{"uid":"cap_l1EAS6gw7E7_9Gy0oVYMe","slug":"tls-certificate-lookup-via-certificate-transparency-aad9660e","name":"TLS Certificate Lookup via Certificate Transparency","description":"60 paid endpoints with no metering, no API key and no account. Each endpoint has one flat price per call, whatever the size of the request: LLM completions with automatic failover across several large models, read-only EVM tooling over Base, Ethereum, Polygon, Arbitrum and Optimism, and pure crypto utilities that touch no network.","url":"https://flat-rate-llm.kikoribera03.workers.dev/v1/red/cert","method":"POST","headers":{},"bodySchema":{"type":"object","required":["domain"],"properties":{"domain":{"type":"string","description":"The domain to look up. A full URL or an email address is accepted and reduced to its host."},"subdomains":{"type":"boolean","description":"Also return certificates issued for subdomains. Defaults to false."}}},"responseSchema":{"type":"object","properties":{"count":{"type":"number"},"found":{"type":"boolean"},"domain":{"type":"string"},"source":{"type":"string"},"current":{"type":"object"},"issuers":{"type":"array","items":{"type":"object"}},"hostnames":{"type":"array","items":{"type":"object"}},"expiringSoon":{"type":"array","items":{"type":"object"}}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_1gUr9WGZdILkdyDrKLq4H","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns all currently valid TLS certificates publicly issued for a domain, read from Certificate Transparency logs, including issuer details, validity windows, days to expiry, revocation status, and covered hostnames.","exampleAgentPrompt":"Can you look up all currently valid TLS certificates that have been issued for example.com in the Certificate Transparency logs, including any subdomains, so I can see the issuers, expiry dates, and every hostname they cover?","exampleUseCases":[{"title":"Detect unauthorized shadow certificates","prompt":"Check the Certificate Transparency logs for acmecorp.com and tell me if there are any TLS certificates issued that we didn't know about — I want to see every issuer, all the hostnames covered, and anything that looks suspicious."},{"title":"Monitor certificate expiry before renewal","prompt":"Look up all the currently valid TLS certificates for mybusiness.io in the CT logs and tell me which ones are expiring soon so I know what to renew first."},{"title":"Subdomain enumeration for security recon","prompt":"Pull all TLS certificates from Certificate Transparency logs for targetdomain.com including its subdomains — I want a full list of every hostname covered by any certificate that's been publicly issued."}],"resultDescription":"Returns a JSON object with: total certificate count, whether any certificates were found, the queried domain, the data source, details on the current certificate (issuer, validity, days to expiry, revocation status), an array of all issuers found, an array of all hostnames/SANs covered by those certificates, and a list of certificates expiring soon.","failureModes":["Domain not found in CT logs returns found:false with count:0","Malformed domain input is coerced from full URLs or emails but invalid strings may return an error","CT log data may lag by minutes to hours for very recently issued certificates","Revocation status may not be real-time; relies on CT log publication","Rate limiting or worker downtime may return 5xx HTTP errors","Payment failure (402) if USDC balance is insufficient"],"whenToPreferThis":"Choose this endpoint when you need to discover what TLS certificates have been publicly issued for a domain — especially to find certificates you didn't provision yourself, enumerate subdomains via CT logs, check expiry timelines, or audit issuers. It reads from Certificate Transparency logs (what was issued), not from a live TLS handshake (what the server serves today), making it ideal for security reconnaissance and shadow-certificate detection. No API key or account needed; pay per call with USDC.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:39:48.505Z","isFirstParty":false}