TokenTimer
Open-source expiration tracker for certificates, API tokens, secrets and licenses, with alerts and automated renewal, self-hosted or cloud.
🔗 Visit TokenTimerDescription
An expired TLS certificate or a forgotten API token can take down a production service with almost no warning — the kind of outage that's entirely preventable if someone had simply been reminded a few weeks earlier. TokenTimer exists to be that reminder system: it scans an organization's infrastructure for anything with an expiration date and makes sure a human finds out before it becomes a problem, not after.
TokenTimer discovers certificates, API tokens, secrets, and software licenses across an infrastructure, tracks their expiration dates, sends alerts ahead of time, and automates renewal where the underlying system supports it. It's designed around metadata-only security, meaning it tracks when things expire without needing to store the actual secret values, which reduces the blast radius if the tracking system itself is ever compromised. It's open source and available on GitHub, with both a cloud-managed SaaS option and a self-hosted deployment for teams that want to keep tracking data entirely in-house.
💬 Our review
The short version: TokenTimer addresses a genuinely common and expensive failure mode — expired certs and tokens causing outages — with a metadata-only design that's a sensible security posture for a tool whose whole job is watching sensitive things.
Compared to general secrets managers like HashiCorp Vault or cloud-native options like AWS Secrets Manager, TokenTimer isn't trying to store or rotate secrets itself — it's a focused expiration-tracking and alerting layer, which makes it complementary rather than a replacement for those tools in many setups. Against simply setting calendar reminders or writing a custom cron script, TokenTimer's advantage is centralized discovery across an entire infrastructure plus automated renewal where possible, rather than relying on someone remembering to check. The open-source, self-hostable option is a real plus for security-conscious teams that don't want expiration data leaving their own infrastructure; the SaaS option is a reasonable convenience trade-off for smaller teams. The lack of public pricing detail on the site is a minor friction for anyone trying to budget before reaching out.
💰 Pricing
📊 Global score
🤖 AI-enriched data
Auto-hébergement open-source gratuit possible ; version SaaS cloud-managée, tarifs non publiés
Pros
Découverte automatique des certificats, tokens, secrets et licences
Sécurité metadata-only, ne stocke pas les valeurs sensibles
Renouvellement automatisé quand le système sous-jacent le permet
Open source, auto-hébergeable ou en SaaS cloud
Cons
Tarifs non publiés
Ne remplace pas un vrai gestionnaire de secrets comme Vault
Renouvellement automatique dépendant des systèmes cibles
