Answer first
No, the Algolia JavaScript search client v4 does not expose TLS, certificate validation or CA bundle options. The client delegates transport to the host runtime’s fetch/XMLHttpRequest implementation. TLS validation is therefore controlled by Electron’s Node/Chromium runtime or React Native’s native networking stack, not by Algolia configuration.
Confirmed fact: the v4 public API has no parameter to inject a custom CA bundle and strict TLS verification is enforced by the underlying runtime. Likely behavior depends on which client build and runtime you are actually using.
Electron
Confirmed: when Node integration is available and the Node build of the client is used, HTTPS follows Node’s https module. TLS validation and custom CAs can only be influenced via runtime-level options, not via client constructor parameters.
Likely: Node’s TLS stack respects NODE_EXTRA_CA_CERTS and the system/OS trust store. Chromium-based fetch used by the browser build of the client respects Chromium’s certificate store, not Node’s process environment.
Steps needed for this case:
- Confirm which entry point is imported. Node build vs browser build changes the transport.
- If you are on Node in Electron, apply a runtime-wide https.Agent with the desired ca before initializing the client, or rely on NODE_EXTRA_CA_CERTS being set for the Electron process. Do not disable rejectUnauthorized globally.
- Test handshake behavior with a known self-signed host to verify the runtime is picking up the CA.
React Native
Likely: JS-level fetch is backed by iOS URLSession and Android OkHttp. The Algolia JS client cannot inject a custom CA bundle from JavaScript.
Confirmed fact: custom trust anchors require native platform configuration, such as network security config on Android or ATS settings on iOS, or routing through a trusted proxy that presents a publicly trusted certificate to the app.
Steps needed for this case:
- Do not attempt CA injection via the Algolia client.
- Evaluate native SSL configuration or a trusted TLS termination proxy for internal PKI or debugging proxy setups.
- Verify TLS errors in platform network logs to confirm the failure is at the native layer.
One missing diagnostic that changes the recommendation: which Algolia client entry point is used in Electron, the browser build versus the Node build, and whether nodeIntegration/contextIsolation is enabled. That determines if Node https options are reachable at all.
Assumptions and uncertainty: exact transport used by the specific v4 release you run can vary with Node version and bundler. Runtime-wide HTTPS agent changes in Electron affect all Node requests in the process, not only Algolia calls. React Native native network security changes require an app rebuild and may affect store review compliance. Disabling strict TLS validation is a security risk and should not be used in production.