{"uid":"cap_ngunfE2eoKr722xLLLUZg","slug":"sicher-halowerk-com-tls-chain-inspector-4cc7e2a2","name":"sicher.halowerk.com TLS Chain Inspector","description":"Opens a TLS connection and reports the chain the server presents. Per certificate: subject and issuer, validity window with days remaining, serial, SHA-256 fingerprint, key type and size, and the subject alternative names. Above that it answers the questions a monitor asks: is the requested hostname covered by the leaf certificate including wildcard rules, how many days until the nearest expiry, is any certificate self-signed or signed with a weak algorithm, does the server send its…","url":"https://sicher.halowerk.com/v1/tls-chain","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"host":{"type":"string","maxLength":255,"description":"Hostname or https URL, e.g. example.com."},"port":{"type":"integer","default":443,"maximum":65535,"minimum":1,"description":"TLS port."},"warn_days":{"type":"integer","default":30,"maximum":365,"minimum":1,"description":"Warn when a certificate expires within this many days."},"servername":{"type":"string","maxLength":255,"description":"SNI name if it differs from host."}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.002","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.002/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_NG4DtbtHORBlh2l7ODsgv","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.002","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Opens a TLS connection to a hostname and returns the full certificate chain with detailed per-cert metadata plus health signals like expiry countdown, coverage check, self-signed flags, and weak algorithm detection.","exampleAgentPrompt":"Can you check the TLS certificate chain for api.example.com on port 443 — I want to know if the hostname is covered, how many days until the nearest cert expires, whether any cert is self-signed or uses a weak algorithm, and the SHA-256 fingerprint of the leaf certificate?","exampleUseCases":[{"title":"Pre-deployment TLS audit","prompt":"Before we go live, can you inspect the full certificate chain for staging.myapp.com on port 443 and tell me if the hostname is properly covered, how many days of validity we have left, and whether anything looks weak or self-signed?"},{"title":"Expiry alert for production API","prompt":"Check the TLS chain for api.payments.io on port 443 and tell me how many days until the nearest certificate in the chain expires — I want to know if we need to renew soon."},{"title":"Wildcard coverage verification","prompt":"We just deployed a wildcard cert and I need to confirm it actually covers sub.internal.acme.com — can you inspect the TLS chain on port 443 and tell me if the hostname is covered including wildcard rules?"}],"resultDescription":"Returns the full ordered certificate chain the server presents, with per-certificate fields including subject, issuer, validity start and end dates, days remaining, serial number, SHA-256 fingerprint, key type and size, and subject alternative names. Also returns aggregated health signals: whether the requested hostname is covered by the leaf certificate (including wildcard matching), the minimum days to expiry across the chain, flags for any self-signed certificate, and flags for any certificate signed with a weak algorithm, plus an indication of whether the server sends a complete chain.","failureModes":["Connection timeout if the host is unreachable or port is closed","TLS handshake failure if the server rejects the connection","Invalid hostname returns an error","Port out of range returns a validation error","Server presents an empty or malformed chain","DNS resolution failure for the provided hostname"],"whenToPreferThis":"Choose this endpoint when you need a live, real-time inspection of what a TLS server actually presents — not a cached or third-party lookup. It is ideal for certificate expiry monitoring, pre-deployment TLS audits, wildcard coverage verification, weak-algorithm detection, and fingerprint validation without relying on external certificate transparency logs or scan databases.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:37:28.827Z","isFirstParty":false}