Key Expiry Tracker for Openclaw

A metadata-only tracker that alerts you before your API keys, client secrets, and certificates expire to prevent unexpected service outages.

tradmangh
v1.0.2
Feb 17, 2026
0
0
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install key-expiry-tracker

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install key-expiry-tracker using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Key Expiry Tracker?

Key Expiry Tracker is a lightweight utility designed for the security-conscious developer. It manages the lifecycle of your credentials by tracking their expiration metadata without ever handling the actual sensitive secrets. By focusing strictly on timestamps and labels within the Openclaw Skills ecosystem, it ensures your privacy while providing essential uptime protection.

This skill is ideal for teams managing multiple third-party integrations, cloud providers, or SSL certificates. It bridges the gap between manual spreadsheets and complex enterprise secret management systems by offering a simple, JSON-driven approach to credential health within your agent's workspace. Because it only processes metadata, it remains a highly secure way to maintain visibility over your environment using Openclaw Skills.

Key Expiry Tracker Use Cases

  • Tracking Azure Client Secret expiration to prevent authentication failures in automated workflows.
  • Monitoring SSL/TLS certificate validity for self-hosted services and public endpoints.
  • Setting up proactive reminders for third-party API keys like OpenAI or AWS before they rotate.
  • Maintaining a centralized metadata repository for all team-wide credentials within Openclaw Skills.
  • Managing recurring password rotation schedules for internal system accounts.

How Key Expiry Tracker Works

  1. The user defines credential metadata, including the name, type, and expiration date, in a local configuration file.
  2. A tracking script parses the local JSON data to calculate the remaining time until each credential expires.
  3. The system evaluates the time delta against predefined warning and critical thresholds (14 and 7 days).
  4. Automated alerts are generated via system events or manual checks to notify the developer of pending expirations.
  5. Integration with the broader Openclaw Skills framework allows for scheduled weekly audits using built-in cron capabilities.

Key Expiry Tracker Setup

First, ensure you have the skill directory initialized within your workspace. You can manually create or edit the .credentials.json file located in ~/.openclaw/workspace/. To add a credential, populate the JSON file with the appropriate metadata:

{
  "credentials": [
    {
      "name": "Azure OpenClaw Calendar",
      "type": "client-secret",
      "expires": "2026-03-15T00:00:00Z",
      "provider": "Microsoft Azure",
      "notes": "For M365 calendar integration"
    }
  ]
}

To run a manual check, execute the following command in your terminal:

~/.openclaw/workspace/skills/key-expiry-tracker/scripts/check-credentials.sh

To automate the process within the Openclaw Skills environment, add a cron schedule to run every Sunday:

cron add --name "key-expiry-tracker" \
  --schedule "0 10 * * 0" \
  --payload '{"kind":"systemEvent","text":"Run key-expiry-tracker weekly check"}' \
  --sessionTarget main

Key Expiry Tracker Data Schema & Taxonomy

The skill utilizes a standard JSON schema to organize metadata. All data is stored locally in ~/.openclaw/workspace/.credentials.json for maximum privacy within Openclaw Skills.

Field Type Description
name String A unique label for the credential (Required).
type String Category: client-secret, api-key, certificate, token, or password (Required).
expires String ISO-8601 timestamp of the expiration date (Required).
provider String The service provider, e.g., Azure, AWS, or Cloudflare (Optional).
renewed String ISO-8601 timestamp of the last renewal date (Optional).
notes String Contextual information for the integration (Optional).

Key Expiry Tracker Advanced Features

  • Automated cron scheduling for hands-off monitoring within Openclaw Skills.
  • Zero-knowledge architecture that never touches or stores actual secret values.
  • Color-coded alerting thresholds for immediate visual identification of critical status (14 days for Warning, 7 days for Critical).
  • Low token consumption (approx. 200-500 tokens) for cost-efficient background monitoring.
  • Support for multiple credential types including certificates, OAuth tokens, and API keys.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*