{"uid":"cap_wOEAYbTwNyU-AuhNq9loo","slug":"certificate-sans-4a6d10e4","name":"certificate-sans","description":"Subject Alternative Names of the newest certificate for a domain from certificate-transparency logs: every hostname the current cert covers, wildcard flags, issuer, validity window and days left. Reveals sibling services, staging hosts and shared certs. $0.01 per domain.","url":"https://intel.rallylive.ca/monitor/cert-chain-sans","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_s_eh5raMtW5DYkIr-5aWy","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns all Subject Alternative Names (SANs) from the most recent TLS certificate for a domain, sourced from certificate-transparency logs, including issuer, validity window, and days remaining.","exampleAgentPrompt":"What hostnames are covered by the current TLS certificate for rallylive.ca — show me all the SANs, any wildcards, who issued it, and how many days until it expires?","exampleUseCases":[{"title":"Discover sibling staging hosts","prompt":"Can you pull the certificate SANs for stripe.com and tell me all the hostnames it covers, including any staging or internal-looking subdomains? I want to see if there are sibling services hiding in the cert."},{"title":"Certificate expiry monitoring","prompt":"Check the TLS certificate for api.acme.com and tell me how many days are left before it expires, plus who issued it."},{"title":"Security recon on a target domain","prompt":"I'm doing a security audit on competitor.io — can you get the Subject Alternative Names from their latest certificate transparency entry so I can map out what services they're running?"}],"resultDescription":"A structured object containing all SAN hostnames listed in the domain's current TLS certificate (from CT logs), wildcard coverage flags, the certificate issuer (CA name), the validity window (not-before and not-after dates), and the number of days remaining before expiry.","failureModes":["Domain has no certificate logged in CT logs — returns empty or not-found result","Domain typo or invalid hostname — may return error or no data","Certificate transparency log delay — newest cert may lag behind actual deployment by minutes","Private/internal CAs not logged to public CT logs — those certs won't appear","Rate limiting or payment failure — 402 response if x402 payment not attached"],"whenToPreferThis":"Choose this endpoint when you need to enumerate all hostnames covered by a domain's active TLS certificate, discover sibling services or staging environments, verify certificate issuer and expiry, or perform infrastructure reconnaissance using certificate transparency data. It is purpose-built for CT-log-sourced SAN extraction at $0.01 per call, making it cost-effective for bulk domain inspection compared to manually parsing CT log APIs.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T13:06:05.549Z","isFirstParty":false}