Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

Jump to content

Draft:TokenTimer

From Wikipedia, the free encyclopedia

TokenTimer
DeveloperTokentimer Sàrl
TypeCertificate lifecycle management; expiration management
LicenseAGPL-3.0 (TokenTimer Core)
Websitetokentimer.ch

TokenTimer is a software platform for tracking and managing the expiration of digital assets, including digital certificates, API keys, secrets, software licenses and other time-bound resources.[1][2] It is developed by Tokentimer Sàrl, a Swiss limited-liability company registered in Carouge, in the canton of Geneva, in 2026.[3]

TokenTimer is available as a hosted software-as-a-service product and as TokenTimer Core, a self-hosted edition deployable with Docker Compose or Kubernetes and Helm.[1][4] TokenTimer Core is distributed under version 3 of the GNU Affero General Public License (AGPL-3.0).[5]

A certificate-lifecycle subsystem called CertOps coordinates certificate inventory, renewal, deployment and verification. Its architecture separates a central control plane from operations involving private keys: the control plane schedules and records jobs, while key-bearing operations execute in infrastructure controlled by the operator.[6] The concept received brief independent attention in the site-reliability newsletter SRE Weekly, which in September 2026 highlighted an article about the approach and described the deployment step after renewal as an important part of certificate operations.[7]

History

[edit]

Tokentimer Sàrl was entered in the Geneva commercial register on 24 April 2026, following statutes dated 13 April 2026; the registration was published in the Swiss Official Gazette of Commerce on 29 April 2026.[3] The company's registered purpose includes the design, development and operation of software and SaaS products concerned with digital assets, certificates, licenses, technical identities, governance, traceability and auditability.[3]

TokenTimer Core was released publicly in 2026 as the self-hosted edition of the platform. The project initially used the Business Source License before being relicensed under AGPL-3.0.[8][5] In the September 2026 HackerNoon article, TokenTimer founder Franz Alliod attributed the licensing change to a desire to emphasize transparency, adoption and community trust as the project expanded into certificate automation.[8]

During 2026 the product expanded from expiration monitoring into certificate-lifecycle automation. Alliod described the change as a shift from detecting upcoming certificate expirations toward coordinating renewal, deployment, service reload and runtime verification.[8] He also described this model in contributed technical articles published by DevOps.com and All Things Open.[9][10]

Expiration management

[edit]

TokenTimer uses the term token for a tracked item with an expiration date rather than only for an authentication credential. Tracked categories include certificates, keys and secrets, licenses and general time-bound assets. Items can be organized into workspaces and assigned ownership or contact groups that determine who receives expiration notifications.[2]

Assets can be entered manually, imported from structured files, discovered from monitored HTTPS endpoints, or imported through integrations. The service documents integrations with systems including HashiCorp Vault, GitHub, GitLab, Amazon Web Services, Microsoft Azure, Microsoft Entra ID and Google Cloud Platform.[11] For one-time cloud integration scans, TokenTimer states that it retrieves metadata such as names, locations and expiration dates rather than secret values or private keys, and discards the supplied scan credentials after use.[11]

The platform supports threshold-based notifications and keeps audit information associated with tracked assets and certificate operations. Self-hosted deployments can run within an organization's own network and can monitor internal endpoints and private DNS names.[4]

Certificate operations

[edit]

TokenTimer's certificate-lifecycle functionality is called CertOps. The documented lifecycle extends expiration monitoring into certificate issuance or renewal, deployment, service reload and verification of the certificate presented by the live service.[8][9]

The CertOps control plane stores certificate inventory and metadata, schedules work, signs jobs and records execution evidence. Operations requiring access to certificate private keys are designed to execute outside the control plane.[6] TokenTimer's documentation describes three execution approaches: an outbound-only TokenTimer agent installed on operator-controlled hosts; a controller used with cert-manager in Kubernetes; and external executors, such as existing scripts or continuous-integration jobs, which report job events through scoped machine API tokens.[6]

For agent-based execution, agents poll the control plane over outbound HTTPS to claim signed jobs. The platform also provides approval gates, limits on simultaneous renewals, failure notifications and a workspace-level pause mechanism for automated certificate operations.[6] The separation between the orchestration layer and the execution environment is intended to avoid transferring certificate private keys to TokenTimer's control plane.[6][10]

TokenTimer distinguishes certificate inventory from renewal eligibility. Its documentation states that a certificate can be monitored without being automatically renewable; automatic renewal additionally requires local key custody, a usable renewal profile and an execution path able to deploy the new certificate.[12]

Deployment and editions

[edit]

