All templates

Automated OneSignal Push Credential Checks

Every Monday, WebRun signs into OneSignal, opens the platform settings for each of your apps, reads the state of the iOS push credential and the Android service account behind them, checks recent delivery status for signs of a failing platform, and flags anything expiring or invalid in Slack and Telegram.

Runs on WebRun · Strict Lockdown policy
Every Monday at 8:00 AM WebRunorchestrates each step
1 OneSignal check every app's push credentials
2 Slack flag what needs replacing
3 Telegram ping the mobile team
In short

How do I know when my push notification credentials are about to expire?

Every Monday, WebRun signs into OneSignal, opens the platform settings for each of your apps, and reads the push credentials behind them: the iOS certificate or key and the Android service account. It flags anything expiring or already invalid in Slack and Telegram, so it is replaced before a send reaches nobody.

  • A certificate is replaced while there is still time, not after a silent send
  • Every app and platform is checked weekly rather than remembered once a year
  • A one-sided delivery drop is reported next to the credential that explains it

Built for mobile developers · growth teams · product managers · app marketers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens app.onesignal.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    OneSignal - check every app's push credentials
    onesignal.com
    WebRun in OneSignal: check every app's push credentials
    WebRun opens OneSignal to check every app's push credentials.
    • Sign in to OneSignal and open the platform settings for each app in the account
    • Read the state of the iOS push credential and note any expiry date shown against it
    • Read the state of the Android service account and note whether it is configured and valid
    • Check the recent delivery status per platform for a sudden drop that points at a broken credential
    • Mark anything expiring inside 60 days, anything already invalid, and any platform left unconfigured
    • Read only. WebRun never uploads a certificate, changes a setting, or sends a push

    Done when Every app has a per-platform credential state, with expiring and invalid ones marked.

  3. 2
    Slack - flag what needs replacing
    slack.com
    WebRun in Slack: flag what needs replacing
    WebRun opens Slack to flag what needs replacing.
    • Post to your mobile channel with the apps and platforms that need attention
    • List anything already invalid first, then anything expiring inside 60 days with its date
    • Note the recent delivery trend on each flagged platform so the impact is clear
    • Stay quiet in weeks where every credential is valid and nothing is close to expiring

    Done when The mobile channel has the list of credentials to replace, worst first.

  4. 3
    Telegram - ping the mobile team
    telegram.org
    WebRun in Telegram: ping the mobile team
    WebRun opens Telegram to ping the mobile team.
    • Send a one-line ping to the mobile on-call group for any credential that is already invalid
    • Name the app, the platform, and what state it is in
    • Keep the detail in Slack and the ping short enough to read on a phone
    • Send it internally to your own group only

    Done when The on-call group has been pinged about every credential that is already failing.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
app.onesignal.com
ScheduleRuns automatically on this cadence
Every Monday at 8:00 AM
DeliveryHow each run's result reaches you
Credential expiry alerts · Slack
OutputWhat each run produces - A credential table per app: the iOS push credential and Android service account state, any expiry date, and the recent delivery trend per platform.
Table
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it upload a new certificate or key for me?

No. WebRun reads the credential state in OneSignal and reports it. File uploads are blocked by policy, so replacing an iOS credential or an Android service account is done by your mobile team.

Will it send a test push?

No. WebRun never sends a notification of any kind. It reads the configured credentials and the delivery status already recorded, so no subscriber receives anything because of a check.

How does it spot a credential that is already broken?

Two ways: the state shown in the platform settings, and a sudden drop in delivery on one platform while the other keeps working. Both are reported together so the cause is obvious.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.