Skip to main content

Does my WanderOS site come with HTTPS and an SSL certificate?

Yes. Every WanderOS site gets a free SSL certificate provisioned automatically through Cloudflare. No setup or renewal needed.

Quick answer

Yes. Every WanderOS site is served over HTTPS with a free SSL certificate provisioned automatically through Cloudflare. This applies to all WanderOS hosts. You don't need to buy, install, or renew anything. The certificate covers your .wander.site subdomain and any custom domain you connect, and renews automatically before it expires. If your site shows a "Not secure" warning, the most common cause is an in-progress domain connection — the certificate is issued shortly after your domain status moves to Active.


Do I need to buy an SSL certificate?

No. WanderOS provides SSL certificates for every site at no extra cost. The certificate is issued automatically through Cloudflare and covers:

  • Your default .wander.site URL

  • Any custom domain you connect (apex and www)

You do not need to upload a certificate, configure renewal, or change any settings.


How long does it take for HTTPS to work after I connect a custom domain?

The certificate is provisioned automatically once your domain status moves to Active in Settings → Website → Domain. In most cases, HTTPS is live within minutes of activation. In rare cases, it can take up to a few hours.

If your domain is still Pending, the certificate has not been issued yet. See Why is my custom domain stuck on Pending in WanderOS? for next steps.


What if I see a "Not secure" warning in the browser?

A "Not secure" warning on your live site usually points to one of these causes:

  • The domain just connected. Wait 1 to 2 hours for the certificate to finish provisioning, then hard-refresh the page.

  • You're loading the site over http:// instead of https://. WanderOS automatically redirects HTTP to HTTPS. If your browser cached the insecure version, clear the cache or test in incognito.

  • A page on your site loads an external image, font, or script over http://. This is called "mixed content" and triggers the warning even though your page itself is secure. Update any external assets to use https://.

  • Your custom domain status is not Active. Check Settings → Website → Domain and follow the Pending troubleshooting article if needed.


Do I need to renew the certificate?

No. The certificate renews automatically through Cloudflare before each expiration. You will never need to take action.


Can I use my own SSL certificate?

WanderOS uses Cloudflare-managed certificates for every site and does not currently support uploading your own. The Cloudflare certificate is industry-standard and is accepted by all modern browsers, so for almost every host this is functionally identical to bringing your own.


Troubleshooting

  • "Not secure" warning right after connecting my domain: Wait 1 to 2 hours and hard-refresh.

  • Mixed content warning on a specific page: A section is loading an external image, font, or script over http://. Update the URL to https:// in the page editor.

  • Browser shows certificate error mentioning expired: Should not happen with auto-renewal, but if it does, contact Wander support immediately.

  • HTTPS works on yourbrand.com but not www.yourbrand.com (or vice versa): Both should be covered. Confirm both versions are listed in your DNS as pointing to WanderOS, then contact support if the issue persists.

Did this answer your question?