Live demo available
Why CertMate?
CertMate solves the complexity of SSL certificate management in modern distributed architectures. Whether you're running a single application or managing certificates across multiple datacenters, CertMate provides:
Zero-Downtime Automation - Certificates renew automatically 30 days before expiry, with deploy hooks to reload services
Multi-Cloud Support - Works with two dozen+ DNS providers (Cloudflare, AWS, Azure, GCP, Akamai Edge DNS, Hetzner, Porkbun, GoDaddy, and more — see docs/dns-providers.md for the full list)
Enterprise-Ready - RBAC, scoped API keys, Docker, Kubernetes, REST API, and monitoring built-in
Simple Integration - One-URL certificate downloads for easy automation
Security-First - Role-based access control, scoped API keys, audit logging, HMAC-signed webhooks
Unified Backup System - Atomic backups of settings and certificates ensuring data consistency
Real-Time Dashboard - SSE-powered live updates, command palette, keyboard shortcuts, dark mode
Key Features
Certificate Management
Multiple CA Providers - Support for Let's Encrypt, ZeroSSL, Google Trust Services, Actalis, DigiCert ACME, SSL.com, and Private CAs
Let's Encrypt Integration - Free, automated SSL certificates, with the staging environment available as a dedicated CA entry for testing
DigiCert ACME Support - Enterprise-grade certificates with External Account Binding (EAB)
Actalis Support - Free 90-day DV certificates from a European CA via ACME with EAB
Private CA Support - Internal/corporate CAs with custom trust bundles and ACME compatibility
Wildcard Support - Single certificate for *.example.com and example.com
Multi-Domain Certificates - SAN certificates for multiple domains
DNS Alias via CNAME Delegation - Delegate ACME DNS validation to an alternative domain using standard CNAME records
Automatic Renewal - Smart renewal 30 days before expiry
Certificate Validation - Real-time SSL certificate status checking
Per-Certificate CA Selection - Choose different CAs for different certificates
Zombie Certificate Scanner - filesystem scanner to identify and clean up orphan ("zombie") certificates no longer tracked in the active configuration
Multi-DNS Provider Support
Multi-Account Support - Manage multiple accounts per provider for enterprise environments
Cloudflare - Global CDN with edge locations worldwide (Multi-Account)
AWS Route53 - Amazon's scalable DNS service (Multi-Account)
Azure DNS - Microsoft's cloud DNS solution (Multi-Account)
Google Cloud DNS - Google's high-performance DNS (Multi-Account)
DigitalOcean - Cloud infrastructure DNS (Multi-Account)
PowerDNS - Open-source DNS server with REST API (Multi-Account)
Enterprise Features
Role-Based Access Control - Three-tier RBAC with viewer, operator, and admin roles
Scoped API Keys - Create, revoke, and manage API keys with per-key role and optional expiration
Multi-Account Management - Support multiple accounts per DNS provider for enterprise workflows
REST API - Complete programmatic control with Swagger/OpenAPI docs
Web Dashboard - Modern, responsive UI built with Tailwind CSS and Alpine.js
Setup Wizard - Guided first-run configuration for DNS, CA, and authentication
Real-Time Updates - Server-Sent Events (SSE) push live status to the dashboard
Docker Ready - Full containerization with Docker Compose
Kubernetes Compatible - Deploy in any Kubernetes cluster
Monitoring Integration - Health checks, Prometheus metrics, and structured JSON logging
Backup and Recovery
Unified Backups - Atomic snapshots of both settings and certificates ensuring data consistency
Automatic Backups - Settings and certificates backed up automatically on changes
Manual Backup Creation - On-demand backup creation via web UI or API
Comprehensive Coverage - Backs up DNS configurations, certificates, and application settings
Retention Management - Configurable retention policies with automatic cleanup
Easy Restore - Simple restore process from any backup point with atomic consistency
Download Support - Export backups for external storage and disaster recovery
Certificate Storage Backends
Local Filesystem - Default secure local storage with proper file permissions (600/700)
Azure Key Vault - Enterprise-grade secret management with Azure integration and HSM protection
AWS Secrets Manager - Scalable secret storage with AWS ecosystem integration and cross-region replication
HashiCorp Vault - Industry-standard secret management with versioning, audit logging, and fine-grained policies
Infisical - Modern open-source secret management with team collaboration and end-to-end encryption
S3-Compatible Object Storage - One backend for any S3 endpoint via a configurable endpoint URL (Hetzner, Contabo, OVHcloud, Scaleway, Exoscale, Wasabi, MinIO, AWS) — ideal for EU-sovereign object storage; no extra dependency
Pluggable Architecture - Easy to extend with additional storage backends
Migration Support - Seamless migration between storage backends without downtime
Backward Compatibility - Existing installations continue working without changes
Notifications & Automation
Multi-Channel Notifications - Email (SMTP), Slack, Discord, Telegram, ntfy, Gotify, and generic webhooks
Webhook HMAC Signatures - SHA-256 signed payloads for secure webhook verification
Deploy Hooks - Post-issuance shell commands to reload Nginx/Apache or run custom scripts
Weekly Digest - Scheduled email summary of certificate status and upcoming renewals
SSE Real-Time Events - Live push updates for certificate operations and deploy hook results
Security & Compliance
Role-Based Access Control - Viewer, operator, and admin roles with hierarchical permissions
Scoped API Keys - Create keys with specific roles and optional expiration dates
Bearer Token Authentication - Secure API access control
File Permissions - Proper certificate file security (600/700)
Audit Logging - Complete certificate lifecycle tracking with timeline view
Environment Variables - Secure credential management
Rate Limit Handling - Let's Encrypt rate limit awareness
Log Sanitizer - Automatically redacts sensitive parameters, private keys, and API tokens from application logs
User Interface
Command Palette - Cmd+K / Ctrl+K quick search and navigation
Keyboard Shortcuts - Power-user shortcuts for navigation and common actions
Dark Mode - System-aware dark/light theme toggle
Mobile-Friendly - Responsive layout with bottom tab bar on small screens
Activity Timeline - Chronological view of all certificate and system events
Developer Experience
One-URL Downloads - Simple certificate retrieval for automation (/{domain}/tls)
Individual Component Downloads - Fetch cert, key, chain, or fullchain separately
Multiple Output Formats - PEM, ZIP, individual files
SDK Examples - Python, Bash, Ansible, Terraform examples
Webhook Support - Certificate lifecycle notifications with HMAC verification
Deploy Hook API - Configure and test post-issuance hooks via REST API
Backup API - Programmatic backup creation and restoration
Swagger & ReDoc - Interactive API documentation at /docs/ and /redoc/
Model Context Protocol (MCP) Server - Built-in Node.js MCP server providing tools for agentic AI assistants to manage certificates and run diagnostics
Enjoy and contribute: https://www.certmate.org and https://github.com/fabriziosalmi/certmate

Replies