Where Does acme.sh Store Certs and Config?
Where acme.sh keeps account keys, certs, and logs under its home dir, and which files to actually deploy..
Last updated
acme.sh keeps everything under one home directory, defaulting to a dot folder in your home. Account keys, per-domain certificate folders, configs, and logs all branch from there. Custom flags relocate home, config, and cert trees independently.
The critical rule: deployed servers must use copies installed by the tool, never the internal files directly. Internal layout shifts between versions without warning. A daily cron drives renewals from this same home, so back it up whole. Losing it means reissuing everything.
Where acme.sh stores this, by platform
~/.acme.sh
Account keys, per-domain cert folders, configs, and logs branch from here. Override with home, config-home, and cert-home flags. Serve only installed copies elsewhere; internal files may restructure. Cron renewals run from this root.
Frequently asked questions
how do I use issued certs in nginx
Copy certs out with the install-cert command to real server paths, never serve from the home tree. Internal files may restructure between versions. Renewals update the deployed copies automatically through saved hooks.
how do I back up acme.sh
Archive the whole home directory with the cron job paused to capture keys, configs, and certs. Per-domain subfolders plus account conf travel together. Restoring means unpacking to the same home path and re-adding cron.
how do I move acme.sh directories
Reinstall with explicit home, config-home, and cert-home flags pointing at custom roots. Account keys and logs follow the same overrides. Defaults suit single-user servers; shared hosts isolate per tenant.
Notice an outdated path? Let us know.