The worst way to learn a client's certificate expired is the client telling you.

CertSentry watches every domain you manage. It polls free registry data for registration and certificate expiry, then pushes an alert to your phone while there is still time to renew.

Get the launch link · $49 one-time · full source · yours forever
CertSentry list: domains with day counts to registration and certificate expiry

The app checking real domains over live RDAP and certificate logs, 15 Sep 2026.

The 30-second story

An agency's domains sprawl. Some sit in the client's registrar account, some in yours, a few in an account a former contractor set up. Renewal reminders go to inboxes nobody reads. Then a browser warning appears on a client's site, the client sends a screenshot, and the morning is gone.

The data to prevent that phone call is public and free. Registries publish expiry dates over RDAP. Certificate transparency logs record every certificate's deadline. CertSentry polls both for your whole list and pings your phone at 30, 14, 7 and 1 days out. You renew on your schedule instead of the client's.

What's included

Registration expiry via RDAPStraight from each TLD's registry, bootstrapped from IANA's public index. No registrar logins, no API keys.
Certificate expiry via crt.shLatest certificate for each domain and its wildcard, read from public certificate transparency logs.
Push alerts that fire onceOne ping per threshold as the countdown crosses it. No daily nag while a renewal sits at 12 days.
No silent failuresWhen a lookup fails, the app keeps last known data and says so. When a registry publishes no date, you see "no data", never a guess.
Private phone appInstallable PWA behind your admin token, with real iPhone push from the home screen (iOS 16.4+). It updates itself on deploy.
Your infrastructureRuns on your Cloudflare account for $5/month. Full TypeScript source, tests included, no phone-home.

Up and running in about 10 minutes

Create the database and apply the included schema.
Run the included key generator, set your secrets.
One deploy command. Open it on your phone, add your domains, tap Enable alerts.

The README walks every step, including the Windows trap that corrupts secrets when you pipe them the wrong way. The exact commands live in the kit.

Questions before you buy

Why pay $49 when monitoring services exist?

Hosted monitors charge by the month and cap your checks by plan. UptimeRobot, the obvious comparable, puts SSL monitoring behind paid tiers at $7 to $29 a month. CertSentry is a one-time purchase you host on a $5 Cloudflare plan, with no per-domain pricing and no data leaving your account.

Where does the data come from?

Registration expiry comes from RDAP, the registry protocol that replaced WHOIS. Certificate expiry comes from crt.sh, a public index of certificate transparency logs. Both are free public infrastructure; the kit adds retries, timeouts and caching around them.

Does iPhone push work?

Yes, from the installed home-screen app on iOS 16.4 or later. That requirement comes from Apple. The kit ships a test-ping button so you can prove the pipe end to end in your first ten minutes.

What do I get?

The full TypeScript source: Worker, parsers, React app, schema, VAPID generator, test suite, and the README. No obfuscation, no license server. Use it for unlimited personal and client work; the one thing you cannot do is resell the kit itself.

How many domains can it watch?

Checks run every six hours, one domain at a time, 1.5 seconds apart, to stay polite to the free registries. That covers the dozens of domains a typical agency manages with room to spare. The design's ceiling is about 200 domains per cycle inside Cloudflare's scheduled-run window. We have not load-tested past that; email first if your list is bigger.

Where do alerts go?

To the phones that installed the app and enabled push. There is no Slack, webhook, or email channel today. If your team needs alerts in a shared channel, CertSentry does not do that yet; buy it for the phone ping.

What is it NOT?
  • Not uptime monitoring. It watches expiry dates and never pings your sites.
  • It renews nothing for you. It warns you in time to renew.
  • crt.sh data can lag. A certificate renewed this morning may show its old date for some hours.
  • Private CAs and internal-only domains are out of scope. The data sources are public registries and public certificate logs.

Get it

$49 one-time

Full source · unlimited projects · free updates to the kit

Launching soon. Leave your email and the launch link lands in your inbox the moment it is live. One email, no list, no spam.