TokenTimer's documentation distinguishes a hosted Cloud service from self-hosted editions. TokenTimer Core runs on operator-controlled infrastructure using Docker Compose or Kubernetes with Helm.[1][4] The self-hosted product uses workspaces for isolation, role-based access control and audit logging, and includes the base CertOps functionality.[4]

A separately licensed Enterprise self-hosted edition adds features aimed at organizational identity and compliance requirements, including SAML and OpenID Connect single sign-on, expanded scheduled integration synchronization and additional CertOps compliance reporting.[13]

Coverage

[edit]

TokenTimer's writing about certificate-expiration incidents has been cited by independent DevOps and site-reliability publications. In August 2026, SRE Weekly issue 530 included TokenTimer's analysis Certificate Expiry Is Still Taking Down Major Platforms, noting that it linked to several incident write-ups.[14][15] The article was also included among the sources discussed in episode 62 of the DevOps and SRE news podcast Ship It Weekly.[16]

In September 2026, SRE Weekly issue 535 selected Alliod's HackerNoon article about certificate monitoring and deployment. The newsletter summarized the distinction between monitoring certificate expiry and successfully deploying a renewed certificate, and specifically noted the article's use of the term CertOps.[7][8]

Articles about the project's certificate-renewal design have also appeared on DevOps.com and All Things Open, although both were written by TokenTimer founder Franz Alliod rather than independent journalists.[9][10]

Licensing

[edit]

TokenTimer Core is licensed under AGPL-3.0.[5] In his September 2026 HackerNoon article, Alliod stated that the project had previously used the Business Source License and had subsequently moved to AGPL-3.0.[8] The hosted service and the separately licensed Enterprise edition are distributed under different commercial arrangements.[13]

See also

[edit]

References

[edit]
  1. 1 2 3 "TokenTimer Documentation". TokenTimer Docs. Tokentimer Sàrl. Retrieved 28 September 2026.
  2. 1 2 "Token model". TokenTimer Docs. Tokentimer Sàrl. Retrieved 28 September 2026.
  3. 1 2 3 "Nouvelles entrées Tokentimer Sàrl, Carouge (GE)". Swiss Official Gazette of Commerce. Swiss Federal Office of Justice. 29 April 2026. Retrieved 28 September 2026.
  4. 1 2 3 4 "TokenTimer Self-hosted". TokenTimer Docs. Tokentimer Sàrl. Retrieved 28 September 2026.
  5. 1 2 3 "LICENSE". GitHub. Tokentimer Sàrl. Retrieved 28 September 2026.
  6. 1 2 3 4 5 "Certificate Automation". TokenTimer Docs. Tokentimer Sàrl. Retrieved 28 September 2026.
  7. 1 2 "SRE Weekly Issue #535". SRE Weekly. 20 September 2026. Retrieved 28 September 2026.
  8. 1 2 3 4 5 6 Alliod, Franz (16 September 2026). "Your Certificate Monitoring Can Work Perfectly and You Can Still Have an Outage". HackerNoon. Retrieved 28 September 2026.
  9. 1 2 3 Alliod, Franz (28 August 2026). "Certificate Renewal Is a Deployment Workflow, Not a Cron Job". DevOps.com. Techstrong Group. Retrieved 28 September 2026.
  10. 1 2 3 Alliod, Franz (25 September 2026). "How we built certificate renewal without sending private keys to the control plane". All Things Open. Retrieved 28 September 2026.
  11. 1 2 "Integrations overview". TokenTimer Docs. Tokentimer Sàrl. Retrieved 28 September 2026.
  12. ↑ "Renew certificates automatically". TokenTimer Docs. Tokentimer Sàrl. Retrieved 28 September 2026.
  13. 1 2 "TokenTimer Enterprise". TokenTimer Docs. Tokentimer Sàrl. Retrieved 28 September 2026.
  14. ↑ "SRE Weekly Issue #530". SRE Weekly. 16 August 2026. Retrieved 28 September 2026.
  15. ↑ "Certificate Expiry Is Still Taking Down Major Platforms". TokenTimer. Tokentimer Sàrl. August 2026. Retrieved 28 September 2026.
  16. ↑ Teller, Brian (21 August 2026). "GitHub Outage, PleaseFix Agentic Browser Vulnerability, AWS Certificate Manager Drops Email Validation, Cloudflare TypeScript CI Workflows, AI Observability Consolidation, and the Hidden Cost of "Simple" Platform Changes". Apple Podcasts (Podcast). No. 62. Ship It Weekly. Retrieved 28 September 2026.
[edit]