Skip to main content
Cert Spotter is SSLMate’s certificate monitoring service. It continuously watches Certificate Transparency logs, and when it finds a certificate issued for one of your monitored domains that you did not know about (an unknown certificate), it can call a webhook. This integration turns each unknown certificate into one Flashduty alert.

In Flashduty On-call


You can obtain an integration push URL in either of the following ways.

Use a dedicated integration

  1. In the Flashduty console, select Channel and open a channel
  2. Select Configuration → Integrations → Private integration, then click Add an integration
  3. Select Cert Spotter, then click Save
  4. Open the generated integration card and copy the Push URL

Use a shared integration

  1. In the Flashduty console, select Integration Center → Alert Events
  2. Select Cert Spotter and enter an integration name
  3. Configure the default route and select a channel; after creation, add more rules under Route if needed
  4. Click Save and copy the generated Push URL

Configure Cert Spotter


Webhook notifications are available on the Cert Spotter Startup plan and above. The Hobbyist plan only sends email.
1

Add a webhook

  1. Sign in to SSLMate and open the Cert Spotter Settings page
  2. In the notification settings, add a webhook and paste the full Flashduty push URL as the webhook URL. The URL must include integration_key
  3. Save the settings
The push URL does not need an HTTP Basic Authentication username and password. Flashduty identifies the integration by the integration_key in the URL, so keep the push URL as secret as a key.
2

Turn on the auto-resolve timeout

An unknown certificate is a one-shot event: after the certificate is revoked, expires, or is confirmed by you, Cert Spotter sends nothing more. In the channel that receives these alerts, turn on the auto-resolve timeout. We suggest a timeout of 24 hours, counted from Incident trigger. Closing the incident also closes its alerts.
3

Verify

Cert Spotter has no button that sends a test delivery. Issue a new certificate for a sub-domain you already monitor (for example with Let’s Encrypt). Once the certificate reaches the CT logs, Cert Spotter delivers it as an unknown certificate and a matching alert appears in Flashduty.

Payload


Cert Spotter sends expiration reminders and installation problems only by email and Slack, not by webhook, so they do not reach this integration.

Alert Key


Flashduty uses the ID of the certificate issuance (id in the webhook) as the Alert Key. A network problem can deliver the same request more than once; the duplicate carries the same id and merges into the same alert. Different certificates create different alerts. Deliveries without id are rejected.

Severity


Cert Spotter sends no severity, so every unknown certificate triggers a Warning alert. Whether the certificate has been revoked is recorded in the revoked label and does not change the severity.

Labels


The alert title is Unknown certificate for <first monitored name>, followed by (+N more) when the certificate covers several names.

FAQ


Cert Spotter only notifies you about unknown certificates. Certificates registered through the Cert Spotter authorization API are known certificates and do not trigger the webhook.
The webhook must return 2xx within 15 seconds, and redirects are not followed. Cert Spotter does not retry failed requests automatically; it emails you instead, and you can ask SSLMate to resend them. Make sure the push URL is complete and includes integration_key.
Cert Spotter has no recovery event. Turn on the channel’s auto-resolve timeout, or close the alert manually in Flashduty.
For field details, see Cert Spotter Webhooks.