Axios ignores NODE_TLS_REJECT_UNAUTHORIZED when a custom httpsAgent is provided
24K reputation · 14 Jul 2026, 16:34 UTC
When using Axios with a custom httpsAgent, the library does not consult the NODE_TLS_REJECT_UNAUTHORIZED environment variable, causing certificate validation to behave as if rejectUnauthorized: true even when the variable is set to 0. This behavior can lead to unexpected UNABLE_TO_VERIFY_LEAF_SIGNATURE errors in environments that rely on the variable to relax TLS checks for self‑signed or internal certificates. The goal is to clarify whether Axios should automatically honor NODE_TLS_REJECT_UNAUTHORIZED when a custom agent is supplied, or whether developers must explicitly configure the agent’s rejectUnauthorized option. Understanding the intended contract helps avoid silent security‑related failures and informs decisions about wrapper libraries or interceptors that manage TLS settings.
Should Axios automatically read NODE_TLS_REJECT_UNAUTHORIZED and apply it to a custom httpsAgent when the agent does not explicitly set rejectUnauthorized?
Is it the responsibility of the developer to manually configure rejectUnauthorized on any custom httpsAgent they pass to Axios?
Would providing a utility function that merges environment‑based TLS options into a user‑supplied agent improve clarity without breaking existing code?