Self-hosted certificate control
One vault for every TLS certificate.
Issue, renew, protect, and distribute certificates across your homelab from one focused control plane.
DNS-01 automation
Encrypted at rest
Scoped client access
Automated issuance
Obtain wildcard and multi-domain certificates through any DNS provider supported by lego.
Protected material
Keep ACME account keys and certificate private keys authenticated-encrypted at rest.
Controlled delivery
Give clients only the operations and certificate artifacts they are explicitly allowed to use.
Operational clarity
See certificate health at a glance.
The responsive console brings validity, renewal activity, version history, ACME accounts, API keys, and audit events into one place.
Explore operations →
A focused control plane for your homelab.
Warning
CertVault can return private keys. Do not expose it over plaintext HTTP outside a trusted local development environment.