On a network, API keys and prompts should not cross the wire in plain text. There are three ways to add HTTPS; pick one.

OptionBest for
Built-in self-signed certificateAn office network with AI Suite apps and a few tools.
Your own certificateA network where clients already trust your internal certificate authority.
A reverse proxy or ingress in frontContainers, Kubernetes, and anything with a public or company domain name.

Built-in certificate

In the Windows app: Server → Server settings → Secure connection (HTTPS) → Use HTTPS (self-signed) for network serving. For containers and services: AISUITE_SERVER_TLS=1 or --tls.

The server creates a certificate valid for five years that names localhost, the computer name and its current network addresses, and renews it when an address changes. AI Suite apps pin its fingerprint the first time they connect and warn if it changes. For other tools, Download certificate exports aiserver.crt to install as trusted on client machines.

If HTTPS is turned on and the certificate cannot be prepared, a server bound to the network stops rather than fall back to plain HTTP.

Your own certificate

Secure connection (HTTPS) → Use my own certificate → Import certificate… accepts a PFX/P12 file with its password, or a PEM certificate and key. For services and containers set AISUITE_SERVER_TLS_CUSTOM=1 (or --tls-custom) as well, so the imported certificate is preferred.

Behind a reverse proxy

Terminate TLS at the proxy (nginx, Traefik, an ingress controller or a cloud load balancer) and forward to AI Server over the private network. Then:

  1. Set AISUITE_TRUST_PROXY=1 so the server uses the client address and scheme the proxy forwards. Rate limits and audit records then see the real client.
  2. Set AISUITE_TRUSTED_PROXIES to the proxy's addresses, for example 10.0.0.0/8. Only those senders may set forwarded headers.
  3. Turn off response buffering for /v1/ and allow read timeouts of at least 60 seconds, or streamed answers stop half-way.
location /v1/ {
    proxy_pass http://127.0.0.1:11436;
    proxy_buffering off;
    proxy_read_timeout 300s;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;
    proxy_set_header Host $host;
}

Note: Never set AISUITE_TRUST_PROXY on a server that clients can reach directly: they could then claim any address and slip past per-client limits.

The legacy listener stays HTTP

The optional legacy local-AI API on port 11434 is plain HTTP. On Free it listens on this computer only. It ends on 2026-12-31; see compatibility.

Questions

Do AI Suite apps need the certificate installed? +

No. They pin the server's certificate fingerprint on first connection and warn if it changes.

Does AI Server support mutual TLS? +

Not directly. Put a proxy that checks client certificates in front of it.