Track and Automate Everything That Expires
TokenTimer is an open-source expiration management and certificate lifecycle automation platform for DevOps, SRE, platform engineering, security, and IT teams.
It brings certificates, API keys, secrets, licenses, subscriptions, and other time-bound infrastructure assets into one place so teams can see what is expiring, who owns it, and what needs action before it becomes an incident.
But TokenTimer goes beyond reminders.
With CertOps, teams can automate certificate renewal, deployment, service reload, and verification while keeping private keys inside their own infrastructure.
Why TokenTimer Exists
Expiring infrastructure is usually scattered across multiple systems:
TLS certificates on endpoints and servers
API keys across repositories and cloud platforms
Secrets in vaults and secret managers
Software licenses and subscriptions
Other time-bound operational assets
Teams often rely on spreadsheets, calendar reminders, scripts, or provider-specific dashboards.
That works until infrastructure grows.
Then ownership becomes unclear, expiration dates are spread across different systems, and teams find out about a missed renewal when something stops working.
TokenTimer gives teams one place to manage that lifecycle proactively.
Centralized Expiration Management
TokenTimer provides a unified inventory for assets such as:
TLS certificates
API keys and tokens
Secrets
Licenses
Subscriptions
Other expiring infrastructure assets
Instead of checking multiple dashboards, teams can see upcoming expirations and lifecycle status from a central interface.
Assets can also be synchronized from infrastructure and developer systems rather than being maintained manually.
Certificate Lifecycle Automation with CertOps
Certificate monitoring tells you that a certificate will expire.
Someone still has to:
Renew it
Deploy the new certificate
Reload the affected service
Verify that the new certificate is actually serving correctly
TokenTimer CertOps is designed to automate that operational lifecycle.
A customer-side agent performs certificate renewal, deployment, reload, and verification inside the operator’s infrastructure.
Supported workflows include ACME automation through tools such as certbot and acme.sh, DNS-01 validation across major providers, cert-manager integrations, and other certificate execution workflows.
Operators retain control through approval gates, failure alerts, rollback safeguards, and a kill switch.
Private Keys Stay in Your Infrastructure
TokenTimer is designed around zero private-key custody.
Certificate operations requiring private key material happen inside customer-controlled infrastructure.
The TokenTimer control plane does not receive or store those private keys.
This allows teams to automate certificate operations without transferring one of their most sensitive infrastructure assets to a third-party control plane.
Proactive Notifications
TokenTimer can notify teams before important assets expire through channels including:
Email
Slack
Microsoft Teams
Discord
WhatsApp
PagerDuty
Webhooks
This allows expiration management to fit into the communication and incident workflows teams already use.
Integrates with Existing Infrastructure
TokenTimer can connect expiration management with services such as:
AWS Secrets Manager
Azure Key Vault
Google Cloud Secret Manager
HashiCorp Vault
GitHub
GitLab
APIs, files, and monitored endpoints
The goal is to reduce manual inventory maintenance while keeping lifecycle information synchronized with the systems teams already operate.
Cloud or Self-Hosted
TokenTimer is available both as a hosted service and as a self-hosted platform.
TokenTimer Core is open source under the AGPL-3.0 license.
Self-hosted deployments support:
Docker Compose
Kubernetes
Helm
This gives teams the choice between using a managed service or running TokenTimer inside their own environment.
Security-First Agent Architecture
For hosted deployments, TokenTimer’s customer-side automation agent communicates outbound over HTTPS.
No inbound connection into customer infrastructure is required.
This makes it possible to run certificate automation close to the systems being managed while maintaining a clear boundary between the TokenTimer control plane and customer infrastructure.
Who Is TokenTimer For?
DevOps and SRE Teams
Reduce preventable outages caused by forgotten certificate renewals, expired credentials, and other time-bound infrastructure.
Platform Engineering Teams
Create a consistent lifecycle process across environments, providers, and applications.
Security Teams
Improve visibility into certificates, credentials, and other expiring security assets without centralizing private-key custody.
IT and Infrastructure Teams
Track licenses, subscriptions, certificates, and operational renewals from a shared system instead of scattered reminders.
From Monitoring to Prevention
The core idea behind TokenTimer is simple:
Knowing that something expires is useful. Making sure it does not expire unexpectedly is better.
TokenTimer combines expiration visibility, ownership, notifications, integrations, and certificate lifecycle automation so teams can move from reacting to expiration incidents to preventing them.
Open Source
TokenTimer Core is available on GitHub under AGPL-3.0.
GitHub: https://github.com/tokentimerch/tokentimer-core
Documentation: https://tokentimer.ch/docs


