{"uid":"cap_9H8BPZUmCBnD6Q0KZ54cr","slug":"sitesignal-tls-security-evidence-3469c6f6","name":"SiteSignal TLS Security Evidence","description":"Inspect a public HTTPS hostname's TLS certificate and observable response security headers without active scanning.","url":"https://trinity-throw-thursday-gravity.trycloudflare.com/x402/tls-security","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["domain"],"properties":{"domain":{"type":"string","description":"Public HTTPS hostname."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.03","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.03/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_n6coWgEhCctPnkHD05k2_","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Inspects a public HTTPS hostname's TLS certificate details and observable HTTP response security headers without active scanning.","exampleAgentPrompt":"Can you check the TLS certificate and security headers for stripe.com — I want to see the certificate issuer, expiry, and what security headers they return?","exampleUseCases":[{"title":"Pre-deployment certificate audit","prompt":"Before we launch, can you inspect the TLS certificate and security headers for api.mycompany.com to make sure everything looks good — I want to know the issuer, expiry date, and whether they have headers like HSTS and CSP configured?"},{"title":"Vendor security due diligence","prompt":"We're onboarding a new payment processor — can you pull the TLS certificate details and response security headers for checkout.vendorpay.io so I can include them in our security review?"},{"title":"Monitoring a competitor's HTTPS posture","prompt":"Can you check what TLS certificate and security headers github.com is currently serving? I want to see the cert validity period and whether they enforce strict transport security."}],"resultDescription":"Returns the inspected TLS certificate metadata (issuer, subject, validity dates, SANs, cipher suite) and observable HTTP response security headers (e.g. HSTS, CSP, X-Frame-Options, X-Content-Type-Options) for the specified public HTTPS hostname, gathered passively without active scanning.","failureModes":["Domain is not publicly reachable or does not serve HTTPS — returns an error or empty result","Invalid or non-existent hostname provided — returns a resolution or connection error","Domain has an expired or self-signed certificate that cannot be inspected normally","Rate limiting or timeout when the target host responds slowly","Cloudflare tunnel availability issues causing endpoint downtime"],"whenToPreferThis":"Choose this endpoint when you need a quick, passive, non-intrusive snapshot of a public domain's TLS certificate and security headers — ideal for due diligence checks, pre-launch audits, or vendor assessments where you don't want to trigger active scanning alerts. Prefer this over full vulnerability scanners when you only need certificate and header evidence without port scanning or exploit probing.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T11:27:34.214Z","isFirstParty":false}