Agencies

Certwatch for Agencies: SSL certificate and domain expiry monitoring you own forever

SSL certificate and domain expiry monitoring you own forever.

Agencies pay per-seat and per-client fees that scale with their success. Self-hosted, pay-once tools replace per-seat pricing with a flat cost that margins actually survive.

The tool this job usually means renting is SSLMate-style SSL monitors, at $10–20/mo — roughly $180 a year, every year. Certwatch does the job for a one-time $24 — running on infrastructure you control.

Fit check

Why it fits how agencies work

🚦 Traffic-light dashboard

Green over 30 days, yellow at 30 or under, red under 7 days, or for expired, invalid or unreachable hosts.

For agencies, traffic-light dashboard pays off across every client account, with no per-seat math — and it's covered by the same one-time $24, not metered per month.

🤝 Real TLS handshake checks

Node tls checks expiry, issuer, SAN list, chain validity, self-signed certs and weak keys (RSA under 2048, EC under 224).

For agencies, real TLS handshake checks pays off across every client account, with no per-seat math — and it's covered by the same one-time $24, not metered per month.

🌐 Domain WHOIS expiry

Best-effort registry lookups so the domain registration itself does not lapse either.

For agencies, domain WHOIS expiry pays off across every client account, with no per-seat math — and it's covered by the same one-time $24, not metered per month.

Workflow

A typical workflow

STEP 01

Buy once on Whop

One payment of $24 gets you the packaged 1-click installer, or clone the MIT source at github.com/bensblueprints/ssl-cert-monitor-mvp and run it yourself for free.

STEP 02

Deploy on your own server

docker compose up on a $5 VPS that can reach your hosts, or run the Electron desktop build, adding SMTP credentials to .env if you want email alerts.

STEP 03

Add your domains

Point it at the sites you care about; it runs real TLS handshakes on a schedule and pages you before anything expires.

What it costs, honestly

Certwatch is $24, once. SSLMate-style SSL monitors at $10–20/mo — roughly $180 a year, every year. Two months of a paid SSL monitor covers Certwatch, and one cert it saves from expiring covers the 2am page it would have cost you.

FAQ

Agencies ask

Is Certwatch worth it for agencies?

Two months of a paid SSL monitor covers Certwatch, and one cert it saves from expiring covers the 2am page it would have cost you. Certwatch costs $24 once; SSLMate-style SSL monitors charges $10–20/mo — about $180 a year. For agencies, that fixed cost is the whole point: the tool is a one-time line item, not a monthly one.

Is it really free on GitHub?

Yes. Certwatch is MIT-licensed at github.com/bensblueprints/ssl-cert-monitor-mvp and always will be. The $24 buys the packaged 1-click installer; building from source is free.

Where does my monitoring data live?

In a SQLite database on your own server. The checker connects directly to your hosts, so run it from a box that can reach them, and nothing goes to any third-party API.

Own Certwatch forever — $24