> ## Documentation Index
> Fetch the complete documentation index at: https://infisical.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Alerts

> Get notified about certificate events anywhere in Certificate Manager, inside or outside an application.

An alert under **Settings** > **Alerts** covers certificates across Certificate Manager for one event, whether or not they belong to an [Application](/docs/documentation/platform/pki/applications/overview). Without filters, it covers every certificate. To alert on a single application, create an [application alert](/docs/documentation/platform/pki/applications/alerting/overview) instead.

Certificate Manager alerts use the same events and [notification channels](/docs/documentation/platform/pki/applications/alerting/overview#notification-channels) as application alerts. They can also alert on [signer certificate expiration](#signer-certificate-expiration) for **Code Signing**.

## Prerequisites

* The Certificate Manager **Admin** role to create or edit an alert
* For Slack, PagerDuty, and webhook channels, the Enterprise plan. Email channels are available on every plan.
* For email alerts, recipients who are organization members, or addresses on one of your organization's [verified email domains](/docs/documentation/platform/email-domain)

## Create an alert

<Steps>
  <Step>
    Go to **Certificate Manager** > **Settings** and select the **Alerts** tab.
  </Step>

  <Step>
    Select **Create Alert**.
  </Step>

  <Step>
    Select the **Alert Type** from the **Certificate Lifecycle** or **Code Signing** group, then enter an **Alert Name** and an optional **Description**. For an expiration alert, enter **Alert Before** as a number and a unit, for example `30d` or `2w`, up to 365 days. Turn on **Repeat daily until expiry** to get a reminder every day. See [how often expiration alerts repeat](/docs/documentation/platform/pki/applications/alerting/overview#faq). Select **Continue**.
  </Step>

  <Step>
    On the **Filters** step, optionally select **Add Filter** to narrow the alert by **Applications**, **Certificate Profiles**, or **Source**. See [which certificates an alert covers](#which-certificates-an-alert-covers). **Matched Certificates** lists the active certificates the alert covers. Select **Continue**.
  </Step>

  <Step>
    Select **Add Channel** and choose where to send notifications. You can add up to 10 channels. Select **Continue**.
  </Step>

  <Step>
    Check the summary on the **Review** step, then select **Create Alert**.
  </Step>
</Steps>

## Which certificates an alert covers

If you don't add a filter, the alert covers every certificate in Certificate Manager. Each filter you add narrows the alert, and a certificate must match every filter:

| Filter | Certificates covered |
| - | - |
| **Applications** | Certificates in one of the selected applications |
| **Certificate Profiles** | Certificates issued from one of the selected profiles |
| **Source** | Certificates with one of the selected sources: **Managed** for certificates issued through Certificate Manager, **Imported**, or **Discovered** |

For example, a **Source** filter set to **Imported** covers every imported certificate, including ones outside any application or profile. Add an **Applications** filter as well, and the alert covers only the imported certificates in those applications.

You can select up to 100 applications and 100 profiles.

## Signer certificate expiration

A **Signer Certificate Expiration** alert, in the **Code Signing** group, warns you before the certificate a signer currently signs with expires. It covers every active signer under **Code Signing** > **Signers**, has no filters, and skips the **Filters** step. It works like a certificate expiration alert: set **Alert Before** and optionally **Repeat daily until expiry**.

Only each signer's current certificate counts. When you reissue a signer's certificate, the alert follows the new one and stops alerting on the one it replaced. Signers that are disabled, failed, or still pending aren't covered.

## FAQ

<AccordionGroup>
  <Accordion title="What happens to an alert when I delete an application or profile it lists?">
    The alert keeps the deleted application or profile in its list, and the deleted one matches no certificates. When you edit the alert, the **Filters** step shows it as **Unknown application** or **Unknown profile**, so you can remove it.
  </Accordion>

  <Accordion title="What do webhook receivers get from Certificate Manager alerts?">
    The same [webhook payload format](/docs/documentation/platform/pki/applications/alerting/webhook-alerts#webhook-payload-format) as application alerts. These examples show one alert of each type:

