Tickd.ai
API errors

OpenAI API SSL Verification Failed: How to Fix

Updated 10/6/2026

Why SSL verification fails on the OpenAI API

When connecting to the OpenAI API via python-openai or node-openai, your client system must validate OpenAI's SSL/TLS certificates. If your local system lacks updated root certificates, sits behind an SSL-intercepting corporate firewall, or uses an outdated Python environment, the connection fails. This typically manifests as SSLError, CertificateVerifyFailed, or UNABLE_TO_VERIFY_LEAF_SIGNATURE.

Follow these troubleshooting steps to resolve local certificate validation issues and restore API access.

1. Run the macOS certificate installation command

If you are on macOS and installed Python via the official package installer or Homebrew, your environment may lack access to system-level root certificates.

1. Open your terminal. 2. Run the command matching your installed Python version: `bash open "/Applications/Python 3.11/Install Certificates.command" ` *(Replace 3.11 with your installed version, such as 3.10 or 3.12)* 3. If you do not know where your Python installation lives, find it using this command: `bash find /Applications -name "Install Certificates.command" ` 4. Execute the command file. This script installs the certifi package and configures your Python installation to point to the correct macOS system certificates.

2. Force upgrade the certifi package

The Python OpenAI SDK uses the certifi package to reference a curated collection of Root Certificates. An outdated version of certifi will cause verification failures if OpenAI updates its root certificate authority.

1. Activate your local virtual environment (if you are using one). 2. Force an upgrade of your certificates: `bash pip install --upgrade certifi ` 3. Verify where your active Python runtime is loading its root certificates: `python import certifi print(certifi.where()) ` 4. Ensure the output path points to the updated file within your active virtual environment.

3. Configure corporate proxies and firewalls

If your local development machine is on a corporate network, your company likely uses deep packet inspection via an SSL proxy (such as Zscaler or Cisco Umbrella). This proxies outgoing traffic and signs it with a custom self-signed corporate certificate, which the OpenAI SDK rejects by default.

1. Export your company's root SSL certificate in .pem format. 2. Set your environment variables to point directly to your corporate bundle path: `bash export REQUESTS_CA_BUNDLE="/path/to/corporate-cert.pem" export SSL_CERT_FILE="/path/to/corporate-cert.pem" ` 3. For Windows Command Prompt: `cmd set REQUESTS_CA_BUNDLE=C:\path\to\corporate-cert.pem ` 4. For Windows PowerShell: `powershell $env:REQUESTS_CA_BUNDLE="C:\path\to\corporate-cert.pem" `

4. Upgrade the OpenAI SDK and HTTP client

Outdated client versions occasionally use obsolete SSL protocols. Upgrading the SDK and the underlying connection utilities ensures compatibility with OpenAI's TLS 1.3 standards.

1. Upgrade the Python OpenAI package and the underlying connection engine httpx: `bash pip install --upgrade openai httpx ` 2. For Node.js, upgrade the official package: `bash npm update openai ` 3. If you run your code behind an authenticating network proxy, explicitly instantiate the Python client using a proxy configuration rather than relying on system environment detection: `python import httpx from openai import OpenAI

client = OpenAI( http_client=httpx.Client( proxy="http://your-proxy-address:port", verify=True ) ) `

5. Bypass SSL validation (Testing only)

If you need to verify whether the root cause is purely local certificate validation or a wider routing problem, you can temporarily instruct the client to skip SSL verification. Never run this configuration in production environments.

For Python: `python import httpx from openai import OpenAI

Instantiate a client that ignores SSL verification unsafe_client = OpenAI( http_client=httpx.Client(verify=False) )

response = unsafe_client.chat.completions.create( model="gpt-4o-mini", messages=[{"role": "user", "content": "Test ping"}] ) print(response.choices[0].message.content) `

For Node.js: Disable TLS checking via your terminal configuration before executing your script: `bash NODE_TLS_REJECT_UNAUTHORIZED=0 node your-app.js `

When to escalate

If you have updated certificates, verified network traffic on a public hotspot (bypassing corporate networks), and still receive SSL connection errors: * Verify that your DNS configuration isn't intercepting or hijacking the api.openai.com address. Run nslookup api.openai.com to check resolving IPs. * Check the official [OpenAI Status Page](https://status.openai.com) to verify if there is an ongoing incident with their edge servers or Content Delivery Network (CDN). * If you are on a restricted network, contact your IT Administrator or Security Operations team to have them whitelist *.openai.com and bypass SSL decryption rules for API endpoints.

While you're here

Tickd is more than troubleshooting — these three are free and take seconds.

Agent BuilderDesign your own AI agent and export it to ChatGPT, Claude, Gemini or Grok.Build one free