Set Up a Local HTTPS Server on Android with Termux

12 min read Step‑by‑step guide to install Termux, generate a self‑signed certificate, run a HTTPS server on your Android device and make the system trust it for secure local development. September 28, 2026 01:00 How to Set Up a Local HTTPS Development Server on Android Using Termux

Before you start

Running a HTTPS server on the device itself is handy when you want to test web‑apps, API calls or progressive web apps without exposing anything to the internet. The tutorial assumes you have a modern Android version (Android 9+), at least 2 GB of free storage, and a stable Wi‑Fi connection. All actions are performed without rooting the device.

Why a self‑signed certificate? A self‑signed certificate lets you encrypt traffic locally without buying a CA‑signed cert. Android will not trust it automatically, so we will add the certificate to the user‑trusted store.
Security note: Never use this setup for production or expose the server to public networks. The certificate is not verified by a trusted authority.

1. Install Termux and required packages

  1. Open the Termux app from the Play Store (or F-Droid for the latest build). Accept the permissions and let the initial setup finish.

    Termux provides a Linux‑like environment where we can run apt, python and openssl.

  2. Update the package repository and upgrade existing packages:

    pkg update && pkg upgrade -y

    This ensures you have the latest security patches.

  3. Install the tools we need:

    pkg install python openssl -y

    python will be used for a tiny HTTPS server, while openssl creates the certificate.

2. Generate a self‑signed certificate

We will create a private key and a certificate that is valid for a few days – enough for development.

  1. Create a directory to keep the crypto material tidy:

    mkdir -p ~/https-demo/certs && cd ~/https-demo/certs
  2. Generate a 2048‑bit RSA private key:

    openssl genrsa -out dev.key 2048
  3. Create a configuration file (dev.cnf) that defines the subject fields. This step is optional but helps avoid interactive prompts:

    cat > dev.cnf <<'EOF'
    [ req ]
    default_bits       = 2048
    prompt             = no
    default_md         = sha256
    distinguished_name = dn
    [ dn ]
    C  = US
    ST = State
    L  = City
    O  = MyDevOrg
    OU = Development
    CN = 10.0.2.2
    EOF
    

    Replace CN with the IP address or hostname you plan to use. For a device‑only server, 10.0.2.2 (the default Android emulator host) works, but you can also use 127.0.0.1 or your Wi‑Fi IP.

  4. Generate a self‑signed X.509 certificate valid for 30 days:

    openssl req -new -x509 -key dev.key -out dev.crt -days 30 -config dev.cnf

    The command produces dev.crt (public cert) and dev.key (private key).

Tip: Keep the private key safe. Do not share it with anyone.

3. Run a simple HTTPS server

Python’s standard library can serve static files over HTTPS with a single command.

  1. Navigate to a folder that contains the files you want to serve, e.g. a simple index.html:

    mkdir -p ~/https-demo/www && echo "

    Hello from Android HTTPS

    " > ~/https-demo/www/index.html cd ~/https-demo/www
  2. Start the HTTPS server on port 8443 (a non‑privileged port that does not require root):

    python -m http.server 8443 --bind 0.0.0.0 --directory . --certfile ~/https-demo/certs/dev.crt --keyfile ~/https-demo/certs/dev.key

    The --bind 0.0.0.0 flag makes the server reachable from other devices on the same Wi‑Fi network.

What you should see: Terminal output similar to
Serving HTTPS on 0.0.0.0 port 8443 (https://0.0.0.0:8443/) ...

4. Make Android trust the self‑signed certificate

By default Android blocks connections to servers with unknown certificates. Adding the cert to the user‑trusted store removes the warning for your own apps and browsers.

  1. Copy the certificate file to a location accessible by the Android Settings app:

    cp ~/https-demo/certs/dev.crt /sdcard/Download/

    Now open the Files app (or any file manager) and locate dev.crt in the Download folder.

  2. Tap the file. Android will display a prompt: “Install certificate?” Choose VPN & apps (or Wi‑Fi on older versions) and give the certificate a recognizable name, e.g., AndroidDevHTTPS.

    You may be asked to set a device lock screen PIN/pattern if you haven’t already – this is required for user‑installed certificates.

  3. Verify installation:

    • Go to Settings > Security > Encryption & credentials > Trusted credentials.
    • Switch to the User tab and look for the name you gave.
Warning: User‑installed certificates are trusted by all apps that opt‑in to user credentials. If you later remove the cert, apps that previously accepted it may need to be restarted.

5. Test the HTTPS server

With the server running and the cert trusted, you can now browse to it from the same device or any other device on the same network.

  1. Find the IP address of your Android phone:

    ip addr show wlan0 | grep inet

    Look for a line like inet 192.168.1.42/24. The address before the slash (e.g., 192.168.1.42) is what you’ll use.

  2. On the same phone, open Chrome and navigate to https://192.168.1.42:8443. You should see the Hello from Android HTTPS page without any “Your connection is not private” warning.

  3. From a laptop on the same Wi‑Fi, open a browser and go to the same URL. The page should load, and the lock icon should indicate a secure connection (because the laptop trusts the certificate only if you import it; otherwise you’ll see a warning, which is expected).

6. Common troubleshooting

If you hit a snag, check the following items.

  • Server does not start: Ensure the port (8443) is not already in use. Use netstat -tuln | grep 8443 to verify.
  • Browser shows “certificate not trusted” on the phone: Double‑check that the certificate was installed under the correct user profile (VPN & apps). Some OEM skins place the option under Settings > Biometrics & security > Install from storage.
  • Cannot reach the server from another device: Verify the phone’s Wi‑Fi IP (step 5‑1) and ensure the firewall on the phone (if any) allows inbound connections on 8443. Android’s built‑in firewall is usually permissive on the Wi‑Fi interface.
  • Python reports “[Errno 13] Permission denied”: You might be trying to bind to a privileged port (< 1024). Use a higher port like 8443 or run Termux with tsu (root) – but the tutorial avoids root.
  • Certificate expires: The cert we generated is valid for 30 days. After expiration, browsers will reject it. Regenerate the cert using the same steps, then reinstall it.

7. Extending the setup

Once the basic HTTPS server works, you can adapt it for more advanced workflows.

  • Serve a Node.js app: Install nodejs in Termux (pkg install nodejs) and run node server.js with the same --cert and --key flags.
  • Use a reverse proxy: Install nginx (pkg install nginx) and configure it to point to the Python server. This lets you host multiple virtual hosts on one device.
  • Automate start‑up: Create a Termux boot script (~/.termux/boot/start-https.sh) that launches the server when the device boots. Enable Termux:Boot from the Play Store to make it work.

8. Clean‑up when you’re done

When the development session ends, stop the server with Ctrl+C in the Termux session. If you no longer need the certificate, remove it from the trusted store:

Settings > Security > Encryption & credentials > Trusted credentials > User > AndroidDevHTTPS > Remove

Delete the files to free space:

rm -rf ~/https-demo

That’s it – you now have a fully functional, locally trusted HTTPS server running directly on Android, ready for web‑app testing, API prototyping, or any scenario where encrypted local traffic is required.

User Comments (0)

Add Comment
We'll never share your email with anyone else.