Skip to main content
An alert under Settings > Alerts covers certificates across Certificate Manager for one event, whether or not they belong to an Application. Without filters, it covers every certificate. To alert on a single application, create an application alert instead. Certificate Manager alerts use the same events and notification channels as application alerts. They can also alert on signer certificate expiration for Code Signing.

Prerequisites

  • The Certificate Manager Admin role to create or edit an alert
  • For Slack, PagerDuty, and webhook channels, the Enterprise plan. Email channels are available on every plan.
  • For email alerts, recipients who are organization members, or addresses on one of your organization’s verified email domains

Create an alert

1
Go to Certificate Manager > Settings and select the Alerts tab.
2
Select Create Alert.
3
Select the Alert Type from the Certificate Lifecycle or Code Signing group, then enter an Alert Name and an optional Description. For an expiration alert, enter Alert Before as a number and a unit, for example 30d or 2w, up to 365 days. Turn on Repeat daily until expiry to get a reminder every day. See how often expiration alerts repeat. Select Continue.
4
On the Filters step, optionally select Add Filter to narrow the alert by Applications, Certificate Profiles, or Source. See which certificates an alert covers. Matched Certificates lists the active certificates the alert covers. Select Continue.
5
Select Add Channel and choose where to send notifications. You can add up to 10 channels. Select Continue.
6
Check the summary on the Review step, then select Create Alert.

Which certificates an alert covers

If you don’t add a filter, the alert covers every certificate in Certificate Manager. Each filter you add narrows the alert, and a certificate must match every filter: For example, a Source filter set to Imported covers every imported certificate, including ones outside any application or profile. Add an Applications filter as well, and the alert covers only the imported certificates in those applications. You can select up to 100 applications and 100 profiles.

Signer certificate expiration

A Signer Certificate Expiration alert, in the Code Signing group, warns you before the certificate a signer currently signs with expires. It covers every active signer under Code Signing > Signers, has no filters, and skips the Filters step. It works like a certificate expiration alert: set Alert Before and optionally Repeat daily until expiry. Only each signer’s current certificate counts. When you reissue a signer’s certificate, the alert follows the new one and stops alerting on the one it replaced. Signers that are disabled, failed, or still pending aren’t covered.

FAQ

The alert keeps the deleted application or profile in its list, and the deleted one matches no certificates. When you edit the alert, the Filters step shows it as Unknown application or Unknown profile, so you can remove it.
The same webhook payload format as application alerts. These examples show one alert of each type:

What’s next?

Application alerts

Alert on the certificates in one application.

Webhook

Send alerts to your own endpoint.