    <CodeGroup>
      ```json Certificate alert theme={"dark"}
      {
        "specversion": "1.0",
        "type": "com.infisical.cert-manager.certificate.revocation",
        "source": "/alerts/453421e2-2e73-4700-92c8-60ccd3e7073e",
        "id": "8360c717-097a-4592-a2b0-63c494c3b558",
        "time": "2026-10-05T21:37:35.935Z",
        "datacontenttype": "application/json",
        "subject": "cert-manager.certificate.revocation",
        "data": {
          "alert": {
            "id": "453421e2-2e73-4700-92c8-60ccd3e7073e",
            "name": "prod-revocations",
            "resourceType": "cert-manager"
          },
          "items": [
            {
              "id": "4f70e08e-ad7a-4f94-ac16-241126ab88ed",
              "title": "api.example.com",
              "summary": "Certificate 'api.example.com' was revoked in application 'payments-api'",
              "severity": "warning",
              "fields": [
                { "label": "Serial Number", "value": "77c2b1368a7dd4a8442c61d51d20cbdb2060a1e5" },
                { "label": "Profile", "value": "tls-server" },
                { "label": "Application", "value": "payments-api" },
                { "label": "Expires", "value": "November 4, 2026 at 09:37 PM UTC" },
                { "label": "Revocation Reason", "value": "Unspecified" }
              ],
              "resource": {
                "id": "4f70e08e-ad7a-4f94-ac16-241126ab88ed",
                "serialNumber": "77c2b1368a7dd4a8442c61d51d20cbdb2060a1e5",
                "commonName": "api.example.com",
                "altNames": [],
                "status": "revoked",
                "notBefore": "2026-10-05T21:37:28.426Z",
                "notAfter": "2026-11-04T21:37:28.426Z",
                "revokedAt": "2026-10-05T21:37:30.299Z",
                "revocationReason": 0,
                "profileId": "8d04ef1b-67cd-4021-8da4-b3096d11133b",
                "profileName": "tls-server",
                "applicationId": "d6e7232b-ffa5-48bf-9133-4731c6d001a0",
                "applicationName": "payments-api"
              }
            }
          ],
          "metadata": {
            "totalItems": 1,
            "viewUrl": "https://app.infisical.com/organizations/<org-id>/projects/cert-manager/<project-id>/inventory"
          }
        }
      }
      ```

      ```json Signer certificate expiration theme={"dark"}
      {
        "specversion": "1.0",
        "type": "com.infisical.cert-manager.signer.certificate.expiry",
        "source": "/alerts/9b3c1d2e-5f6a-4b7c-8d9e-0f1a2b3c4d5e",
        "id": "2c4e6a8b-1d3f-4a5c-9e7b-0d2f4a6c8e1b",
        "time": "2026-10-05T00:05:00.000Z",
        "datacontenttype": "application/json",
        "subject": "cert-manager.signer.certificate.expiry",
        "data": {
          "alert": {
            "id": "9b3c1d2e-5f6a-4b7c-8d9e-0f1a2b3c4d5e",
            "name": "signer-expiry",
            "resourceType": "cert-manager.signer"
          },
          "items": [
            {
              "id": "7e1f3a5c-9b2d-4e6f-8a0c-1d3e5f7a9b2c",
              "title": "release signing",
              "summary": "Certificate 'release signing' of signer 'release-signer' expires on October 25, 2026 at 12:00 AM UTC",
              "severity": "warning",
              "fields": [
                { "label": "Signer", "value": "release-signer" },
                { "label": "Serial Number", "value": "0a1b2c3d4e5f60718293a4b5c6d7e8f901234567" },
                { "label": "Expires", "value": "October 25, 2026 at 12:00 AM UTC" }
              ],
              "resource": {
                "id": "7e1f3a5c-9b2d-4e6f-8a0c-1d3e5f7a9b2c",
                "serialNumber": "0a1b2c3d4e5f60718293a4b5c6d7e8f901234567",
                "commonName": "release signing",
                "altNames": [],
                "status": "active",
                "notBefore": "2025-10-25T00:00:00.000Z",
                "notAfter": "2026-10-25T00:00:00.000Z",
                "signerIds": ["3d5f7a9b-2c4e-4f6a-8b0d-1e3f5a7c9e2b"],
                "signerNames": ["release-signer"]
              }
            }
          ],
          "metadata": {
            "totalItems": 1,
            "viewUrl": "https://app.infisical.com/organizations/<org-id>/projects/cert-manager/<project-id>/code-signing"
          }
        }
      }
      ```
    </CodeGroup>
  </Accordion>
</AccordionGroup>

## What's next?

<CardGroup cols={2}>
  <Card title="Application alerts" icon="bell" href="/docs/documentation/platform/pki/applications/alerting/overview">
    Alert on the certificates in one application.
  </Card>

  <Card title="Webhook" icon="webhook" href="/docs/documentation/platform/pki/applications/alerting/webhook-alerts">
    Send alerts to your own endpoint.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.