Live demo available

by

Why CertMate?

CertMate solves the complexity of SSL certificate management in modern distributed architectures. Whether you're running a single application or managing certificates across multiple datacenters, CertMate provides:

  • Zero-Downtime Automation - Certificates renew automatically 30 days before expiry, with deploy hooks to reload services

  • Multi-Cloud Support - Works with two dozen+ DNS providers (Cloudflare, AWS, Azure, GCP, Akamai Edge DNS, Hetzner, Porkbun, GoDaddy, and more — see for the full list)

  • Enterprise-Ready - RBAC, scoped API keys, Docker, Kubernetes, REST API, and monitoring built-in

  • Simple Integration - One-URL certificate downloads for easy automation

  • Security-First - Role-based access control, scoped API keys, audit logging, HMAC-signed webhooks

  • Unified Backup System - Atomic backups of settings and certificates ensuring data consistency

  • Real-Time Dashboard - SSE-powered live updates, command palette, keyboard shortcuts, dark mode

Key Features

Certificate Management

  • Multiple CA Providers - Support for Let's Encrypt, ZeroSSL, Google Trust Services, Actalis, DigiCert ACME, , and Private CAs

  • Let's Encrypt Integration - Free, automated SSL certificates, with the staging environment available as a dedicated CA entry for testing

  • DigiCert ACME Support - Enterprise-grade certificates with External Account Binding (EAB)

  • Actalis Support - Free 90-day DV certificates from a European CA via ACME with EAB

  • Private CA Support - Internal/corporate CAs with custom trust bundles and ACME compatibility

  • Wildcard Support - Single certificate for *. and

  • Multi-Domain Certificates - SAN certificates for multiple domains

  • DNS Alias via CNAME Delegation - Delegate ACME DNS validation to an alternative domain using standard CNAME records

  • Automatic Renewal - Smart renewal 30 days before expiry

  • Certificate Validation - Real-time SSL certificate status checking

  • Per-Certificate CA Selection - Choose different CAs for different certificates

  • Zombie Certificate Scanner - filesystem scanner to identify and clean up orphan ("zombie") certificates no longer tracked in the active configuration

Multi-DNS Provider Support

  • Multi-Account Support - Manage multiple accounts per provider for enterprise environments

  • Cloudflare - Global CDN with edge locations worldwide (Multi-Account)

  • AWS Route53 - Amazon's scalable DNS service (Multi-Account)

  • Azure DNS - Microsoft's cloud DNS solution (Multi-Account)

  • Google Cloud DNS - Google's high-performance DNS (Multi-Account)

  • DigitalOcean - Cloud infrastructure DNS (Multi-Account)

  • PowerDNS - Open-source DNS server with REST API (Multi-Account)

Enterprise Features

  • Role-Based Access Control - Three-tier RBAC with viewer, operator, and admin roles

  • Scoped API Keys - Create, revoke, and manage API keys with per-key role and optional expiration

  • Multi-Account Management - Support multiple accounts per DNS provider for enterprise workflows

  • REST API - Complete programmatic control with Swagger/OpenAPI docs

  • Web Dashboard - Modern, responsive UI built with Tailwind CSS and Alpine.js

  • Setup Wizard - Guided first-run configuration for DNS, CA, and authentication

  • Real-Time Updates - Server-Sent Events (SSE) push live status to the dashboard

  • Docker Ready - Full containerization with Docker Compose

  • Kubernetes Compatible - Deploy in any Kubernetes cluster

  • Monitoring Integration - Health checks, Prometheus metrics, and structured JSON logging

Backup and Recovery

  • Unified Backups - Atomic snapshots of both settings and certificates ensuring data consistency

  • Automatic Backups - Settings and certificates backed up automatically on changes

  • Manual Backup Creation - On-demand backup creation via web UI or API

  • Comprehensive Coverage - Backs up DNS configurations, certificates, and application settings

  • Retention Management - Configurable retention policies with automatic cleanup

  • Easy Restore - Simple restore process from any backup point with atomic consistency

  • Download Support - Export backups for external storage and disaster recovery

Certificate Storage Backends

  • Local Filesystem - Default secure local storage with proper file permissions (600/700)

  • Azure Key Vault - Enterprise-grade secret management with Azure integration and HSM protection

  • AWS Secrets Manager - Scalable secret storage with AWS ecosystem integration and cross-region replication

  • HashiCorp Vault - Industry-standard secret management with versioning, audit logging, and fine-grained policies

  • Infisical - Modern open-source secret management with team collaboration and end-to-end encryption

  • S3-Compatible Object Storage - One backend for any S3 endpoint via a configurable endpoint URL (Hetzner, Contabo, OVHcloud, Scaleway, Exoscale, Wasabi, MinIO, AWS) — ideal for EU-sovereign object storage; no extra dependency

  • Pluggable Architecture - Easy to extend with additional storage backends

  • Migration Support - Seamless migration between storage backends without downtime

  • Backward Compatibility - Existing installations continue working without changes

Notifications & Automation

  • Multi-Channel Notifications - Email (SMTP), Slack, Discord, Telegram, ntfy, Gotify, and generic webhooks

  • Webhook HMAC Signatures - SHA-256 signed payloads for secure webhook verification

  • Deploy Hooks - Post-issuance shell commands to reload Nginx/Apache or run custom scripts

  • Weekly Digest - Scheduled email summary of certificate status and upcoming renewals

  • SSE Real-Time Events - Live push updates for certificate operations and deploy hook results

Security & Compliance

  • Role-Based Access Control - Viewer, operator, and admin roles with hierarchical permissions

  • Scoped API Keys - Create keys with specific roles and optional expiration dates

  • Bearer Token Authentication - Secure API access control

  • File Permissions - Proper certificate file security (600/700)

  • Audit Logging - Complete certificate lifecycle tracking with timeline view

  • Environment Variables - Secure credential management

  • Rate Limit Handling - Let's Encrypt rate limit awareness

  • Log Sanitizer - Automatically redacts sensitive parameters, private keys, and API tokens from application logs

User Interface

  • Command Palette - Cmd+K / Ctrl+K quick search and navigation

  • Keyboard Shortcuts - Power-user shortcuts for navigation and common actions

  • Dark Mode - System-aware dark/light theme toggle

  • Mobile-Friendly - Responsive layout with bottom tab bar on small screens

  • Activity Timeline - Chronological view of all certificate and system events

Developer Experience

  • One-URL Downloads - Simple certificate retrieval for automation (/{domain}/tls)

  • Individual Component Downloads - Fetch cert, key, chain, or fullchain separately

  • Multiple Output Formats - PEM, ZIP, individual files

  • SDK Examples - Python, Bash, Ansible, Terraform examples

  • Webhook Support - Certificate lifecycle notifications with HMAC verification

  • Deploy Hook API - Configure and test post-issuance hooks via REST API

  • Backup API - Programmatic backup creation and restoration

  • Swagger & ReDoc - Interactive API documentation at /docs/ and /redoc/

  • Model Context Protocol (MCP) Server - Built-in Node.js MCP server providing tools for agentic AI assistants to manage certificates and run diagnostics

    Enjoy and contribute: and

12 views

Add a comment

Replies

Be the first to comment