microsoft/playwright · error · Error

clientCertificates.origin is required

Error message

clientCertificates.origin is required

What it means

A validation error thrown while parsing the browser context options: an entry in the clientCertificates array was provided without an origin field. Each certificate entry must declare which origin(s) it applies to, so Playwright can decide when to present it during TLS authentication; an entry with a certificate/key but no origin is unusable and rejected at context creation time.

Solutions

  1. Add `origin: 'https://host'` to each clientCertificates entry
  2. Group cert/key/passphrase/pfx under the correct origin
  3. Validate each entry has origin before launching the context

Example fix

// before
await browser.newContext({
  clientCertificates: [{ cert: 'c.pem', key: 'k.pem' }]
});

// after
await browser.newContext({
  clientCertificates: [{ origin: 'https://example.com', cert: 'c.pem', key: 'k.pem' }]
});
Defensive patterns

Strategy: validation

Validate before calling

function validateClientCerts(certs?: { origin?: string; cert?: string; key?: string; passphrase?: string; pfx?: string }[]) {
  if (!certs) return;
  for (const c of certs) {
    if (!c.origin) throw new Error('Each clientCertificates entry requires an `origin` (e.g. https://host).');
    if (!c.cert && !c.key && !c.passphrase && !c.pfx)
      throw new Error(`clientCertificates entry for ${c.origin} has no cert/key/passphrase/pfx`);
    if (c.cert && !c.key) throw new Error(`cert requires key for ${c.origin}`);
    if (!c.cert && c.key) throw new Error(`key requires cert for ${c.origin}`);
    if (c.pfx && (c.cert || c.key)) throw new Error(`pfx is exclusive of cert/key for ${c.origin}`);
  }
}
validateClientCerts(opts.clientCertificates);
await browser.newContext(opts);

Type guard

function isValidCertEntry(c: unknown): c is { origin: string; cert?: string; key?: string; passphrase?: string; pfx?: string } {
  return !!c && typeof c === 'object' && typeof (c as any).origin === 'string' && (c as any).origin.length > 0;
}

Prevention

When it happens

Trigger: `browser.newContext({ clientCertificates: [{ cert: '...', key: '...' }] })` — an entry missing the `origin` field.

Common situations: Incomplete TLS client-auth configs; assuming Playwright applies certs globally rather than per-origin; partial refactor of cert loading.

Understand the failure class

Related errors


AI-assisted analysis of microsoft/playwright@f1d33b5029 (2026-09-15). Data as JSON: /api/errors/32a9ddc22f929618. Report an issue: GitHub.

Appendix: source

Thrown at packages/playwright-core/src/server/browserContext.ts:814

export function verifyGeolocation(geolocation?: types.Geolocation): asserts geolocation is types.Geolocation {
  if (!geolocation)
    return;
  geolocation.accuracy = geolocation.accuracy || 0;
  const { longitude, latitude, accuracy } = geolocation;
  if (longitude < -180 || longitude > 180)
    throw new Error(`geolocation.longitude: precondition -180 <= LONGITUDE <= 180 failed.`);
  if (latitude < -90 || latitude > 90)
    throw new Error(`geolocation.latitude: precondition -90 <= LATITUDE <= 90 failed.`);
  if (accuracy < 0)
    throw new Error(`geolocation.accuracy: precondition 0 <= ACCURACY failed.`);
}

export function verifyClientCertificates(clientCertificates?: types.BrowserContextOptions['clientCertificates']) {
  if (!clientCertificates)
    return;
  for (const cert of clientCertificates) {
    if (!cert.origin)
      throw new Error(`clientCertificates.origin is required`);
    if (cert.noCertificate) {
      if (cert.cert || cert.key || cert.passphrase || cert.pfx)
        throw new Error('noCertificate is set together with cert, key, passphrase or pfx');
      continue;
    }
    if (!cert.cert && !cert.key && !cert.passphrase && !cert.pfx)
      throw new Error('None of cert, key, passphrase or pfx is specified');
    if (cert.cert && !cert.key)
      throw new Error('cert is specified without key');
    if (!cert.cert && cert.key)
      throw new Error('key is specified without cert');
    if (cert.pfx && (cert.cert || cert.key))
      throw new Error('pfx is specified together with cert, key or passphrase');
  }
}

export function normalizeProxySettings(proxy: types.ProxySettings): types.ProxySettings {
  let { server, bypass } = proxy;

View on GitHub (pinned to f1d33b5029)