What Are HTTPS and SSL? How Secure Websites Work, Explained Simply
HTTPS encrypts the connection between a browser and a website using TLS (once called SSL). What certificates are, what the padlock means and doesn't, and fixes.
Mythex Team · · 5 min read
HTTPS is the secure version of HTTP, the protocol browsers use to talk to websites. It wraps every request and response in an encrypted connection using TLS (Transport Layer Security), so nobody between the visitor and the website can read or tamper with what's sent. SSL is the older name for the same idea — the original protocol TLS replaced — which is why people still say "SSL certificate."
Why HTTPS matters when you build with AI
Any app you publish should be served over HTTPS. That's not only good practice:
- Browsers expect it. Sites on plain HTTP get labelled "Not secure," and some browser features — such as location access, camera and microphone, and service workers for offline apps — generally only work on secure (HTTPS) pages.
- Logins and forms. Without HTTPS, passwords, session cookies and form data travel in readable text. Anyone on the same café Wi-Fi could potentially capture them.
- Payments and third parties. Payment providers, OAuth sign-in and many APIs require HTTPS redirect and callback URLs.
- Trust and search. Visitors notice the warning, and Google has said it treats HTTPS as a ranking signal.
The good news: on most modern hosting platforms, HTTPS is set up automatically. What you mostly need is to understand the pieces well enough to fix it when a custom domain or a mixed-content warning goes wrong.
An everyday analogy
Sending data over plain HTTP is like mailing a postcard: every postal worker who handles it can read it, and someone could even change the message.
HTTPS is like sending a sealed, tamper-evident envelope — and first checking the recipient's official ID. The certificate is that ID card, issued by a trusted authority (the certificate authority) that has checked the website really controls the domain. The encryption is the sealed envelope. The ID proves you're writing to the right address; the envelope keeps the contents private.
How HTTPS works, simply
When a browser opens https://shop.example.com:
- Hello. The browser connects and says which encryption methods it supports.
- Certificate. The server sends its certificate, which says "this key belongs to
shop.example.com" and is signed by a certificate authority. - Check. The browser verifies the signature against authorities it already trusts, checks the certificate hasn't expired, and checks the domain matches.
- Keys. Browser and server agree on a fresh secret key for this session, without ever sending it in the open.
- Encrypted conversation. All requests and responses — pages, form data, cookies — now travel encrypted.
This TLS handshake takes a few milliseconds and happens automatically. The visitor just sees the padlock icon (or, in some browsers, a neutral site-info icon).
What HTTPS does and doesn't protect
| Protects | Doesn't protect |
|---|---|
| Data in transit between browser and server | Data once it's on your server or in your database |
| Against eavesdropping on public Wi-Fi | Against a malicious or scam website |
| Against someone altering pages on the way | Against bugs in your app, like missing permission checks |
| Cookies and passwords while being sent | Against weak passwords or leaked API keys |
HTTPS encrypts the contents of requests, including the page path and query string. But the domain name you visit is usually still visible to networks along the way. That's one reason never to put personal data in URLs anyway — they also end up in logs and browser history.
A worked example: connecting a custom domain
Say you publish a booking app and want it at book.myyogastudio.com:
- You add a DNS record pointing
book.myyogastudio.comto your host. See how domains and DNS work. - The host proves to a certificate authority that it controls that name — typically by responding to a challenge on that domain — and receives a certificate.
- The host installs it and renews it automatically before it expires. Certificates are deliberately short-lived, so automatic renewal matters.
- Visitors to
http://book.myyogastudio.comare redirected tohttps://.
If step 1 is wrong — the record points elsewhere, or a proxy sits in the middle — step 2 can fail and visitors see a certificate error. That's the most common HTTPS problem people hit when connecting a custom domain.
Key terms
| Term | Meaning |
|---|---|
| TLS | Transport Layer Security, the encryption protocol behind HTTPS. |
| SSL | Secure Sockets Layer, TLS's outdated predecessor. The name lingers. |
| Certificate | A signed file linking a domain to a public key. |
| Certificate authority (CA) | An organisation browsers trust to issue certificates, such as Let's Encrypt. |
| Domain validation (DV) | A certificate that proves control of the domain — what almost all sites use. |
| Wildcard certificate | Covers all subdomains one level deep, like *.example.com. |
| Mixed content | An HTTPS page loading some resources over plain HTTP. Browsers block or warn about it. |
| HSTS | A header telling browsers to always use HTTPS for your site from then on. |
| Port 443 | The standard port for HTTPS (HTTP uses port 80). |
Common misconceptions
- "The padlock means the site is trustworthy." It means the connection is private and the domain matches. Scammers get certificates too.
- "HTTPS is only needed for payment pages." Any page with a login, a form or a cookie needs it — which is nearly every app. Just use it everywhere.
- "Certificates are expensive." Free, trusted certificates are standard, and most hosts manage them for you.
- "HTTPS makes my app secure." It secures the connection. Your app still needs server-side permission checks, safe secret handling and input validation. See the security checklist for AI-built apps.
- "HTTPS makes sites slow." Modern TLS adds very little overhead, and features like HTTP/2 that make sites faster generally require HTTPS in browsers.
Fixing common HTTPS problems
| Symptom | Likely cause |
|---|---|
| "Your connection is not private" | Certificate doesn't cover this exact domain, has expired, or hasn't been issued yet |
Works on www. but not the bare domain (or vice versa) | Only one name has DNS and a certificate |
| Padlock missing, "Not secure" on some pages | Mixed content: an image, script or font loaded via http:// |
| Certificate error right after connecting a domain | DNS still propagating, or a proxy in front blocking the certificate check |
What to ask your AI builder
- "Make sure every image, script and font loads over HTTPS or a relative URL — no
http://links." - "Redirect all HTTP traffic to HTTPS."
- "Set session cookies with the
SecureandHttpOnlyflags." - "Use
https://for every OAuth, payment and webhook callback URL." - "My custom domain shows a certificate error — what DNS record does the host expect?"
HTTPS in Mythex
When you connect a custom domain on Mythex (a Pro feature), you add a CNAME record pointing to your app's slug.mythex.ai address, click Verify, and Mythex issues HTTPS for the domain automatically. The docs cover the two most common snags: if your DNS is on Cloudflare, set the record to "DNS only" (grey cloud) rather than proxied, so Mythex can issue the certificate; and DNS can verify before HTTPS is fully set up, so wait a few minutes and verify again. See custom domains in the docs and our guide to connecting a custom domain.
Questions
What is the difference between HTTP and HTTPS?
HTTP sends data between the browser and the website as readable text. HTTPS is HTTP sent through an encrypted TLS connection, so people on the same network or along the route can't read or change what's sent, and the browser can check it's talking to the real site.
Are SSL and TLS the same thing?
TLS is the modern successor to SSL. All versions of SSL are outdated and insecure, and today's secure websites use TLS. People still say "SSL certificate" out of habit, but the certificates are used with TLS.
Does the padlock mean a website is safe?
No. The padlock means the connection is encrypted and the certificate matches the domain. A scam site can have a valid certificate too. It tells you nobody can snoop on the connection, not that the site's owner is trustworthy.
Do I have to pay for an SSL certificate?
Usually not. Free, automated certificate authorities such as Let's Encrypt issue certificates that browsers trust, and most hosting platforms get and renew them for you. Paid certificates mainly add support or extra identity checks.
Why does my site say Not Secure?
Common causes are opening the site over http:// instead of https://, a certificate that has expired or doesn't cover that exact domain, or a page loading images or scripts over plain http:// (mixed content).