{"uid":"cap_EZqvqvpilws3yqGmJQNvY","slug":"netintel-ssl-certificate-facts-2e15dacd","name":"NetIntel SSL Certificate Facts","description":"Fast SSL/TLS certificate facts for any domain — issuer, subject, SANs, valid from/to, days until expiry, expired/self-signed flags, TLS version, chain length. One TLS handshake, sub-2-second answer. The light, cheap tier under /ssl/analyze (full analysis, grading). No API key.","url":"https://netintel.dev/ssl/cert","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["domain"],"properties":{"port":{"type":"number","description":"Port to connect to (default: 443, clamped to 1-65535). Alias: p"},"domain":{"type":"string","description":"Domain to check (e.g. example.com) — a full URL is also accepted, the host is extracted. Aliases: host, hostname, url, site"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","properties":{"key":{"type":"object","properties":{"bits":{"type":["number","null"]},"type":{"type":["string","null"]}}},"port":{"type":"number"},"sans":{"type":"array"},"domain":{"type":"string"},"issuer":{"type":"object","properties":{"common_name":{"type":["string","null"]},"organization":{"type":["string","null"]}}},"expired":{"type":"boolean"},"sig_alg":{"type":["string","null"]},"subject":{"type":["string","null"]},"findings":{"type":"array"},"valid_to":{"type":["string","null"]},"valid_from":{"type":["string","null"]},"self_signed":{"type":"boolean"},"tls_version":{"type":["string","null"]},"chain_length":{"type":"number"},"not_yet_valid":{"type":"boolean"},"days_remaining":{"type":["number","null"]},"sans_truncated":{"type":"boolean"},"cache_age_seconds":{"type":"number"}}}}}}},"responseSchema":{"type":"json","example":{"key":{"bits":256,"type":"EC"},"port":443,"sans":["example.com","www.example.com"],"domain":"example.com","issuer":{"common_name":"R11","organization":"Let's Encrypt"},"expired":false,"sig_alg":"sha256WithRSAEncryption","subject":"example.com","findings":[],"valid_to":"2026-09-29T23:59:59.000Z","valid_from":"2026-07-01T00:00:00.000Z","self_signed":false,"tls_version":"TLSv1.3","chain_length":3,"not_yet_valid":false,"days_remaining":27,"sans_truncated":false,"cache_age_seconds":0}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_b19HzpauVGdFaM5d-qlOx","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches SSL/TLS certificate details for any domain — issuer, SANs, validity dates, days until expiry, expired/self-signed flags, TLS version, and chain length — via a single TLS handshake in under 2 seconds.","exampleAgentPrompt":"Can you pull the SSL certificate details for stripe.com — I want to know who issued it, when it expires, how many days are left, and whether it's self-signed or using TLSv1.3?","exampleUseCases":[{"title":"Expiry alert before cert lapses","prompt":"Check the SSL cert for api.mycompany.com and tell me how many days are left before it expires — I need to know if we're at risk of it lapsing soon."},{"title":"Self-signed cert audit for staging servers","prompt":"I need to verify whether staging.internal.example.com is using a self-signed SSL certificate or a real CA-issued one — can you check and tell me the issuer and TLS version too?"},{"title":"SAN coverage check for multi-domain site","prompt":"What SANs are listed on the SSL certificate for shop.example.com? I want to make sure www.shop.example.com and api.shop.example.com are both covered."}],"resultDescription":"Returns a JSON object with the domain and port checked, issuer (common name and organization), subject, list of SANs, validity window (valid_from, valid_to), days_remaining, boolean flags for expired/self_signed/not_yet_valid, TLS version negotiated, certificate chain length, signature algorithm, key type and bit length, any findings, and cache_age_seconds indicating data freshness.","failureModes":["Domain not reachable or TLS handshake timeout — connection refused or no response","Invalid domain format — returns error if host cannot be resolved","Port out of range — clamped to 1–65535 but unreachable ports yield connection failure","Domain with no TLS listener on specified port — returns error or empty cert fields","Payment not processed — x402 payment required before response is returned"],"whenToPreferThis":"Choose this endpoint when you need fast, lightweight SSL/TLS certificate metadata — issuer, expiry, SANs, TLS version — without a full security grade or vulnerability scan. It is cheaper and faster than /ssl/analyze, requires no API key, and is ideal for monitoring pipelines, expiry alerting, SAN coverage checks, or any agent workflow that just needs raw certificate facts rather than a scored security report.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T18:47:14.078Z","isFirstParty":false}