Hesklo
Home/Features/SSL expiry tracking
SSL expiry tracking

Never be surprised by a certificate again.

Every HTTPS monitor tracks its certificate expiry automatically. There is nothing extra to configure and nothing extra to pay for. Branch on days remaining in a policy and the warning arrives while there is still time to act.

  • Automatic on every HTTPS check. If a monitor uses HTTPS, the certificate countdown comes with it. There is no separate certificate monitor to create.
  • Branch on days remaining. An if / else branch can test whether a certificate expires within N days and route the flow accordingly.
  • Warn early, not at the deadline. Because you choose the threshold, a warning can arrive weeks ahead rather than on the morning it breaks.
01 · How it works

A countdown that comes for free.

Tracked on every HTTPS monitor

The expiry date is read as part of the normal check. You do not create a separate monitor or enable an extra feature.

Days remaining, visible

The current countdown appears alongside response time and uptime on the monitor, so it is part of the picture rather than buried.

A branch condition on the canvas

An if / else branch offers "certificate expiring within N days" as a condition, which means renewal warnings use the same policy machinery as outages.

Any destination

Route the warning wherever it will actually be seen: a channel, a named engineer, a Jira ticket that becomes a scheduled task.

02 · Why it still matters

Automation does not remove the risk.

Most certificates renew themselves now, which is exactly why the failures that do happen catch people off guard.

Automation fails quietly

A renewal job that stops working gives no signal until the certificate actually expires. A countdown notices the gap; the job cannot report its own absence.

Certificates you do not control

Vendor endpoints, partner APIs and appliances with manual certificates are the ones most likely to lapse and least likely to be watched.

A full outage, instantly

An expired certificate does not degrade a service. Every browser and client rejects it at once, and the fix takes longer than the warning would have.

Cheap insurance

The check costs nothing extra because it rides along with a monitor you already wanted.

Questions

Common questions

Do I need a separate monitor to track SSL expiry?
No. Certificate expiry is tracked automatically on every HTTPS monitor as part of the normal check. There is nothing extra to create, enable or pay for.
How do I get warned before a certificate expires?
Use an if / else branch in the escalation policy with the condition "certificate expiring within N days". You choose the threshold and where the warning goes, so it can reach a channel weeks before anything breaks.
My certificates renew automatically. Is this still useful?
Usually yes, because the risk is not the certificate, it is the renewal job. When automation stops working it does so silently, and the first signal is the expired certificate itself. A countdown notices the problem while there is still time to fix it.
Does this work for certificates I do not manage?
Yes. Any HTTPS endpoint you can monitor has its expiry tracked, which makes it useful for vendor APIs and partner services where you have no visibility into their renewal process.
Keep reading

Related features

Get the warning while it is still cheap.

Add an HTTPS monitor, branch on certificate days remaining, and stop finding out from a customer.