Running a HTTPS server on the device itself is handy when you want to test web‑apps, API calls or progressive web apps without exposing anything to the internet. The tutorial assumes you have a modern Android version (Android 9+), at least 2 GB of free storage, and a stable Wi‑Fi connection. All actions are performed without rooting the device.
Open the Termux app from the Play Store (or F-Droid for the latest build). Accept the permissions and let the initial setup finish.
Termux provides a Linux‑like environment where we can run apt, python and openssl.
Update the package repository and upgrade existing packages:
pkg update && pkg upgrade -y
This ensures you have the latest security patches.
Install the tools we need:
pkg install python openssl -y
python will be used for a tiny HTTPS server, while openssl creates the certificate.
We will create a private key and a certificate that is valid for a few days – enough for development.
Create a directory to keep the crypto material tidy:
mkdir -p ~/https-demo/certs && cd ~/https-demo/certs
Generate a 2048‑bit RSA private key:
openssl genrsa -out dev.key 2048
Create a configuration file (dev.cnf) that defines the subject fields. This step is optional but helps avoid interactive prompts:
cat > dev.cnf <<'EOF'
[ req ]
default_bits = 2048
prompt = no
default_md = sha256
distinguished_name = dn
[ dn ]
C = US
ST = State
L = City
O = MyDevOrg
OU = Development
CN = 10.0.2.2
EOF
Replace CN with the IP address or hostname you plan to use. For a device‑only server, 10.0.2.2 (the default Android emulator host) works, but you can also use 127.0.0.1 or your Wi‑Fi IP.
Generate a self‑signed X.509 certificate valid for 30 days:
openssl req -new -x509 -key dev.key -out dev.crt -days 30 -config dev.cnf
The command produces dev.crt (public cert) and dev.key (private key).
Python’s standard library can serve static files over HTTPS with a single command.
Navigate to a folder that contains the files you want to serve, e.g. a simple index.html:
mkdir -p ~/https-demo/www && echo "Hello from Android HTTPS
" > ~/https-demo/www/index.html
cd ~/https-demo/www
Start the HTTPS server on port 8443 (a non‑privileged port that does not require root):
python -m http.server 8443 --bind 0.0.0.0 --directory . --certfile ~/https-demo/certs/dev.crt --keyfile ~/https-demo/certs/dev.key
The --bind 0.0.0.0 flag makes the server reachable from other devices on the same Wi‑Fi network.
Serving HTTPS on 0.0.0.0 port 8443 (https://0.0.0.0:8443/) ...By default Android blocks connections to servers with unknown certificates. Adding the cert to the user‑trusted store removes the warning for your own apps and browsers.
Copy the certificate file to a location accessible by the Android Settings app:
cp ~/https-demo/certs/dev.crt /sdcard/Download/
Now open the Files app (or any file manager) and locate dev.crt in the Download folder.
Tap the file. Android will display a prompt: “Install certificate?” Choose VPN & apps (or Wi‑Fi on older versions) and give the certificate a recognizable name, e.g., AndroidDevHTTPS.
You may be asked to set a device lock screen PIN/pattern if you haven’t already – this is required for user‑installed certificates.
Verify installation:
Settings > Security > Encryption & credentials > Trusted credentials.With the server running and the cert trusted, you can now browse to it from the same device or any other device on the same network.
Find the IP address of your Android phone:
ip addr show wlan0 | grep inet
Look for a line like inet 192.168.1.42/24. The address before the slash (e.g., 192.168.1.42) is what you’ll use.
On the same phone, open Chrome and navigate to https://192.168.1.42:8443. You should see the Hello from Android HTTPS page without any “Your connection is not private” warning.
From a laptop on the same Wi‑Fi, open a browser and go to the same URL. The page should load, and the lock icon should indicate a secure connection (because the laptop trusts the certificate only if you import it; otherwise you’ll see a warning, which is expected).
If you hit a snag, check the following items.
netstat -tuln | grep 8443 to verify.Settings > Biometrics & security > Install from storage.tsu (root) – but the tutorial avoids root.Once the basic HTTPS server works, you can adapt it for more advanced workflows.
nodejs in Termux (pkg install nodejs) and run node server.js with the same --cert and --key flags.nginx (pkg install nginx) and configure it to point to the Python server. This lets you host multiple virtual hosts on one device.~/.termux/boot/start-https.sh) that launches the server when the device boots. Enable Termux:Boot from the Play Store to make it work.When the development session ends, stop the server with Ctrl+C in the Termux session. If you no longer need the certificate, remove it from the trusted store:
Settings > Security > Encryption & credentials > Trusted credentials > User > AndroidDevHTTPS > Remove
Delete the files to free space:
rm -rf ~/https-demo
That’s it – you now have a fully functional, locally trusted HTTPS server running directly on Android, ready for web‑app testing, API prototyping, or any scenario where encrypted local traffic is required.









