What would you like to do?
Choose an action to get started.
Manage
Recent Certificates
What domain(s) do you need a certificate for?
One domain per line. Use *.domain for wildcards.
A friendly name to identify this certificate. Auto-filled from first domain.
How do you manage DNS for this domain?
Choose how DNS validation will work for the ACME certificate challenge.
No DNS providers configured. .
Add this CNAME record
Add the following record at the DNS provider for :
*.),
the same CNAME record works - no additional record needed.
Verifying DNS records
Checking DNS records for ...
DNS changes can take a few minutes to propagate.
CNAME Record
NS Delegation
Tips:
- DNS changes can take up to 5 minutes to propagate
- Check that the CNAME record was saved correctly at the DNS provider
- Make sure the NS delegation for the zone is active
Assign to Client
Select which client agent should have access to this certificate, or create a new API key.
Or create a new API key:
Selected:
Certificate Configuration
Configure the certificate settings before issuing.
Requires EAB credentials from the provider portal.
External Account Binding (EAB)
Generate these credentials from your provider portal. For SSLTrust: login → SSL Manager → ACME Credentials → Create New. For ZeroSSL: login → Developer → EAB Credentials → Generate.
Certificate Requested
Certificate issuance is in progress...
This typically takes 30-60 seconds. The page will update automatically.
Certificate issued successfully!
- expires
Certificate issuance failed
Certificates
| Time | Host | Target | Deployed | Verified | Detail |
|---|---|---|---|---|---|
DNS Providers
Delegated DNS Entries
These entries are created automatically when you use the Issue Certificate (Delegated DNS) wizard. Each entry represents a CNAME delegation for a customer domain.
CNAME:
NS delegation:
Client API Keys
Each client/agent gets their own key. Disable a key to immediately cut off access.
.env is currently the only way to authenticate.
Created ·
Config backed up ·
Settings
Notification and scheduler configuration
Saving…
Settings saved.
Leave blank to disable webhook notifications.
Certificate lifecycle (server)
Agent deployment reports (client)
Comma-separated days. A warning is sent each time the scheduler runs and the cert is exactly this many days from expiry.
How often the server checks for certificates due for renewal. Changing this takes effect immediately.
Fire an agent_offline webhook if a client agent hasn't checked in within this many hours. Set to 0 to disable.
Test Webhook
Send a sample payload to your configured URL to verify delivery and formatting.
Assign Certificate
Assign to a client API key so the client agent can access it.