Skip to content

KrakenKey documentation

KrakenKey issues TLS certificates through ACME DNS-01. You do a one-time DNS setup per domain, and certificates arrive in about four minutes. Your private keys stay with you: KrakenKey only ever sees the certificate signing request.

  • Getting started: add a domain, set up its DNS records, and issue your first certificate.
  • How KrakenKey fits your stack: how issuance works, where the private key can live, and which setup matches what you run.
  • Set up with an AI agent: point your coding agent at the runbook, do the few steps that need a person, and say go.
  • KrakenKey CLI: issue, submit, download and renew certificates from a terminal or CI job.
  • API reference: every endpoint in the KrakenKey REST API.
  • nginx and HAProxy: issue on the server, point the proxy at the files, and renew with a systemd timer.
  • Caddy: load a KrakenKey wildcard with the tls directive for internal hosts, with no DNS credentials on the proxy.
  • GitHub Actions: issue once, renew on a schedule, and deploy to servers over SSH only when they serve an older certificate.
  • AWS Certificate Manager, ALB, and CloudFront: import into ACM, keep the key in Secrets Manager, and re-import each renewal to the same ARN.
  • Terraform: register domains, publish their DNS records, issue certificates and set up monitoring in code, without the private key in state.
  • Azure Key Vault, App Service, and Container Apps: keep the private key in Key Vault, have KrakenKey sign its CSR, and bind the certificate in App Service or Container Apps.