Answer
Yes – when a tunnel is configured for a reserved subdomain and TLS is enabled, ngrok 3.x automatically provisions and renews the TLS certificate without manual intervention.
Confirmed facts
- ngrok 3.0 retains automatic TLS certificate provisioning and renewal for reserved subdomains when the tunnel defines
subdomain: <name> and TLS is enabled (implicitly for proto: http or explicitly via tls: true).
- The ngrok edge manages the full certificate lifecycle; the user does not need to run renewal commands.
Likely explanation of observed uncertainty
After configuration changes in ngrok 3.0, users sometimes see varying expiry dates because the TLS flag may have been omitted or overridden (e.g., switching to proto: tcp without TLS, setting tls: false, or moving to a custom domain without uploading a custom certificate). In those cases ngrok does not manage a certificate, so the dashboard shows no expiry or a short‑lived self‑signed cert, creating the impression that renewal is uncertain.
Steps to verify and maintain valid certificates
- Confirm you are running ngrok 3.0 or later:
ngrok version.
- Ensure your
ngrok.yml contains a tunnel like:
tunnels:
myapp:
proto: http
subdomain: my-reserved-subdomain
or, for explicit TLS:
tunnels:
myapp:
proto: tls
subdomain: my-reserved-subdomain
tls: true
- Restart ngrok:
ngrok start myapp (or ngrok start --all).
- Check the tunnel status via the dashboard or API:
ngrok api tunnels. Look for config.tls: true and a far‑future cert_expires timestamp.
- Optionally, inspect the certificate with OpenSSL:
openssl s_client -servername my-reserved-subdomain.ngrok.io -connect my-reserved-subdomain.ngrok.io:443 -showcerts
Missing diagnostic detail
If you are using a custom domain or have explicitly set tls: false in your tunnel configuration, please confirm so we can adjust the recommendation (manual certificate management would be required).