Back to Blog
New
Agents

Monitor private certificates with agents

June 24, 2026 · 4 min read

Not every certificate lives on the public internet. Internal APIs, admin panels, and service-to-service mTLS all rely on certificates that expire just as surely as your public ones — and are far easier to forget. With NxMon agents, those private certificates get the same proactive alerting as everything else.

How it works

Deploy the lightweight agent inside your network. It reaches the internal endpoints you point it at, reads their certificate chains, and reports expiry, issuer, and chain health back to NxMon over an outbound, authenticated connection. No inbound firewall rules required.

One dashboard for everything

Private and public certificates show up side by side. Alerts, escalation policies, and notification channels work identically no matter where the certificate lives.

Getting started

Create an agent under Settings → Agents to receive a scoped enrollment token, run the agent, and assign it the internal domains you want watched.