Home → Help
ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] unable to get local issuer certificateError: unable to verify the first certificateUNABLE_TO_GET_ISSUER_CERT_LOCALLYrequests.exceptions.SSLError ... certificate verify failedCorporate proxies, some antivirus products and most VPN inspection appliances decrypt HTTPS to look inside it, then issue their own certificate. Operating systems get that root installed centrally; Python, Node and Go often ship or use their own trust store and never see it. That is the exact gap where curl succeeds and your code fails.
The error also appears with no proxy at all when a runtime's bundled CA list has gone stale, typically on an old container image or a long-lived VM that has never been updated.
It is not an authentication problem. The request never completes the handshake, so no key is ever sent and nothing reaches the provider's logs.
Look at who signed the certificate you are actually receiving:
openssl s_client -connect YOUR_DOMAIN:443 -servername YOUR_DOMAIN </dev/null 2>/dev/null \
| openssl x509 -noout -issuer -subject
If the issuer is a public CA, your runtime's trust store is stale. If it names your company, a security appliance or an antivirus vendor, traffic is being intercepted and you need that root installed where your runtime looks.
Last checked 2026-10-01. Written from problems diagnosed on a live OpenAI-compatible gateway, not collected from other sites.