{"uid":"cap_CjcgcsmhOAN-t1H2eK8gq","slug":"dns-intel-api-live-tls-certificate-lookup-9b435e58","name":"DNS Intel API – Live TLS Certificate Lookup","description":"Live TLS certificate for a domain: issuer, subject, validity dates, days remaining, SANs, TLS version, and cipher suite.","url":"https://dns-intel-api-production.up.railway.app/dns/ssl","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"port":{"type":"integer","maximum":65535,"minimum":1,"description":"TLS port for the handshake. Defaults to 443."},"domain":{"type":"string","description":"Domain name to fetch the live TLS certificate from, e.g. 'example.com'."}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.002","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.002/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_c_7F1sIlMoOrsr8JWHt9X","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.002","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches the live TLS certificate for a domain by performing a real handshake, returning issuer, subject, validity dates, days remaining, SANs, TLS version, and cipher suite.","exampleAgentPrompt":"Can you fetch the live TLS certificate for github.com on port 443 and tell me who issued it, when it expires, what TLS version is being used, and how many days are left before it expires?","exampleUseCases":[{"title":"SSL expiry monitoring for production site","prompt":"Check the live TLS certificate on api.mycompany.com port 443 — I need to know who issued it, the exact expiry date, and how many days are left so I can plan a renewal."},{"title":"Security audit of TLS configuration","prompt":"Inspect the TLS certificate for payments.example.com — I want to see the cipher suite and TLS version it's negotiating to make sure it's not using anything outdated or insecure."},{"title":"Verify SAN coverage for a domain","prompt":"Fetch the live SSL certificate for shop.acme.com and list all the Subject Alternative Names so I can confirm which hostnames are covered under it."}],"resultDescription":"Returns structured details from the live TLS handshake: certificate issuer (CA name, organization), subject (common name, organization), validity window (not-before and not-after dates), days remaining until expiry, list of Subject Alternative Names (SANs), negotiated TLS version (e.g. TLS 1.3), and the cipher suite in use.","failureModes":["Domain does not exist or is unreachable — connection timeout or DNS resolution failure","Port is closed or not serving TLS — handshake failure error","Expired or self-signed certificate may still return data but with warnings","Invalid domain string input — validation error returned","Non-standard port with no TLS listener — connection refused"],"whenToPreferThis":"Choose this endpoint when you need real, live certificate data obtained via an actual TLS handshake rather than cached or third-party registry data. It is ideal for expiry monitoring, cipher suite audits, SAN verification, and TLS version compliance checks. Prefer it over WHOIS or passive DNS lookups when the certificate's runtime configuration — not just registration metadata — is what matters.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T18:34:20.027Z","isFirstParty":false}