Algolia v4 JavaScript client strict TLS validation and custom CA bundle handling in Electron/React Native
27.5K reputation · 24 Jul 2026, 09:56 UTC
Developers using Algolia's official JavaScript search client version 4 need to confirm whether the library honors custom certificate authority configurations when operating inside Electron or React Native wrappers. The v4 release enabled strict TLS verification by default and removed the previous fallback that tolerated self‑signed certificates, but the public API does not expose an option to inject a custom CA bundle.
Because the underlying HTTP layer relies on Node.js's https agent or the browser's fetch implementation, it is unclear if setting the NODE_EXTRA_CA_CERTS environment variable or adding roots to the platform's certificate store will be respected, leaving a gap in secure configuration for internal PKI or debugging proxy setups.
Does the Algolia v4 JavaScript client automatically pick up NODE_EXTRA_CA_CERTS in Node‑based environments? Does it trust custom roots added to the Electron or React Native certificate store when making HTTPS calls to the Algolia API?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
27,525 reputation · 24 Jul 2026, 17:29 UTC
The Algolia v4 JavaScript client does not expose a TLS‑option API; it simply uses whatever HTTP implementation the host provides. The important detail is which build of the client is actually loaded:
- When the code runs in a Node‑like context (e.g., Electron with nodeIntegration:true or a bundler targeting Node), the node build is used and the request goes through Node’s https module. In that case the process environment variable NODE_EXTRA_CA_CERTS (or a custom https.Agent) is respected.
- When the same code is bundled for the browser (the default for most web‑bundlers or when using the browser field), the browser build is used and the client relies on fetch/XMLHttpRequest. Those APIs ignore NODE_EXTRA_CA_CERTS and instead trust Chromium’s certificate store (Electron) or the platform’s SSL stack (React Native).
Therefore, setting NODE_EXTRA_CA_CERTS only helps if you are explicitly using the Node build inside Electron; otherwise you must add the CA to Chromium’s trust store (via session.setCertificateVerifyProc) or configure the native networking stack in React Native.