{"uid":"cap_JZb5ePPJZp3R8fdgqkSAf","slug":"certificate-transparency-log-search-crt-sh-c7f96fb5","name":"Certificate Transparency Log Search (crt.sh)","description":"Search public Certificate Transparency logs (via crt.sh) for every cert issued to a domain. Returns the cert list plus a deduped subdomain set extracted from the SANs - the fastest way to enumerate subdomains for a security audit. Free upstream, no key required.","url":"https://agent402.tools/api/cert-transparency","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"limit":{"type":"integer","description":"Max certs to return (1–500, default 50)"},"domain":{"type":"string","description":"Domain to search (also accepts host/hostname/url/email)"},"includeExpired":{"type":"boolean","description":"Include expired certs (default false)"}}},"responseSchema":{"type":"json","example":{"certs":[{"id":1234567890,"sans":["agent402.tools"],"issuer":"C=US, O=Let's Encrypt, CN=E5","serial":"0a:1b:2c","notAfter":"2027-02-14T23:59:59","notBefore":"2026-01-15T00:00:00","commonName":"agent402.tools"}],"count":2,"domain":"agent402.tools","queriedAt":"2026-06-19T22:00:00.000Z","truncated":false,"subdomains":["agent402.tools"]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_z5vrJkaoBGOxOiE3AnO4A","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Searches public Certificate Transparency logs via crt.sh to enumerate all SSL/TLS certificates issued for a domain and extract a deduplicated list of subdomains from the SANs.","exampleAgentPrompt":"Search Certificate Transparency logs for all certs issued to example.com — include expired ones and return up to 200 results — I want the full subdomain list extracted from the SANs for a security audit.","exampleUseCases":null,"resultDescription":"Returns a list of SSL/TLS certificates issued to the queried domain (up to the specified limit) along with a deduplicated set of subdomains extracted from the Subject Alternative Names (SANs) across all matching certificates. Each cert entry includes relevant metadata such as issuance date, expiry, and issuer.","failureModes":["Domain not found in CT logs — returns empty certificate list","Invalid domain format — returns validation error","Upstream crt.sh unavailable — returns 502 or timeout","Limit out of range (outside 1–500) — returns parameter validation error","Payment failure via x402 — request not processed"],"whenToPreferThis":"Use this endpoint when you need fast, passive subdomain enumeration without active scanning. Ideal for security audits, recon phases, or verifying certificate issuance history. Prefer this over DNS brute-forcing or active scanners when stealth or speed matters — CT log data is public and requires no special permissions. Best when you need a quick, free-to-source subdomain surface map of a target domain.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T00:54:30.513Z","isFirstParty":false}