> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Cert Spotter alert integration

> Sync unknown certificates detected by Cert Spotter to Flashduty On-call through a webhook.

Cert Spotter is SSLMate's certificate monitoring service. It continuously watches Certificate Transparency logs, and when it finds a certificate issued for one of your monitored domains that you did not know about (an unknown certificate), it can call a webhook. This integration turns each unknown certificate into one Flashduty alert.

<div className="hide">
  ## In Flashduty On-call

  ***

  You can obtain an integration push URL in either of the following ways.

  ### Use a dedicated integration

  1. In the Flashduty console, select **Channel** and open a channel
  2. Select **Configuration** → **Integrations** → **Private integration**, then click **Add an integration**
  3. Select **Cert Spotter**, then click **Save**
  4. Open the generated integration card and copy the **Push URL**

  ### Use a shared integration

  1. In the Flashduty console, select **Integration Center → Alert Events**
  2. Select **Cert Spotter** and enter an integration name
  3. Configure the default route and select a channel; after creation, add more rules under **Route** if needed
  4. Click **Save** and copy the generated **Push URL**
</div>

## Configure Cert Spotter

***

Webhook notifications are available on the Cert Spotter Startup plan and above. The Hobbyist plan only sends email.

<Steps>
  <Step title="Add a webhook">
    1. Sign in to SSLMate and open the Cert Spotter **Settings** page
    2. In the notification settings, add a webhook and paste the full Flashduty push URL as the webhook URL. The URL must include `integration_key`
    3. Save the settings

    The push URL does not need an HTTP Basic Authentication username and password. Flashduty identifies the integration by the `integration_key` in the URL, so keep the push URL as secret as a key.
  </Step>

  <Step title="Turn on the auto-resolve timeout">
    An unknown certificate is a one-shot event: after the certificate is revoked, expires, or is confirmed by you, Cert Spotter sends nothing more. In the channel that receives these alerts, turn on the [auto-resolve timeout](/en/on-call/channel/create-edit). We suggest a timeout of **24 hours**, counted from **Incident trigger**. Closing the incident also closes its alerts.
  </Step>

  <Step title="Verify">
    Cert Spotter has no button that sends a test delivery. Issue a new certificate for a sub-domain you already monitor (for example with Let's Encrypt). Once the certificate reaches the CT logs, Cert Spotter delivers it as an unknown certificate and a matching alert appears in Flashduty.
  </Step>
</Steps>

## Payload

***

| Cert Spotter event | Result in Flashduty |
| :- | :- |
| Unknown Certificate | Triggers one Warning alert |
| New Endpoint (a newly discovered sub-domain; beta, enabled by emailing SSLMate) | Returns success, creates no alert |

Cert Spotter sends expiration reminders and installation problems only by email and Slack, not by webhook, so they do not reach this integration.

## Alert Key

***

Flashduty uses the ID of the certificate issuance (`id` in the webhook) as the Alert Key. A network problem can deliver the same request more than once; the duplicate carries the same `id` and merges into the same alert. Different certificates create different alerts.

Deliveries without `id` are rejected.

## Severity

***

Cert Spotter sends no severity, so every unknown certificate triggers a **Warning** alert. Whether the certificate has been revoked is recorded in the `revoked` label and does not change the severity.

## Labels

***

| Label | Source |
| :- | :- |
| `issuance_id` | Certificate issuance ID, which is the Alert Key |
| `url` | The certificate's detail page in Cert Spotter |
| `endpoints` | Your monitored domain names that the certificate covers |
| `monitored_domains` | The monitored domains that match those names |
| `dns_names` | Every DNS name in the certificate |
| `issuer` | Name of the issuing certificate authority, such as `Sectigo` |
| `issuer_name` | Full subject of the issuer certificate |
| `not_before` / `not_after` | Start and end of the certificate's validity |
| `revoked` | Whether the certificate has been revoked |
| `cert_sha256` | SHA-256 fingerprint of the certificate |

The alert title is `Unknown certificate for <first monitored name>`, followed by `(+N more)` when the certificate covers several names.

## FAQ

***

<AccordionGroup>
  <Accordion title="Why did a certificate I issued myself not create an alert?">
    Cert Spotter only notifies you about unknown certificates. Certificates registered through the [Cert Spotter authorization API](https://sslmate.com/help/reference/certspotter_authorization_api) are known certificates and do not trigger the webhook.
  </Accordion>

  <Accordion title="Are failed deliveries retried?">
    The webhook must return 2xx within 15 seconds, and redirects are not followed. Cert Spotter does not retry failed requests automatically; it emails you instead, and you can ask SSLMate to resend them. Make sure the push URL is complete and includes `integration_key`.
  </Accordion>

  <Accordion title="Why does the alert never close?">
    Cert Spotter has no recovery event. Turn on the channel's auto-resolve timeout, or close the alert manually in Flashduty.
  </Accordion>
</AccordionGroup>

For field details, see [Cert Spotter Webhooks](https://sslmate.com/help/reference/certspotter_webhook).
