In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select Cert Spotter, then click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select Cert Spotter and enter an integration name
- Configure the default route and select a channel; after creation, add more rules under Route if needed
- Click Save and copy the generated Push URL
Configure Cert Spotter
Webhook notifications are available on the Cert Spotter Startup plan and above. The Hobbyist plan only sends email.
1
Add a webhook
- Sign in to SSLMate and open the Cert Spotter Settings page
- In the notification settings, add a webhook and paste the full Flashduty push URL as the webhook URL. The URL must include
integration_key - Save the settings
integration_key in the URL, so keep the push URL as secret as a key.2
Turn on the auto-resolve timeout
An unknown certificate is a one-shot event: after the certificate is revoked, expires, or is confirmed by you, Cert Spotter sends nothing more. In the channel that receives these alerts, turn on the auto-resolve timeout. We suggest a timeout of 24 hours, counted from Incident trigger. Closing the incident also closes its alerts.
3
Verify
Cert Spotter has no button that sends a test delivery. Issue a new certificate for a sub-domain you already monitor (for example with Let’s Encrypt). Once the certificate reaches the CT logs, Cert Spotter delivers it as an unknown certificate and a matching alert appears in Flashduty.
Payload
Cert Spotter sends expiration reminders and installation problems only by email and Slack, not by webhook, so they do not reach this integration.
Alert Key
Flashduty uses the ID of the certificate issuance (
id in the webhook) as the Alert Key. A network problem can deliver the same request more than once; the duplicate carries the same id and merges into the same alert. Different certificates create different alerts.
Deliveries without id are rejected.
Severity
Cert Spotter sends no severity, so every unknown certificate triggers a Warning alert. Whether the certificate has been revoked is recorded in the
revoked label and does not change the severity.
Labels
The alert title is
Unknown certificate for <first monitored name>, followed by (+N more) when the certificate covers several names.
FAQ
Why did a certificate I issued myself not create an alert?
Why did a certificate I issued myself not create an alert?
Cert Spotter only notifies you about unknown certificates. Certificates registered through the Cert Spotter authorization API are known certificates and do not trigger the webhook.
Are failed deliveries retried?
Are failed deliveries retried?
The webhook must return 2xx within 15 seconds, and redirects are not followed. Cert Spotter does not retry failed requests automatically; it emails you instead, and you can ask SSLMate to resend them. Make sure the push URL is complete and includes
integration_key.Why does the alert never close?
Why does the alert never close?
Cert Spotter has no recovery event. Turn on the channel’s auto-resolve timeout, or close the alert manually in Flashduty.