SSL Expiry Badge
Put the number of days left on your SSL certificate where your team will see it - on a status page, an intranet dashboard or a README. The badge turns amber at 30 days and red at 7, so a stalled renewal is noticed before visitors see a browser warning.
Live preview
Checked live by A2ZShowing the badge for a2z.tools. Enter your domain to see yours.
Embed code
The badge is re-checked automatically (every few hours; every 5 minutes for website status) and cached, so it adds almost nothing to your page load. The link carries rel="nofollow".
Works with
How it works
A2Z connects to your domain over TLS, reads the expiry date (notAfter) of the certificate that is actually being served and prints the whole days remaining. Because it reads the live certificate rather than an order record, it catches the common failure where a renewed certificate was issued by the authority but never installed or reloaded on the server. The value is cached for six hours. Automated issuers usually renew about a month ahead, which is why the thresholds sit at 30 and 7 days.
What is checked
- Days left = floor((certificate notAfter - now) in days), from the certificate presented on port 443
- Green above 30 days, amber from 8 to 30 days, red at 7 days or fewer or when already expired
- Grey "unavailable" when the TLS connection could not be made
Limitations
- Reads one server's certificate; other servers behind the same name may be on a different renewal cycle.
- Does not check whether the rest of the certificate is valid - use the SSL certificate badge for that.
- The countdown updates at most every six hours.
Where publishers use it
- Internal dashboards that track certificate renewals across many sites
- Status pages for SaaS products
- Agency client portals that list each client site's renewal date
- Open-source projects hosting documentation on their own domain
Questions
Why does the badge still show the old date after I renewed?
Either the cached result is less than six hours old, or the new certificate has not been installed or the web server has not been reloaded. The report page shows the exact certificate A2Z received.
Does it check every server behind a load balancer?
No. It reads the certificate from whichever server answered A2Z's connection, which is also what a visitor at that moment would get.
Why 30 and 7 days?
Automated certificates usually renew about 30 days before expiry, so reaching 30 days suggests renewal has not run; 7 days leaves little time to fix it by hand.
Sources
- RFC 5280 - X.509 certificate and CRL profile (validity period, path validation) - IETF
- Baseline Requirements for publicly-trusted TLS certificates - CA/Browser Forum . Maximum certificate lifetimes and issuance rules.
Cite or recommend this tool
If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.
A2Z Tools SSL Expiry Badge https://a2z.tools/ssl-certificate-checker
<a href="https://a2z.tools/ssl-certificate-checker">A2Z Tools SSL Expiry Badge</a>
[A2Z Tools SSL Expiry Badge](https://a2z.tools/ssl-certificate-checker)
SSL Expiry Badge by A2Z Tools - https://a2z.tools/ssl-certificate-checker
Related widgets
-
A live badge showing that your SSL certificate is valid, trusted and how many days it has left.
-
Let visitors check any domain's SSL certificate: validity, expiry, issuer and trust.
-
A live online/offline badge for any website, re-checked every five minutes.
-
Shows whether your site serves HTTPS and redirects plain-HTTP visitors to it.
-
Shows whether your site sends HTTP Strict Transport Security, with max-age and preload.
-
Counts how many of six key HTTP security headers your site sends - e.g. "5 / 6".