How Shopify Moved Millions of Storefronts to HTTPS
Shopify began sponsoring Let’s Encrypt in 2015, but the relationship that would eventually secure more than 4.5 million domains traces back to an earlier challenge: taking every merchant storefront fully onto HTTPS.
When the SSL team first explored automated certificate provisioning a few years earlier, the market offered little help. A handful of certificate authorities had APIs, but they were designed around a human buyer: purchase a certificate, download it, install it. Error handling was built for that workflow too. Responses were human-readable messages rather than defined error codes, useful when a person could read them, useless in a fully automated pipeline. For Shopify, automation was the whole point. All 650,000 domains at the time were to receive certificates, provisioned and renewed with no merchant interaction.
An Open Specification Changes the Calculus
Word about Let’s Encrypt in 2014 focused almost entirely on free certificates, which were still expensive elsewhere. The more significant development was the ACME protocol, an attempt to standardize and automate how software talks to certificate authorities. In the summer of 2015, before launch, one engineer began drafting a Ruby implementation of the ACME client protocol to explore the spec.
Writing code against a published specification was a different experience than integrating with the established providers. Specifications are dry reading, but when you are automating hundreds of thousands of domains you do not control, you need to know every exception case is accounted for. That early work led Shopify to reach out and agree to sponsor Let’s Encrypt—initially without plans to use the service. The shared interest was the open web and lowering the barrier to entry with technology.
The openness changed support dynamics as well. Typical certificate authority interactions meant an account manager forwarding questions to a technical team, often a team that did not write the software they ran. With Let’s Encrypt, questions on IRC were answered with links to the actual implementation in GitHub. Bugs or inconsistencies reported in the specification resulted in tags on the pull request that fixed them.
Throttles, Napkin Math, and a Backup Plan
Shopify began rolling out its automated provisioning system in late November 2015 and hit throttling limits from its initial providers immediately. The numbers were stark: at the imposed rate, provisioning every domain would take roughly 100 days. The process ran through the holidays, and Shopify launched all-store HTTPS in February 2016.
The bulk migration was done, and new domains arriving at a slower pace combined with renewals was manageable for a while. The real concern was emergency rotation. If private keys needed to be rotated or a certificate chain were compromised, a 100-day provisioning rate was far too slow to respond to an incident.
That drove the decision to bring Let’s Encrypt in as a backup certificate authority. Rolling it out took hours rather than months. Errors were predictable because both the specification and the server implementation were open source, making it possible to investigate unexpected behavior directly. The reliability was enough that Let’s Encrypt became the primary authority.
The advantage of a standardized protocol has compounded since. Because the system is built around ACME, a certificate authority supporting the protocol can be swapped or added without redesigning infrastructure. The API was designed for full automation from the start, which makes it more dependable than the older, human-oriented interfaces.



