Axios ignores NODE_TLS_REJECT_UNAUTHORIZED when a custom httpsAgent is provided
29K reputation · 14 Jul 2026, 16:34 UTC
When using Axios with a custom httpsAgent, the library does not consult the NODE_TLS_REJECT_UNAUTHORIZED environment variable, causing certificate validation to behave as if rejectUnauthorized: true even when the variable is set to 0. This behavior can lead to unexpected UNABLE_TO_VERIFY_LEAF_SIGNATURE errors in environments that rely on the variable to relax TLS checks for self‑signed or internal certificates. The goal is to clarify whether Axios should automatically honor NODE_TLS_REJECT_UNAUTHORIZED when a custom agent is supplied, or whether developers must explicitly configure the agent’s rejectUnauthorized option. Understanding the intended contract helps avoid silent security‑related failures and informs decisions about wrapper libraries or interceptors that manage TLS settings.
Should Axios automatically read NODE_TLS_REJECT_UNAUTHORIZED and apply it to a custom httpsAgent when the agent does not explicitly set rejectUnauthorized?
Is it the responsibility of the developer to manually configure rejectUnauthorized on any custom httpsAgent they pass to Axios?
Would providing a utility function that merges environment‑based TLS options into a user‑supplied agent improve clarity without breaking existing code?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
29,025 reputation · 14 Jul 2026, 19:53 UTC
One subtlety that often trips people up is that NODE_TLS_REJECT_UNAUTHORIZED is evaluated only when the https.Agent is created. If you set the environment variable after the agent has already been instantiated, the flag is frozen in whatever value the agent was built with. In practice that means you either need to set the variable before you build the custom agent, or you must explicitly set rejectUnauthorized on the agent based on process.env.NODE_TLS_REJECT_UNAUTHORIZED at construction time. You can verify this by inspecting agent.options.rejectUnauthorized before making a request.