TokenTimer

TokenTimer

Open-source expiration tracker for certificates, API tokens, secrets and licenses, with alerts and automated renewal, self-hosted or cloud.

🔗 Visit TokenTimer
📁 Security & Privacy🗣️ English📅 August 24, 2026

Description

An expired TLS certificate or a forgotten API token can take down a production service with almost no warning — the kind of outage that's entirely preventable if someone had simply been reminded a few weeks earlier. TokenTimer exists to be that reminder system: it scans an organization's infrastructure for anything with an expiration date and makes sure a human finds out before it becomes a problem, not after.

TokenTimer discovers certificates, API tokens, secrets, and software licenses across an infrastructure, tracks their expiration dates, sends alerts ahead of time, and automates renewal where the underlying system supports it. It's designed around metadata-only security, meaning it tracks when things expire without needing to store the actual secret values, which reduces the blast radius if the tracking system itself is ever compromised. It's open source and available on GitHub, with both a cloud-managed SaaS option and a self-hosted deployment for teams that want to keep tracking data entirely in-house.

💬 Our review

The short version: TokenTimer addresses a genuinely common and expensive failure mode — expired certs and tokens causing outages — with a metadata-only design that's a sensible security posture for a tool whose whole job is watching sensitive things.

Compared to general secrets managers like HashiCorp Vault or cloud-native options like AWS Secrets Manager, TokenTimer isn't trying to store or rotate secrets itself — it's a focused expiration-tracking and alerting layer, which makes it complementary rather than a replacement for those tools in many setups. Against simply setting calendar reminders or writing a custom cron script, TokenTimer's advantage is centralized discovery across an entire infrastructure plus automated renewal where possible, rather than relying on someone remembering to check. The open-source, self-hostable option is a real plus for security-conscious teams that don't want expiration data leaving their own infrastructure; the SaaS option is a reasonable convenience trade-off for smaller teams. The lack of public pricing detail on the site is a minor friction for anyone trying to budget before reaching out.

💰 Pricing

Not disclosedSelf-hosted (open-source) or cloud-managed SaaS; specific pricing not published on the site.

📊 Global score

53Average
🌐Availability15/100Faible

1 language · 0 platform

📄Profile90/100Excellent

Profile completeness

🤖 AI-enriched data

💰 Pricing model
💳 Non communiqué

Auto-hébergement open-source gratuit possible ; version SaaS cloud-managée, tarifs non publiés

👥 Target audienceÉquipes DevOps, IT ops et sécurité gérant certificats, tokens API, secrets et licences logicielles
🗣️ Languagesen
🌍 Target countriesInternational
👍

Pros

Découverte automatique des certificats, tokens, secrets et licences

Sécurité metadata-only, ne stocke pas les valeurs sensibles

Renouvellement automatisé quand le système sous-jacent le permet

Open source, auto-hébergeable ou en SaaS cloud

👎

Cons

Tarifs non publiés

Ne remplace pas un vrai gestionnaire de secrets comme Vault

Renouvellement automatique dépendant des systèmes cibles

❓ Frequently asked questions

What is TokenTimer in one sentence?
Does TokenTimer store my actual secrets and passwords?
Can TokenTimer renew certificates automatically?
Can I self-host TokenTimer?
How much does TokenTimer cost?
Is it worth the money compared to alternatives?
Which tool should you pick for your case?