Uptime monitoring
Catch downtime the moment it happens, from multiple regions, before your customers notice.
SSL certificate and domain expiry monitoring on every HTTPS monitor. Reminders up to 90 days ahead, and silence once you’ve renewed.
On every plan, Free included. 20 monitors free, no credit card required.
Automated renewals fail without a sound: an expired API token, a DNS change, a full disk. Pick when the first alert goes out, from 90 days to a day before expiry, with reminders after it.
Expiry alertsA server that doesn’t send its intermediates still works in most browsers, which repair the chain. curl, Android and API clients don’t. Hyperping verifies the chain the way they do.
Chain validationAfter a key leak or a mis-issuance, the authority revokes the certificate. Hyperping checks the stapled response, the OCSP responder and the revocation list, which is what Let’s Encrypt now relies on.
Revocation checksA new subdomain behind the wrong load balancer, a CDN serving someone else’s certificate. Every name the certificate covers is matched against the host, wildcards included, the way browsers match them.
Hostname checksCurrent browsers refuse servers that only speak TLS 1.0 or 1.1. Hyperping flags them, along with SHA-1 or MD5 signatures and keys shorter than 2048-bit RSA.
TLS and crypto checksWhen a registration lapses, the website, email and certificates go down together, and anyone can buy the name. Hyperping reads the expiry date from the registry and reminds you ahead of time.
Domain expiry monitoringEach check opens a TLS connection the way a browser would and verifies what the server actually serves. A certificate your provider renewed but your server doesn’t serve yet still counts as expiring.
The certificate, or an intermediate the server relies on, is past its end date.
The start date is in the future, often a server clock problem or a certificate installed too early.
None of the names in the certificate covers the monitored host. Wildcards and IP addresses are matched like browsers do.
The certificate signs itself instead of being issued by an authority.
The chain ends at an authority browsers don’t trust, such as a private or internal CA.
The server doesn’t send its intermediate certificates. Some browsers repair this; curl, Android and most API clients don’t.
Any other reason the chain doesn’t verify against the public trust store.
The authority revoked the certificate. Checked with the stapled response, the OCSP responder or the revocation list (CRL).
The server only offers TLS 1.0 or 1.1, which current browsers refuse.
The certificate or an intermediate is signed with SHA-1 or MD5.
A key shorter than 2048-bit RSA or 224-bit ECDSA.
Checked on every HTTPS monitor, and on port monitors whose port speaks TLS directly: 443, 8443, 993, 995, 465, 636, 8883 and more. A URL like https://example.com:8443 is checked on its own port.
Choose the first alert per monitor. Reminders follow at 30, 15, 7, 3 and 1 days below it, and stop the moment the new certificate is served.
Pick how many days before expiry the first alert goes out, per monitor, in its Notifications tab. Or never.
With reminders on, one follows at each step below the threshold. If a check couldn’t run the day a reminder was due, it goes out on the next one, once.
Email and chat channels get every reminder. PagerDuty and Opsgenie are only paged in the final day, and the renewal resolves the page.
The certificate is read again right before each reminder. Renewed in the meantime, nothing goes out. Already warned, you get a renewed notice instead.
Certificate errors and reminders go to the monitor’s SSL channels and to your team by email. PagerDuty and Opsgenie are paged in the last 24 hours only.
When a registration lapses, the website, email and certificates stop at once, and an expired domain can be bought by someone else. Domain expiry alerts warn you first.
The registered domain behind each monitor, api.status.example.co.uk checked as example.co.uk, for HTTP, ping, port and DNS monitors. Daily inside 45 days, weekly before that.
Ten monitors on the same domain in a project send one reminder, not ten, at the earliest threshold among them: 7, 14, 30, 60 or 90 days before the registration ends.
Registrars often renew in the last days, so the registry is asked again right before each reminder. Renewed meanwhile, nothing goes out, and any PagerDuty or Opsgenie page is resolved.
Read from the registry over RDAP, the successor of WHOIS. Six monitors point at example.com, so its reminders go out once, at the earliest threshold among them.
ssl_alert_days, ssl_reminders, ssl_notify_on_change and domain_alert_days, in the API, the Terraform provider and the MCP server, so every new monitor ships with the right thresholds.
Turn on certificate change notifications to see each renewal, new issuer or new key, with the new and the previous certificate side by side. A CDN rotating several certificates doesn’t trigger it.
Webhooks get certificate errors in the same shape as downtime alerts. Notices carry their own event and isDown: false, so a consumer acting on down ignores them.
curl -X PUT https://api.hyperping.io/v1/monitors/mon_123abc \
-H "Authorization: Bearer $API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"ssl_alert_days": 30,
"ssl_reminders": true,
"ssl_notify_on_change": true,
"domain_alert_days": 30
}'
@hyperping is really amazing

Hyperping’s reputation in our company is that it’s more reactive than Datadog. We usually get notifications from Hyperping before Datadog.

