TigerTrust ships with first-party integrations across five categories. Every integration is opt-in and configured per workspace. Credentials are stored encrypted and can be tested from the product before being used in production workflows.

Integration categories

Cloud providers

Discover certificates in AWS ACM, Azure Key Vault, and Google Certificate Manager. Results flow into Certificate Inventory automatically.

DNS providers

12 DNS APIs for ACME DNS-01 challenges and record automation — Cloudflare, Route 53, Azure DNS, Google Cloud DNS, DigitalOcean, Linode, Vultr, Hetzner, DNSimple, Namecheap, GoDaddy, and NS1.

Identity (SSO)

SAML 2.0, OIDC / OAuth 2 (Google built-in), and SCIM 2.0 provisioning.

Notifications

Email, Slack, Microsoft Teams, PagerDuty, generic webhook, and SMS fan-out for alerts, expiry warnings, and workflow events.

Outbound webhooks

Signed webhooks for every domain event.

API keys

Environment-scoped keys for programmatic access and agent enrollment.

Cloud providers

Discovers ACM certificates across every commercial region, ALB and NLB listener certificates, IAM server certificates, and KMS-backed private keys. See AWS setup.
Discovers Key Vault certificates, App Service certificates, Application Gateway SSL and trusted-root certificates, and AKS managed-cluster certificates via the Azure Resource Manager API. See Azure setup.
Discovers Certificate Manager certificates (managed and self-managed), global SSL certificates on Compute Engine load balancers, GKE cluster CA certificates, and Cloud KMS keys. See GCP setup.

DNS providers

Used primarily to solve ACME DNS-01 challenges when issuing publicly-trusted certificates. All 12 providers support zone listing, TXT record creation and deletion, and connection testing. Full provider list and credential requirements at DNS providers.

Identity

Full IdP-initiated and SP-initiated flows with attribute mapping, auto-provisioning, and allowed-domain enforcement. Tested with Okta, Azure AD, JumpCloud, and OneLogin.

Notification channels

TigerTrust routes alerts through channels configured in Settings > Notifications. Supported types: email, Slack, Teams, PagerDuty, webhook, and SMS. See Notification channels.

Outbound webhooks

Every workspace can register multiple webhook endpoints. Each delivery is signed with an HMAC secret. See Webhooks.

API keys

Two types:
  • API keys (ck_*) — user-scoped, expirable, with a custom scope list. Use for dashboards, scripts, and CI pipelines.
  • Agent keys (ak_*) — used by TigerTrust field agents connecting to the control plane. Fixed scopes covering agent connectivity and certificate reporting.
Full details at API keys.

Next steps

Connect AWS

Start with cloud discovery — see every ACM certificate in minutes.

Wire up DNS

Required for ACME DNS-01 issuance of wildcard certificates.

Enable SSO

Delegate authentication to your IdP and provision users automatically.

Configure alerts

Route expiry, revocation, and anomaly alerts to Slack or PagerDuty.