> Fetch clean Markdown by appending `.md` to any page URL under https://signalwire.com/docs or requesting it with the HTTP header `Accept: text/markdown`. The root index at https://signalwire.com/docs/llms.txt lists the available documentation indexes. # SslConfig > SSL/TLS configuration for HTTPS serving with HSTS support. [isconfigured]: /docs/server-sdks/reference/typescript/agents/configuration/ssl-config/is-configured [getcert]: /docs/server-sdks/reference/typescript/agents/configuration/ssl-config/get-cert [getkey]: /docs/server-sdks/reference/typescript/agents/configuration/ssl-config/get-key [gethstsheader]: /docs/server-sdks/reference/typescript/agents/configuration/ssl-config/get-hsts-header [getserveroptions]: /docs/server-sdks/reference/typescript/agents/configuration/ssl-config/get-server-options [hstsmiddleware]: /docs/server-sdks/reference/typescript/agents/configuration/ssl-config/hsts-middleware [env-vars]: /docs/server-sdks/reference/typescript/agents/configuration/environment-variables `SslConfig` manages SSL/TLS configuration for serving agents over HTTPS. It reads from explicit options or falls back to environment variables (`SWML_SSL_ENABLED`, `SWML_SSL_CERT_PATH`, `SWML_SSL_KEY_PATH`, `SWML_SSL_DOMAIN`). See [Environment Variables][env-vars] for the full list. ```typescript {3} import { SslConfig } from '@signalwire/sdk'; const ssl = new SslConfig({ certPath: './cert.pem', keyPath: './key.pem' }); ``` ## **Constructor** **`opts`** `SslOptions` Optional SSL configuration overrides. Any field omitted falls back to the corresponding `SWML_SSL_*` environment variable. Accepts the same keys as the [`Properties`](#properties) section below (`enabled`, `certPath`, `keyPath`, `domain`, `hsts`, `hstsMaxAge`). --- ## **Properties** **`enabled`** `boolean` Whether SSL is enabled. Falls back to `SWML_SSL_ENABLED` env var. --- **`certPath`** `string | null` Filesystem path to the PEM-encoded certificate. Falls back to `SWML_SSL_CERT_PATH`. --- **`keyPath`** `string | null` Filesystem path to the PEM-encoded private key. Falls back to `SWML_SSL_KEY_PATH`. --- **`domain`** `string | null` Domain name for HSTS headers. Falls back to `SWML_SSL_DOMAIN`. --- **`hsts`** `boolean` — default: true Whether to emit Strict-Transport-Security headers. --- **`hstsMaxAge`** `number` — default: 31536000 HSTS max-age value in seconds (default 1 year). --- ## **Methods** #### [isConfigured](/docs/server-sdks/reference/typescript/agents/configuration/ssl-config/is-configured) Check if SSL is fully configured with cert and key files. #### [getCert](/docs/server-sdks/reference/typescript/agents/configuration/ssl-config/get-cert) Read the PEM certificate from disk. #### [getKey](/docs/server-sdks/reference/typescript/agents/configuration/ssl-config/get-key) Read the PEM private key from disk. #### [getHstsHeader](/docs/server-sdks/reference/typescript/agents/configuration/ssl-config/get-hsts-header) Build the HSTS header value. #### [getServerOptions](/docs/server-sdks/reference/typescript/agents/configuration/ssl-config/get-server-options) Create options for Node.js https.createServer(). #### [hstsMiddleware](/docs/server-sdks/reference/typescript/agents/configuration/ssl-config/hsts-middleware) Hono middleware that appends HSTS headers. ## **Example** ```typescript {3,6-7} import { SslConfig } from '@signalwire/sdk'; const ssl = new SslConfig(); if (ssl.isConfigured()) { const opts = ssl.getServerOptions(); console.log('SSL ready with cert and key'); } else { console.log('SSL not configured — set SWML_SSL_ENABLED=true'); } ``` > SSL/TLS configuration for HTTPS serving with HSTS support. ## Docs - [getCert](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/ssl-config/get-cert.md): Read the PEM certificate file from disk. - [getHstsHeader](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/ssl-config/get-hsts-header.md): Build the Strict-Transport-Security header value. - [getKey](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/ssl-config/get-key.md): Read the PEM private key file from disk. - [getServerOptions](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/ssl-config/get-server-options.md): Create the options object for Node.js https.createServer(). - [hstsMiddleware](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/ssl-config/hsts-middleware.md): Hono middleware that appends HSTS headers to responses. - [isConfigured](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/ssl-config/is-configured.md): Check whether SSL is fully configured with cert and key files on disk.