We picked Hyperping to bring a high quality incidents and status reporting dashboard to our users.

We have the real-time alerts from Hyperping telling us if the app is down. These are sometimes arriving even before AWS notices or notifies us.

We couldn’t imagine running our SaaS business without Hyperping now.

Hyperping nails all aspects: from smooth setup to peace of mind and attentive customer service.
You learn your site is down from a customer’s support ticket.
Catch downtime the moment it happens, from multiple regions, before your customers notice.
A lightweight agent tracks CPU, memory and disk, so you spot trouble before it turns into downtime.
Playwright tests that catch broken sign-ins and checkouts before your customers do.
Get alerted when a backup or scheduled job silently fails to run, not days later.
Alerts reach the right person on Slack,
Teams, SMS or a phone call, whichever wakes them up.
Keep certificates in check. Get alerted before they expire, so your customers always connect securely.
Plan rotations, share the load, and see who’s on call. Every incident reaches the right person, at the right time.
USD · Monthly billing for every plan
Three subscriptions to keep it all running.
$747/month
$8,964 over 12 monthsEverything connected, from the first check.
$299/month
$3,588 over 12 monthsSave $5,376 a year with this mix.
Reviewed . All amounts are USD; local currency prices may differ.
This is one example of a three-tool stack, not the cheapest possible setup or a feature-for-feature match. Pingdom and PagerDuty also include status-page features; a separate Statuspage subscription may not be needed by every team. Usage charges and paid connectors are not included. Annual totals are 12 monthly payments, not annual subscription quotes.
SSL monitoring checks the TLS certificate a server actually serves and warns you before it expires or stops being trusted. Hyperping checks the certificate of every HTTPS monitor once a day, with no extra setup: expiry, hostname, chain, trust, revocation, TLS version and signature strength. See SSL monitoring in the docs.
You choose per monitor: 1, 3, 7, 15, 30, 60 or 90 days before expiry, or never. With reminders on, another alert follows at each step below that threshold, so 30 days means alerts at 30, 15, 7, 3 and 1 days. If the certificate is renewed in the meantime, the remaining reminders are skipped.
Expired and not yet valid certificates, hostname mismatches, self-signed certificates, untrusted roots, incomplete or invalid chains, revoked certificates, servers that only offer TLS 1.0 or 1.1, and SHA-1 or MD5 signatures. Weak keys are shown on the monitor without sending an alert. A new problem alerts the monitor’s SSL channels, and a resolved notification follows once everything is fixed.
Yes. It uses the OCSP response the server staples, then the authority’s OCSP responder, then its certificate revocation list (CRL). The CRL step matters for Let’s Encrypt, which stopped running OCSP in 2025.
Yes. Domain expiry alerts read the registration’s expiry date from the registry, over RDAP or WHOIS, and remind you 7 to 90 days before it lapses. Ten monitors on the same domain send one reminder, not ten. Monitors created from the dashboard start at 14 days. Registries that don’t publish dates, such as .de, .eu, .ch, .be and .nl, are skipped. See domain expiry monitoring.
Expiry reminders go to everyone on the project by email and to the monitor’s SSL notification channels: Slack, Microsoft Teams, Discord, Google Chat, Telegram and webhooks. PagerDuty and Opsgenie are only paged in the last 24 hours, and the renewal resolves the page. See integrations.
Yes. SSL and domain expiry monitoring are included on every plan, Free included, for every HTTPS monitor you create. The Free plan includes 20 monitors and needs no credit card. See pricing.
Yes. Monitors in the API take ssl_alert_days, ssl_reminders, ssl_notify_on_change and domain_alert_days, and return the days left in ssl_expiration and domain_expiration. The Terraform provider’s hyperping_monitor resource and the MCP server take the same settings.