Checkmate reads the certificate your server presents, warns you ahead of expiry and shows the details right on the monitor. Renewal stays your job, remembering stops being one.
An expired certificate greets your visitors with a full-page security warning, and most of them leave. Checkmate tracks expiry for the certificates behind your HTTPS monitors and warns you while there is still time to renew calmly.
The warning arrives on the channels you already use: email, Slack, PagerDuty or any of the 12 supported channels.
Certificate tracking is built into HTTPS uptime monitors, so there is no second product to configure and no second list of hostnames to maintain. Add a monitor for an endpoint and its certificate is watched from that moment on.
Fleets with many domains get one sortable view of what expires when, instead of a spreadsheet someone forgets to update.
Domains lapse the same way certificates do: quietly, then all at once. Checkmate also tracks domain registration expiry on uptime monitors, so the registration renewal and the certificate renewal live on the same page.
It is a small check that prevents a uniquely embarrassing outage.
Dozens of client sites means dozens of renewal dates. One dashboard shows what expires next across the whole book of clients.
Custom customer domains multiply your certificate surface. Watch them all without adding each to a calendar by hand.
Automated renewal works until a cron job silently dies. An independent expiry check catches the failure weeks before the deadline.
Expiry comes from the certificate your server presents during checks, not from a registry lookup. If a renewal ran but the web server never reloaded, the monitor shows the certificate your visitors get.
Let's Encrypt certificates renew every 90 days, which means more renewals and more chances for automation to fail quietly. An independent watcher that pages you on a missed renewal is the safety net.
Because your instance runs the checks, hosts on internal networks are reachable too. Certificates on intranet services get the same expiry warnings as public ones.
A hosted certificate watcher learns your full domain inventory. Checkmate runs on your infrastructure, so the list of what you monitor never leaves it.
Certificate tracking is part of HTTPS uptime monitors. Checkmate reads the certificate your server presents during checks, shows its expiry on the monitor page and warns you ahead of the date on your notification channels.
Yes, and it is a good match: short-lived certificates renew often, so automation has more chances to fail quietly. Checkmate acts as the independent check that notices a missed renewal before the certificate lapses.
Yes. The checks run from your own Checkmate instance, so anything your instance can reach, including intranet services, gets the same certificate monitoring as public sites.
No. Checkmate monitors and alerts, your ACME client or CA tooling renews. The separation is deliberate: the watcher stays independent of the automation it watches.
Yes. Uptime monitors track domain registration expiry alongside certificate expiry, so both renewal dates live on the same monitor page.
Checkmate is one. It is open source under AGPL-3.0, so you can self-host it and monitor as many certificates as you like with no per-domain pricing.
Websites and APIs checked from 6 continents.
CPU, memory, disk and network via the Capture agent.
Container status, health checks and resource usage.
More than 100 game types over native protocols.
Branded public pages served from your own instance.
12 native channels, from email to PagerDuty.
All featuresCheckmate is open source under AGPL-3.0. Self-host it and this feature ships free, on your servers, with your data.