Roadmap
This is where we're headed, but we'd rather build what you actually need. Vote on the features that matter to you, or tell us what we're missing.
Get updates from us
Get notified when we ship features from the roadmap. Join our newsletter.
In progress
We are currently building these features. Vote to help us prioritize.
-
Google Trust Services (and other ACME Issuers)
Support for other ACME issuers like Google Trust Services and specifying custom EAB.
High priority
These are features often requested by customers, or critical to the next step in our vision.
-
DNS-PERSIST-01 Validation
Switch certificate validation over to DNS-PERSIST-01 once implemented by Let's Encrypt.
-
Audit Log
View, search, and export an audit log from your account. See who has logged in, interacted with certificate, agents, or alerting. Audit the automatic renewal and deployment actions of CertKit.
-
Private CA
Issue private certificates directly from CertKit. Trust your account's root Certificate and generate unlimited certificates signed by CertKit.
-
Advanced Alerting
Configure customized alerting types, rules, and destinations
-
Certificate Tags
Create and manage tags for certificates to organize by owner, department, or use case. UI search and filtering by tag.
Backlog
Features that we think are neat, or have been requested, but we're not sure where they fit into the plan yet.
-
IP Certificates
Certificates for IP Addresses with HTTP-01 Validation
-
Self-serve rotate API keys
Rotate and re-issue API keys from the UI.
-
Certificate Transparency Log API
API access to the Certificate Transparency Log to do advanced searches and firehose data.
-
Certificate Push
Agent, gateway, or other mechanism to "push" certificates into appliances or systems that are unable to run the agent themselves. This might look like a scripted API call or allowing the agent to upload certificates via SSH or file share.
-
Microsoft Exchange
Agent integration to update Microsoft Exchange server certificates
-
Data Sovereignty
Keep your hosted certificates geographically located in the EU, UK, or other locations
-
Certificate Transparency Log Monitoring
Setup alerts when new certificates show up in the CTLog, or when a certificate from the log changes status or expires.
Completed
All the things that CertKit already does today!
-
Microsoft Remote Desktop
Released 2026-03 • Blog Announcement
Agent integration to update RDP Certificates
-
Java Keystore
Released 2026-03 • Blog Announcement
Add and renew certificates into a Java Keystore.
-
CertKit Keystore (formerly known as the Local Gateway)
Released 2026-03 • Blog Announcement
A on-premise installable service for the generation and storage of certificate private keys.
-
ARI Certificate Renewal
Released 2026-03 • Blog Announcement
Honor the ARI certificate renewal timing from Let's Encrypt.
-
6-Day Certificates
Released 2026-03 • Blog Announcement
Support for Let's Encrypt's short-term 6 day certificates.
-
Single Sign On
Released 2026-03 • Blog Announcement
SAML-compliant SSO implementation
-
User management and roles
Released 2026-03 • Blog Announcement
Add/invite/remote users from your account. Give them permissions for applications and support manager and viewer roles.
-
Weekly Email Summary
Released 2026-03 • Blog Announcement
Weekly summary email of certificates, renewals, expirations, and agent status. Also the ability to subscribe/unsubscribe from email.
-
Microsoft RRAS VPN Support
Released 2026-02 • Blog Announcement
Expand the Windows agent to include support for Microsoft Routing and Remote Access Service.
-
Host Agent
Released 2026-02 • Blog Announcement
The agent simplifies the distribution of certificates to your infrastructure. The agent runs as a service on each of your hosts, allowing you to configure the services and certificates to distribute to each host.
-
Multiple applications
Released 2026-01 • Blog Announcement
Create multiple groups of certificates within an account. Each group should have its own access credentials.
-
Multi-domain certificates
Released 2025-12 • Blog Announcement
Create multi-domain (multi-san) certificates. Allow the control of the certificate Common Name (CN).
-
Certificate Transparency Log Search
Released 2025-11 • Blog Announcement
Be able to search for all the certificates in a domain from the Certificate Transparency Log, and import them to be monitored or managed by CertKit.
Get updates from us
Get notified when we ship features from the roadmap. Join our newsletter.