TokenTimer - Certificate lifecycle automation without private-key custody

by
TokenTimer discovers every certificate, token, secret and license you own, alerts the right people before expiry, and automates renewal where it matters. Cloud-managed SaaS or self-hosted, metadata-only security, source-available on GitHub.

Add a comment

Replies

Best
Maker
📌

Hey Product Hunt 👋

If you don’t already know TokenTimer, here is a quick explainer video:

We originally launched TokenTimer around a simple problem: infrastructure assets expire, ownership gets lost, and teams often discover it when something breaks.

Since then, we kept seeing the same limitation: knowing that a TLS certificate expires in 15 days is useful, but somebody still has to renew it, deploy it, reload the service and verify that the right certificate is actually live.

That led us to build CertOps into TokenTimer.

TokenTimer now combines managed certificate inventory with customer-side certificate operations. The key architectural decision was that private keys should never need to enter our control plane: key-bearing work stays in infrastructure controlled by the customer.

We also still handle the broader expiration problem: API keys, secrets, licenses and other time-bound assets.

I’d especially appreciate feedback from DevOps, SRE, platform, security and PKI teams:

Where does certificate lifecycle automation still hurt in your environment: discovery, ownership, renewal, deployment, or verification?