{"uid":"cap_2xeCbtDvOlMiY6qi__DSl","slug":"synthora-certificate-transparency-issuance-search-f3ebbbc3","name":"SYNTHORA Certificate Transparency Issuance Search","description":"Returns issued TLS certificates (and all subdomains in their SAN dns_names) for a domain from SSLMate's Cert Spotter Certificate Transparency log aggregator, including issuer, validity window and revocation flag. A2A use: attack-surface-discovery and subdomain-enumeration agents map an org's hostnames and detect unexpected or expiring certs. Reliable crt.sh alternative. First 3 calls FREE per wallet — send header X-WALLET: 0x<addr>. No charge on upstream failure.","url":"https://certspotter-ct-issuances.hergertsynthora.com/service","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"domain":{"type":"string","description":"domain"}}},"responseSchema":{"type":"json","example":{"ok":true,"niche":"certspotter-ct-issuances","result":{}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_lDGGRt2Bv80j6tbzTcyoR","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Queries SSLMate's Cert Spotter CT log aggregator to return all issued TLS certificates and their SAN subdomains for a given domain, including issuer, validity window, and revocation status.","exampleAgentPrompt":"Can you pull all the TLS certificates and subdomains that have been issued for example.com from the Certificate Transparency logs, including who issued them, their validity dates, and whether any have been revoked?","exampleUseCases":[{"title":"Attack surface mapping for security audit","prompt":"I'm doing a security assessment of acme-corp.com — can you pull all the subdomains and TLS certificates that have ever been issued for that domain from Certificate Transparency logs so I can map their full attack surface?"},{"title":"Detecting rogue or unexpected certificates","prompt":"Can you check Certificate Transparency logs for any certificates issued for my domain mycompany.com that I might not know about? I want to find anything suspicious or unauthorized."},{"title":"Finding expiring certificates before outage","prompt":"Can you look up all the TLS certificates issued for ourstartup.io in the CT logs and tell me which ones are expiring soon so I can renew them before anything goes down?"}],"resultDescription":"Returns a JSON object containing all TLS certificates issued for the queried domain as recorded in Certificate Transparency logs via Cert Spotter. Each record includes the certificate's SAN dns_names (revealing all associated subdomains), the issuing certificate authority, the validity window (not-before / not-after dates), and a revocation flag indicating whether the certificate has been revoked.","failureModes":["Domain not found in CT logs — returns empty result set if no certificates have ever been issued","Invalid domain format — may return error if domain string is malformed","Rate limiting or upstream Cert Spotter API unavailability — may return error or timeout","Very new domains with no CT log entries yet — returns empty results","Network or service downtime — endpoint unreachable"],"whenToPreferThis":"Prefer this endpoint over direct crt.sh queries when you need a reliable, pay-per-use, agent-friendly API that aggregates Certificate Transparency logs via Cert Spotter. Ideal for automated attack surface discovery, subdomain enumeration pipelines, and certificate monitoring workflows where you need structured JSON output with issuer, validity, and revocation data without scraping or rate-limit concerns of public CT search frontends.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T18:33:25.124Z","isFirstParty":false}