GET
$0.01 default
/checkDescription
SSL/TLS certificate check: expiry, issuer, SANs, chain validity, hostname match, negotiated protocol/cipher, and weak-algo warnings for a public HTTPS host. Clean JSON.
Pricing
$0.01 default
Parameters
{
"properties": {
"host": {
"description": "Hostname to inspect (no scheme, no IP literal, not localhost or a reserved/internal suffix)",
"type": "string"
},
"port": {
"default": 443,
"description": "TLS port; restricted to an allowlist",
"enum": [
443,
8443
],
"type": "integer"
}
},
"required": [
"host"
],
"type": "object"
}Example response
{
"certificate": {
"issuer_cn": "DigiCert Global G3 TLS ECC SHA384 2020 CA1",
"issuer_org": "DigiCert Inc",
"key_algorithm": "ECDSA",
"key_size": 256,
"not_after": "2027-02-15T23:59:59Z",
"not_before": "2026-01-15T00:00:00Z",
"sans": [
"example.com",
"www.example.com"
],
"serial_number": "212351572002930070173044758915925313",
"signature_algorithm": "ECDSA-SHA384",
"subject_cn": "example.com"
},
"chain": {
"chain_valid": true,
"days_until_expiry": 228,
"hostname_matches": true,
"is_expired": false,
"is_self_signed": false
},
"connection": {
"cipher_suite": "TLS_AES_128_GCM_SHA256",
"tls_version": "TLS 1.3"
},
"host": "example.com",
"port": 443,
"queried_at": "2026-07-02T12:00:00Z",
"warnings": []
}