Automatic HTTPS certificate: why you never need to buy one again
The old way, and why it was painful
The automated way: what changed
How "on-demand" issuance actually works
What happens after your domain verifies
Ownership is proven
The DNS ownership check passes — see connecting a domain for exactly what that involves.
The first real request triggers issuance
The moment traffic for your domain reaches the edge, a certificate is requested from the public certificate authority on your behalf.
The certificate is installed automatically
There's no file to download and no server configuration to touch — the edge holds and serves the certificate itself.
Renewal happens in the background
The edge tracks its own certificates' expiry and renews them ahead of time, without any action from you, indefinitely.
How Olmira handles this
Olmira's edge runs exactly this model: on-demand TLS gated by domain verification, issued by a public certificate authority once the domain is confirmed yours. There is no certificate file anywhere in Control because there is nothing to manage. A status of "pending" usually just means no real visitor has hit the domain since it verified — it is designed to sit at "pending" rather than flip to an error on a momentary hiccup, so it is safe to ignore while it settles.
Your free yourname.olmira.app address is HTTPS-secured from the moment you publish, and a custom domain gets the identical automatic treatment the instant it verifies — see connecting a domain for the DNS step that unlocks it, and custom domains for what each plan includes.
No. On Olmira, HTTPS is included with your free address and with every connected custom domain — part of the domain working at all, never a separate line item.
That issuance hasn't been confirmed as complete yet — often simply because no real visitor has reached the domain since it verified, since on-demand issuance is triggered by that first real request. It's not an error state, and it resolves itself.
Yes. A certificate issued by a public certificate authority through the automated protocol is trusted by every standard browser exactly the same way a purchased one is — the validation being automated doesn't make it weaker, it makes it consistent.
Nothing needs to be manually revoked or cleaned up on your end — an on-demand certificate for a domain that's no longer being served is simply left to expire unused on the edge's own renewal cycle.
No — that's the entire point of automated issuance. Renewal happens ahead of the expiry date without any reminder, calendar entry, or action required from you.