0
0 Comments

Update on credOclock - shipped a lot since launch, still hunting for real signal

Posted a few weeks back about credOclock, a tool that tracks expiring API keys, SSL certs, and webhooks so your team gets a heads-up before something breaks instead of after.

Quick update on where it's at.

Shipped since launch:

Auto SSL detection, ack/snooze links right in the reminder email, and Slack/Discord/Teams alerts, all live and tested for real, not just in my own head.

Rotation tracking. A credential can have its own rotation schedule, separate from its expiry date, and get flagged if it's overdue. Turns out "the automation that rotates this key quietly stopped working three months ago" is its own failure mode, distinct from "this is about to expire."

The bigger one: real role-based permissions (Admin, Member, Viewer) and per-client credential scoping. That second part specifically came out of thinking harder about who'd actually use this, agencies and MSPs managing infrastructure for multiple clients out of one team, who need to control who on their own team can see which client's stuff. Wasn't part of the original plan, became obvious once I thought about the actual buyer.

Also ran a proper security pass on the whole thing and fixed what needed fixing. Not going to list specifics publicly, that's not a flex, it's just common sense, but it's part of why I'm comfortable saying this is solid enough for a real team to actually use now.

Still true from the first post: genuinely no idea yet if this is a problem other teams actually feel, or if it was mostly my own itch. Free tier's still there, 5 credentials, no card. If you've ever had a cert lapse on a Saturday or a key nobody remembered to rotate, curious if this is useful or if I'm solving a problem that doesn't really exist outside my own head.

credoclock.com if you want to look. Feedback, especially the "this doesn't solve my actual problem" kind, is genuinely welcome.

posted toAvatar for product credOclock
credOclock