Roadmap

This is where we're headed, but we'd rather build what you actually need. Vote on the features that matter to you, or tell us what we're missing.

In progress

We are currently building these features and expect to launch them in the coming weeks.

  1. Host Agent

    The agent simplifies the distribution of certificates to your infrastructure. The agent runs as a service on each of your hosts, allowing you to configure the services and certificates to distribute to each host.

High priority

These are features often requested by customers, or critical to the next step in our vision.

  1. Single Sign On

    SAML-compliant SSO implementation

  2. User management and roles

    Add/invite/remote users from your account. Give them permissions for applications and support manager and viewer roles.

  3. Advanced Alerting

    Configure customized alerting types, rules, and destinations

  4. Certificate Tags

    Create and manage tags for certificates to organize by owner, department, or use case. UI search and filtering by tag.

  5. DNS-PERSIST-01 Validation

    Switch certificate validation over to DNS-PERSIST-01 once implemented by Let's Encrypt.

  6. ARI Certificate Renewal

    Honor the ARI certificate renewal timing from Let's Encrypt.

Backlog

Features that we think are neat, or have been requested, but we're not sure where they fit into the plan yet.

  1. Local Gateway

    A proxy and private key storage service that runs locally in the customer's environment.

  2. Private CA

    Issue private certificates directly from CertKit. Trust your account's root Certificate and generate unlimited certificates signed by CertKit.

  3. Other Issuers

    Support for other ACME issuers like Digicert, ZeroSSL, etc.

  4. Self-serve rotate API keys

    Rotate and re-issue API keys from the UI.

  5. Certificate Transparency Log API

    API access to the Certificate Transparency Log to do advanced searches and firehose data.

Completed

All the things that CertKit already does today!

  1. Multiple applications

    launched 2026-01

    Create multiple groups of certificates within an account. Each group should have its own access credentials.

  2. Multi-domain certificates

    launched 2025-12

    Create multi-domain (multi-san) certificates. Allow the control of the certificate Common Name (CN).

  3. Certificate Transparency Log Search

    launched 2025-11

    Be able to search for all the certificates in a domain from the Certificate Transparency Log, and import them to be monitored or managed by CertKit.