{"id":"letsencrypt-api","name":"Let's Encrypt (ACME)","homepage":"https://letsencrypt.org","repo_url":"https://github.com/letsencrypt/boulder","category":"security","subcategories":["tls","certificates","pki"],"tags":["letsencrypt","tls","ssl","certificates","acme","free","https"],"what_it_does":"Free, automated certificate authority that issues TLS/SSL certificates via the ACME protocol, enabling agents and automation to programmatically obtain, renew, and revoke certificates without manual intervention.","use_cases":["Automatically issuing TLS certificates for new domain/service deployments","Programmatic certificate renewal before expiry in infrastructure automation","Wildcard certificate issuance via DNS-01 challenge for entire domain coverage","Certificate revocation when services are decommissioned","Building certificate lifecycle management into agent-driven infrastructure pipelines"],"not_for":["EV (Extended Validation) certificates requiring organizational identity display","Code signing certificates (Let's Encrypt only issues domain validation certificates)","Certificates with validity longer than 90 days (LE limit; use DigiCert for longer certs)","Internal PKI or private network certificates (no internal hostnames or IPs)"],"best_when":"You need free, automated TLS certificate management for public-facing domains and want to eliminate manual certificate procurement and renewal entirely.","avoid_when":"You need EV certificates, code signing, internal PKI, or certificates valid longer than 90 days.","alternatives":[{"id":"vault-api","reason":"HashiCorp Vault provides internal PKI for private certificates and secrets management beyond public TLS"},{"id":"digicert-api","reason":"For EV certificates, code signing, or certs valid longer than 90 days"},{"id":"aws-acm-api","reason":"AWS Certificate Manager provides free auto-renewing certs for AWS-hosted services without ACME complexity"}],"af_score":78.8,"security_score":null,"reliability_score":null,"package_type":"mcp_server","discovery_source":["github"],"priority":"low","status":"evaluated","version_evaluated":"current","last_evaluated":"2026-03-01T09:50:05.782698+00:00","performance":{"latency_p50_ms":500,"latency_p99_ms":2000,"uptime_sla_percent":99.9,"rate_limits":"50 certificates per registered domain per week; 5 failed validations per domain per hour","data_source":"llm_estimated","measured_on":null}}