microsoft/playwright · error · Error
noCertificate is set together with cert, key, passphrase or…
Error message
noCertificate is set together with cert, key, passphrase or pfx
What it means
Playwright validates each clientCertificates entry when a browser context is created. A cert entry flagged with noCertificate=true is a 'deny/ignore certificates for this origin' marker and must not carry actual certificate material (cert, key, passphrase, pfx). Supplying both is contradictory, so the context creation fails fast in browserContext.ts.
Solutions
- Remove the cert, key, passphrase and pfx fields from the entry that has noCertificate: true.
- If you actually want TLS client auth on the origin, delete noCertificate and keep the cert/key or pfx fields.
- If you have multiple entries for the same origin, split them: one noCertificate-only entry, or one cert-carrying entry — not a hybrid.
Example fix
// before
clientCertificates: [{ origin: 'https://example.com', noCertificate: true, cert: './client.pem', key: './key.pem' }]
// after
clientCertificates: [{ origin: 'https://example.com', noCertificate: true }] Defensive patterns
Strategy: validation
Validate before calling
for (const c of clientCertificates) {
const fields = ['cert', 'key', 'passphrase', 'pfx'].filter(k => c[k] != null);
if (c.noCertificate && fields.length) throw new Error(`noCertificate entry has: ${fields.join(',')}`);
if (!c.origin) throw new Error('origin required');
} Type guard
function isNoCertOnlyEntry(c: { noCertificate?: boolean; cert?: string; key?: string; passphrase?: string; pfx?: Buffer }) {
return !!c.noCertificate && !c.cert && !c.key && !c.passphrase && !c.pfx;
} Try / catch
null
Prevention
- Model noCertificate entries as a separate variant type in your config layer.
- Deduplicate and normalize clientCertificates after merging configs from multiple sources.
When it happens
Trigger: Calling browser.newContext({ clientCertificates: [{ origin: 'https://example.com', noCertificate: true, cert: '...', key: '...' }] }) or the same via contextOptions in the test config — any entry with noCertificate set to true that also sets cert, key, passphrase or pfx.
Common situations: Merging default client-certificate config with an override entry that adds noCertificate: true; copy-pasting a working cert entry and appending noCertificate to disable it instead of removing the fields; spreading config objects where cert fields leak into a noCertificate entry.
Understand the failure class
Background: Conflicting config options: "cannot be used together" — configuration validation errors across open-source libraries — this error's family across 162 libraries.
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
Related errors
- clientCertificates for origin
- None of cert, key, passphrase or pfx is specified
- cert is specified without key
- clientCertificates.origin is required
- key is specified without cert
AI-assisted analysis of microsoft/playwright@f1d33b5029 (2026-09-15).
Data as JSON: /api/errors/9989b5bed92798f9.
Report an issue: GitHub.
Appendix: source
Thrown at packages/playwright-core/src/server/browserContext.ts:817
geolocation.accuracy = geolocation.accuracy || 0;
const { longitude, latitude, accuracy } = geolocation;
if (longitude < -180 || longitude > 180)
throw new Error(`geolocation.longitude: precondition -180 <= LONGITUDE <= 180 failed.`);
if (latitude < -90 || latitude > 90)
throw new Error(`geolocation.latitude: precondition -90 <= LATITUDE <= 90 failed.`);
if (accuracy < 0)
throw new Error(`geolocation.accuracy: precondition 0 <= ACCURACY failed.`);
}
export function verifyClientCertificates(clientCertificates?: types.BrowserContextOptions['clientCertificates']) {
if (!clientCertificates)
return;
for (const cert of clientCertificates) {
if (!cert.origin)
throw new Error(`clientCertificates.origin is required`);
if (cert.noCertificate) {
if (cert.cert || cert.key || cert.passphrase || cert.pfx)
throw new Error('noCertificate is set together with cert, key, passphrase or pfx');
continue;
}
if (!cert.cert && !cert.key && !cert.passphrase && !cert.pfx)
throw new Error('None of cert, key, passphrase or pfx is specified');
if (cert.cert && !cert.key)
throw new Error('cert is specified without key');
if (!cert.cert && cert.key)
throw new Error('key is specified without cert');
if (cert.pfx && (cert.cert || cert.key))
throw new Error('pfx is specified together with cert, key or passphrase');
}
}
export function normalizeProxySettings(proxy: types.ProxySettings): types.ProxySettings {
let { server, bypass } = proxy;
let url;
try {
// new URL('127.0.0.1:8080') throwsView on GitHub (pinned to f1d33b5029)