Do SSL HTTPS requests on Localhost using backloop.dev certificates pointing to your local environment.
https://<any subdomain>.backloop.dev/ → https://localhost/
Any subdomain of *.backloop.dev points to localhost!
backloop.dev stopped publishing its certificate openly on 2026-09-04. A public certificate authority must revoke any certificate whose private key is published, and both of them did. https://backloop.dev explains it in full.
This plugin still works, and since
backloop.dev5.1.0 it works for everybody again. Two ways to get a certificate need no secret: bring one of your own, or use the shared self-signed certificate the package now falls back to. See Certificates below.
On version 1 of this plugin, your dev server is quietly serving a revoked certificate. The old
backloop.dev/pack.jsonwas left in place so that existing installs degrade instead of breaking, so nothing has visibly changed for you — but that certificate was revoked on 2026-07-31, it expires on 2026-10-29, and a client that checks revocation already rejects it. Nothing will replace it.Upgrade to version 2 of this plugin. It requires
backloop.dev5, which gets a certificate that is not revoked.vite-plugin-mkcert remains an excellent alternative, and is the better choice if you use Firefox. It installs a local root into your trust store, which is the trade-off backloop.dev existed to avoid, and the only one a public authority is not obliged to break.
npm install vite-plugin-backloop.dev --save-dev- Edit
vite.config.js- Add
import backloop from 'vite-plugin-backloop.dev' - Add
backloop('myHostName')to the plugins list
- Add
Example
// vite.config.js
import { defineConfig } from 'vite';
import backloop from 'vite-plugin-backloop.dev';
export default defineConfig({
plugins: [
// ..
backloop('myComputer')
],
// ..
});Launch viteJs in dev model npm run dev
Open https://myComputer.backloop.dev:<port>
The plugin applies to serve only and loads the certificate inside its hook, so
vite build neither needs a secret nor makes a request. Before 2.0.1 it imported the
certificate at module load: a build downloaded one for nothing, and on Node 22 or later
it failed outright with ERR_REQUIRE_ASYNC_MODULE, because Vite loads vite.config.js
with require() and the import pulled in a top-level await.
The plugin holds no certificate and no secret of its own. It uses whatever the
backloop.dev package finds, in this order.
The best option, and the one to use if Firefox is your development browser. Any
certificate covering *.backloop.dev will do:
mkcert -install
mkcert '*.backloop.dev' backloop.dev
export BACKLOOP_DEV_CERT=$PWD/_wildcard.backloop.dev+1.pem
export BACKLOOP_DEV_KEY=$PWD/_wildcard.backloop.dev+1-key.pemA backloop.dev.json in the project root works too, as
{ "cert": "...", "key": "..." } with paths relative to the file. Nothing is
downloaded, and no secret is involved.
With nothing configured, npm run dev downloads the shared self-signed certificate
from https://backloop.dev/public/ and tells you so. Your browser rejects it until
you install it once on this machine, which that page explains for macOS, Windows and
Linux. Firefox will not accept it at all, so use your own certificate there.
For the private setup this project became. Set BACKLOOPDEV in your environment or
{ "secret": "..." } in backloop.dev.json, and add that file to .gitignore.
Access is not open and there is no way to request a secret.
backloop.dev's README
covers every option, including BACKLOOP_DEV_CERTS_DIR.
- Pull requests are welcome