microsoft/playwright · error · Error
clientCertificates.origin is required
Error message
clientCertificates.origin is required
What it means
A validation error thrown while parsing the browser context options: an entry in the clientCertificates array was provided without an origin field. Each certificate entry must declare which origin(s) it applies to, so Playwright can decide when to present it during TLS authentication; an entry with a certificate/key but no origin is unusable and rejected at context creation time.
Solutions
- Add `origin: 'https://host'` to each clientCertificates entry
- Group cert/key/passphrase/pfx under the correct origin
- Validate each entry has origin before launching the context
Example fix
// before
await browser.newContext({
clientCertificates: [{ cert: 'c.pem', key: 'k.pem' }]
});
// after
await browser.newContext({
clientCertificates: [{ origin: 'https://example.com', cert: 'c.pem', key: 'k.pem' }]
}); Defensive patterns
Strategy: validation
Validate before calling
function validateClientCerts(certs?: { origin?: string; cert?: string; key?: string; passphrase?: string; pfx?: string }[]) {
if (!certs) return;
for (const c of certs) {
if (!c.origin) throw new Error('Each clientCertificates entry requires an `origin` (e.g. https://host).');
if (!c.cert && !c.key && !c.passphrase && !c.pfx)
throw new Error(`clientCertificates entry for ${c.origin} has no cert/key/passphrase/pfx`);
if (c.cert && !c.key) throw new Error(`cert requires key for ${c.origin}`);
if (!c.cert && c.key) throw new Error(`key requires cert for ${c.origin}`);
if (c.pfx && (c.cert || c.key)) throw new Error(`pfx is exclusive of cert/key for ${c.origin}`);
}
}
validateClientCerts(opts.clientCertificates);
await browser.newContext(opts); Type guard
function isValidCertEntry(c: unknown): c is { origin: string; cert?: string; key?: string; passphrase?: string; pfx?: string } {
return !!c && typeof c === 'object' && typeof (c as any).origin === 'string' && (c as any).origin.length > 0;
} Prevention
- Always include `origin` on every clientCertificates entry
- Validate the full cert/key/pfx matrix before launch
- Centralize TLS config validation to fail fast with a clear message
When it happens
Trigger: `browser.newContext({ clientCertificates: [{ cert: '...', key: '...' }] })` — an entry missing the `origin` field.
Common situations: Incomplete TLS client-auth configs; assuming Playwright applies certs globally rather than per-origin; partial refactor of cert loading.
Understand the failure class
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
Related errors
- cert is specified without key
- key is specified without cert
- None of cert, key, passphrase or pfx is specified
- pfx is specified together with cert, key or passphrase
- Browser userDataDir is not supported in isolated mode.
AI-assisted analysis of microsoft/playwright@f1d33b5029 (2026-09-15).
Data as JSON: /api/errors/32a9ddc22f929618.
Report an issue: GitHub.
Appendix: source
Thrown at packages/playwright-core/src/server/browserContext.ts:814
export function verifyGeolocation(geolocation?: types.Geolocation): asserts geolocation is types.Geolocation {
if (!geolocation)
return;
geolocation.accuracy = geolocation.accuracy || 0;
const { longitude, latitude, accuracy } = geolocation;
if (longitude < -180 || longitude > 180)
throw new Error(`geolocation.longitude: precondition -180 <= LONGITUDE <= 180 failed.`);
if (latitude < -90 || latitude > 90)
throw new Error(`geolocation.latitude: precondition -90 <= LATITUDE <= 90 failed.`);
if (accuracy < 0)
throw new Error(`geolocation.accuracy: precondition 0 <= ACCURACY failed.`);
}
export function verifyClientCertificates(clientCertificates?: types.BrowserContextOptions['clientCertificates']) {
if (!clientCertificates)
return;
for (const cert of clientCertificates) {
if (!cert.origin)
throw new Error(`clientCertificates.origin is required`);
if (cert.noCertificate) {
if (cert.cert || cert.key || cert.passphrase || cert.pfx)
throw new Error('noCertificate is set together with cert, key, passphrase or pfx');
continue;
}
if (!cert.cert && !cert.key && !cert.passphrase && !cert.pfx)
throw new Error('None of cert, key, passphrase or pfx is specified');
if (cert.cert && !cert.key)
throw new Error('cert is specified without key');
if (!cert.cert && cert.key)
throw new Error('key is specified without cert');
if (cert.pfx && (cert.cert || cert.key))
throw new Error('pfx is specified together with cert, key or passphrase');
}
}
export function normalizeProxySettings(proxy: types.ProxySettings): types.ProxySettings {
let { server, bypass } = proxy;View on GitHub (pinned to f1d33b5029)