARE_API_TOKEN=…

The certificate usually arrives within two minutes of starting. The token works only from the environment, never as a flag: keep /etc/nifty.env as install.sh writes it, root:nifty, mode 640.

Certificate files

NIFTY_ORIGIN=https://notes.example.com
NIFTY_LISTEN=:443
NIFTY_TLS_CERT=/etc/ssl/nifty/fullchain.pem
NIFTY_TLS_KEY=/etc/ssl/nifty/privkey.pem
  • PEM files: the full chain, and its private key. Nifty won't start if they don't match, have expired or don't cover the origin's host.
  • Nifty re-reads them within a minute of a change, so renewals need no restart. If a new pair doesn't load, it keeps the old one and logs why.
  • The nifty user must be able to read them, and they can't live under /home or /root. For certbot's files: sudo setfacl -m u:nifty:r <file>, plus u:nifty:x on each directory above it.

Ports 443 and 80

Ports below 1024 need a systemd drop-in. install.sh adds it; to add it yourself, create /etc/systemd/system/nifty.service.d/ports.conf:

[Service]
AmbientCapabilities=CAP_NET_BIND_SERVICE
CapabilityBoundingSet=CAP_NET_BIND_SERVICE

Then sudo systemctl daemon-reload && sudo systemctl restart nifty. To redirect from somewhere other than port 80, or not at all, set NIFTY_REDIRECT_HTTP (Configuration).

Try it first

Let's Encrypt limits how often it issues certificates. While you experiment, use its staging server (browsers won't trust the certificate):

NIFTY_ACME_DIRECTORY=https://acme-staging-v02.api.letsencrypt.org/directory

When it works, remove that line and restart. Nifty then gets a real certificate.

If no certificate comes

Every step is in the log, as lines starting tls::

journalctl -u nifty | grep tls:

A failure logs Let's Encrypt's reason, the fix where it's known, and when Nifty tries again (an hour later). Fix the cause and restart to try at once. Nifty warns in the log when a certificate has less than 14 days left.

Menu

2026.10.1-beta.1Contact support