{"uid":"cap_BrM5Jo3C3LxS2bL5gVxYV","slug":"netintel-ssl-certificate-inspector-a069ef55","name":"NetIntel SSL Certificate Inspector","description":"Network intelligence API — 138 endpoints, all pay-per-call via x402 micropayments (USDC on Base or Solana mainnet).\n\nNetIntel is agent fair-trade aligned: transparent per-call pricing in USDC on Base or Solana via x402, no API keys or signup, and automatic no-charge on server errors, upstream failures, and input-validation rejections — failed calls are never billed across NetIntel's network, domain, and data-intelligence endpoints.","url":"https://netintel-production-440c.up.railway.app/ssl/cert","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["domain"],"properties":{"port":{"type":"number","description":"Port to connect to (default: 443, clamped to 1-65535). Alias: p"},"domain":{"type":"string","description":"Domain to check (e.g. example.com) — a full URL is also accepted, the host is extracted. Aliases: host, hostname, url, site"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","properties":{"key":{"type":"object","properties":{"bits":{"type":["number","null"]},"type":{"type":["string","null"]}}},"port":{"type":"number"},"sans":{"type":"array"},"domain":{"type":"string"},"issuer":{"type":"object","properties":{"common_name":{"type":["string","null"]},"organization":{"type":["string","null"]}}},"expired":{"type":"boolean"},"sig_alg":{"type":["string","null"]},"subject":{"type":["string","null"]},"findings":{"type":"array"},"valid_to":{"type":["string","null"]},"valid_from":{"type":["string","null"]},"self_signed":{"type":"boolean"},"tls_version":{"type":["string","null"]},"chain_length":{"type":"number"},"not_yet_valid":{"type":"boolean"},"days_remaining":{"type":["number","null"]},"sans_truncated":{"type":"boolean"},"cache_age_seconds":{"type":"number"}}}}}}},"responseSchema":{"type":"json","example":{"key":{"bits":256,"type":"EC"},"port":443,"sans":["example.com","www.example.com"],"domain":"example.com","issuer":{"common_name":"R11","organization":"Let's Encrypt"},"expired":false,"sig_alg":"sha256WithRSAEncryption","subject":"example.com","findings":[],"valid_to":"2026-09-29T23:59:59.000Z","valid_from":"2026-07-01T00:00:00.000Z","self_signed":false,"tls_version":"TLSv1.3","chain_length":3,"not_yet_valid":false,"days_remaining":27,"sans_truncated":false,"cache_age_seconds":0}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_9XAJBhMW7BLXVw8h63KLb","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches and parses the SSL/TLS certificate for a given domain, returning expiry, issuer, SANs, key info, chain length, and security findings.","exampleAgentPrompt":"Can you check the SSL certificate for stripe.com — I want to know who issued it, when it expires, whether it's self-signed, and how many days are left before it needs renewal?","exampleUseCases":[{"title":"Certificate expiry monitoring for fleet","prompt":"Check the SSL certificate on api.mycompany.com and tell me how many days are left before it expires and whether there are any security findings I should know about."},{"title":"Vendor security due diligence","prompt":"I'm about to integrate with a third-party payment provider at checkout.vendorsite.com — can you pull their SSL certificate details and tell me if it's properly issued by a trusted CA, what TLS version they're using, and if the cert is still valid?"},{"title":"Troubleshooting HTTPS connection errors","prompt":"Users are getting SSL errors connecting to portal.internalapp.net on port 8443 — can you fetch the certificate there and check if it's expired, not yet valid, or self-signed?"}],"resultDescription":"Returns a JSON object with the domain and port probed, certificate subject and SANs list, issuer (common name and organization), validity window (valid_from, valid_to, days_remaining), boolean flags for expired/not_yet_valid/self_signed, TLS version negotiated, signature algorithm, public key type and bit size, certificate chain length, an array of security findings, and a cache_age_seconds field indicating data freshness.","failureModes":["Domain does not exist or cannot be resolved — returns error with no charge","Domain is unreachable or port is closed — connection timeout error, no charge","Domain has no SSL certificate (plain HTTP only) — error indicating no TLS","Invalid domain input fails schema validation — rejected before billing","Upstream TLS handshake failure — no charge per NetIntel policy"],"whenToPreferThis":"Choose this endpoint when you need detailed, structured SSL certificate metadata for a single domain — including expiry countdown, issuer identity, SANs, key specs, and chain length — rather than just a pass/fail validity check. Ideal for automated certificate monitoring, security audits, or vendor due diligence. Prefer this over generic TLS scanning tools when you need pay-per-call access with no signup, automatic no-charge on failures, and machine-readable JSON output ready for downstream agent logic.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T00:43:54.969Z","isFirstParty":false}