{"uid":"cap_7_FRMkcuiAhjgoSutBwl9","slug":"hyrule-cloud-deep-tls-scan-29c05427","name":"Hyrule Cloud Deep TLS Scan","description":"Full-stack network infrastructure for AI agents on AS215932 (RIPE): IPv6-native VMs with SSH and automatic HTTPS subdomains, domain registration and DNS, a broad network-intelligence suite (BGP/routing, IP/ASN & reputation, DNS, RDAP/WHOIS, web & deep TLS, mail deliverability, port/NAT/CGNAT, VoIP/SIP), and proxied requests over Direct/Tor/I2P/Yggdrasil. Pay per request in USDC on Base via x402; VM checkout may also accept BTC/XMR when advertised. This OpenAPI document intentionally contains only the launch-ready, independently payable agent surface.","url":"https://cloud.hyrule.host/v1/web/tls/deep","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"host":{"type":"string","title":"Host","maxLength":253,"minLength":1},"port":{"type":"integer","title":"Port","default":443,"maximum":65535,"minimum":1},"checks":{"type":"array","items":{"enum":["protocol_versions","cipher_suites","certificate_chain","ocsp","hsts","caa","security_headers"],"type":"string","title":"WebTLSDeepCheck"},"title":"Checks"},"include_raw":{"type":"boolean","title":"Include Raw","default":false},"scan_profile":{"type":"string","title":"Scan Profile","default":"ssl_labs_style"}}},"responseSchema":{"type":"json","example":{"status":"ok","target":{"type":"host","input":"example.com","normalized":"example.com"},"partial":false,"sources":{},"summary":"Deep TLS scan completed","findings":[{"code":"example","message":"No issue found","severity":"ok"}],"request_id":"diag_a1b2c3d4","generated_at":"2026-07-15T00:00:00Z"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_joWCTWy4zm9YifzD4Vk3s","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a comprehensive TLS/SSL analysis of a host including protocol versions, cipher suites, certificate chain, OCSP, HSTS, CAA records, and security headers","exampleAgentPrompt":"Run a deep TLS scan on api.example.com port 443 and check the certificate chain, cipher suites, protocol versions, HSTS, and security headers — give me a full SSL Labs-style audit report.","exampleUseCases":[{"title":"Pre-launch SSL audit for new service","prompt":"Before we go live, can you do a deep TLS scan on checkout.mystore.com on port 443 and check everything — certificate chain, supported protocol versions, cipher suites, HSTS, and security headers? I want an SSL Labs-style report so I know if anything is misconfigured."},{"title":"Investigating weak cipher alerts","prompt":"Our security scanner flagged potential weak ciphers on legacy.internalapi.com port 8443 — can you run a deep TLS check focused on cipher suites and protocol versions to confirm which ones are actually being offered?"},{"title":"Certificate chain and OCSP verification","prompt":"Can you inspect the TLS certificate chain and OCSP status for mail.company.org on port 443? I want to make sure the chain is complete and OCSP stapling is working correctly before our compliance review."}],"resultDescription":"Returns a structured diagnostic response with an overall status (ok/info/warning/critical/error), a summary string, the normalized target host, a list of findings each with a code, message, and severity level, source health metadata, a request ID, and a timestamp. Optionally includes raw scan data if requested.","failureModes":["Host unreachable or connection refused — returns error status with connectivity finding","Invalid or expired certificate causing scan partial results — returns warning/critical findings","Host does not support TLS at all on given port — returns critical finding","Timeout during deep scan — may return partial:true with incomplete findings","Invalid hostname format — request rejected with validation error","Port out of range (0 or >65535) — schema validation failure"],"whenToPreferThis":"Use this endpoint when you need a comprehensive, multi-dimensional TLS audit similar to SSL Labs — covering not just certificate validity but also cipher suites, protocol versions, HSTS enforcement, CAA DNS records, OCSP, and HTTP security headers in one call. Prefer this over simple certificate checkers when you need actionable severity-graded findings across the full TLS stack, or when preparing for security compliance reviews.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T12:37:45.390Z","isFirstParty":false}