Integration categories
Cloud providers
Discover certificates in AWS ACM, Azure Key Vault, and Google Certificate Manager. Results flow into Certificate Inventory automatically.
DNS providers
12 DNS APIs for ACME DNS-01 challenges and record automation — Cloudflare, Route 53, Azure DNS, Google Cloud DNS, DigitalOcean, Linode, Vultr, Hetzner, DNSimple, Namecheap, GoDaddy, and NS1.
Identity (SSO)
SAML 2.0, OIDC / OAuth 2 (Google built-in), and SCIM 2.0 provisioning.
Notifications
Email, Slack, Microsoft Teams, PagerDuty, generic webhook, and SMS fan-out for alerts, expiry warnings, and workflow events.
Outbound webhooks
Signed webhooks for every domain event.
API keys
Environment-scoped keys for programmatic access and agent enrollment.
Cloud providers
AWS
AWS
Discovers ACM certificates across every commercial region, ALB and NLB listener certificates, IAM server certificates, and KMS-backed private keys. See AWS setup.
Azure
Azure
Discovers Key Vault certificates, App Service certificates, Application Gateway SSL and trusted-root certificates, and AKS managed-cluster certificates via the Azure Resource Manager API. See Azure setup.
GCP
GCP
Discovers Certificate Manager certificates (managed and self-managed), global SSL certificates on Compute Engine load balancers, GKE cluster CA certificates, and Cloud KMS keys. See GCP setup.
DNS providers
Used primarily to solve ACME DNS-01 challenges when issuing publicly-trusted certificates. All 12 providers support zone listing, TXT record creation and deletion, and connection testing. Full provider list and credential requirements at DNS providers.Identity
- SAML 2.0
- OIDC / OAuth 2
- SCIM 2.0
Full IdP-initiated and SP-initiated flows with attribute mapping, auto-provisioning, and allowed-domain enforcement. Tested with Okta, Azure AD, JumpCloud, and OneLogin.
Notification channels
TigerTrust routes alerts through channels configured in Settings > Notifications. Supported types: email, Slack, Teams, PagerDuty, webhook, and SMS. See Notification channels.Outbound webhooks
Every workspace can register multiple webhook endpoints. Each delivery is signed with an HMAC secret. See Webhooks.API keys
Two types:- API keys (
ck_*) — user-scoped, expirable, with a custom scope list. Use for dashboards, scripts, and CI pipelines. - Agent keys (
ak_*) — used by TigerTrust field agents connecting to the control plane. Fixed scopes covering agent connectivity and certificate reporting.
Next steps
Connect AWS
Start with cloud discovery — see every ACM certificate in minutes.
Wire up DNS
Required for ACME DNS-01 issuance of wildcard certificates.
Enable SSO
Delegate authentication to your IdP and provision users automatically.
Configure alerts
Route expiry, revocation, and anomaly alerts to Slack or PagerDuty.