Troubleshoot your first workspace
Start with the symptom below. These steps apply to TokenTimer Cloud; operators running Core or Enterprise should also inspect SMTP and worker health in the self-hosted first-asset guide.
No expiry alert arrived
- Confirm the recipient address. Check the email recorded on the workspace contact. Email-and-password sign-in requires a verified account address; if sign-in is blocked, request a new verification email from the sign-in screen.
- Find the asset in the correct workspace. Open Details → Alerting and alert history. Confirm its expiration date and upcoming thresholds. An asset marked Never expires has no scheduled expiry reminder.
- Check eligibility. In Control Center → Workspace alerting → Eligibility, distinguish an asset that is outside its thresholds from one that is due. A file or provider import suppresses already-passed thresholds. Expired assets need a configured negative threshold for post-expiry follow-ups. Retired certificates do not send expiry alerts.
- Check recipients. An asset uses its assigned contact groups, or the workspace default when none are assigned. Confirm that at least one matching group includes your email and its email channel. For multiple groups, a threshold delivers only to groups that include that threshold.
- Check delivery. Review Queue, Activity, and the asset's alert history. A closed delivery window, retries, a delivery cap, or a frozen workspace can delay or prevent delivery. Check the window timezone, Usage & limits, and spam filtering.
Resolved: history records a successful delivery and the message arrives. Saving an asset or seeing a pending queue entry does not prove delivery. See Expiry reminders and thresholds for scheduling and retry details.
An import did not add the expected asset
- Confirm the workspace selection and scan filters before importing.
- For file uploads, compare the preview row count with the file and check required fields, especially
expiresAt. The dashboard excludes undated rows; use2099-12-31for a Never expires record. See Import from file. - Read the scan summary for permission failures, partial results, or item limits. A completed request can still have incomplete provider coverage.
- Re-importing the same name and location can update an existing asset rather than create another row. Search before assuming it is missing.
- Credentials without an exposed expiry can appear as Never expires; set a meaningful rotation date manually if you want reminders.
- Check the provider's permissions guide and your plan allowance.
Leave obsolete-item cleanup disabled while diagnosing an incomplete scan. It can delete inventory records and cannot be undone. See Obsolete-token cleanup.
A control is unavailable
Check your workspace role and plan. Viewers can read asset details and history; managers and admins can manage assets and workspace alerting. CertOps requires Pro or Team. A frozen workspace is read-only. See Roles, Plan limits, and Downgrade behavior.
Get help
Contact support@tokentimer.ch. Include the symptom, time and timezone, workspace and asset identifiers, and any visible error code. Say which steps above you checked. Never include passwords, integration credentials, machine API tokens, private keys, or session cookie jars.
For failed renewals, use CertOps policy and verification troubleshooting and Certificate renewal failure alerts.