{"uid":"cap_xxGiMMuWfgdiKUZW5ClFr","slug":"sitesignal-tls-security-evidence-3cfe1cf0","name":"SiteSignal TLS Security Evidence","description":"Inspect a public HTTPS hostname's TLS certificate and observable response security headers without active scanning.","url":"https://phases-prot-shine-royal.trycloudflare.com/x402/tls-security","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["domain"],"properties":{"domain":{"type":"string","description":"Public HTTPS hostname."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.03","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.03/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_cftDeB_0Zm7_nwPqYI_XH","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Inspects a public HTTPS hostname's TLS certificate details and observable response security headers without active scanning.","exampleAgentPrompt":"Can you pull the TLS certificate details and security headers for api.stripe.com so I can see what cipher suites and response security headers they're using?","exampleUseCases":[{"title":"Vendor security due diligence check","prompt":"I need to verify the TLS setup and security response headers for payments.acme.com before we integrate with them — can you pull a snapshot of their certificate and observable security headers?"},{"title":"Pre-launch HTTPS compliance audit","prompt":"We're about to launch myapp.example.com — can you check its TLS certificate validity and what security headers it's serving so I can confirm everything looks right before we go live?"},{"title":"Competitive security posture comparison","prompt":"Can you grab the TLS certificate info and security headers from competitor.io so I can see what HSTS, CSP, and other security headers they have in place?"}],"resultDescription":"Returns point-in-time evidence of the target hostname's TLS certificate (issuer, validity dates, subject, cipher info) and observable HTTP response security headers (e.g. HSTS, CSP, X-Frame-Options, X-Content-Type-Options), all collected passively without active scanning.","failureModes":["Domain does not exist or is unreachable — returns error indicating hostname could not be resolved","Hostname uses HTTP only (no HTTPS) — endpoint may return empty or error response","Certificate is self-signed or expired — data returned but may flag anomalies","Cloudflare or CDN shields actual origin headers — results reflect edge, not origin","Rate limiting or network timeout on the target host — returns partial or error result","Invalid domain format provided — schema validation error"],"whenToPreferThis":"Choose this endpoint when you need a passive, non-intrusive read of a public HTTPS domain's TLS certificate properties and security response headers without triggering active scans or port sweeps. Ideal for due diligence, compliance snapshots, or pre-integration security checks where you want structured evidence without touching the target aggressively. Prefer this over general website analysis tools when TLS and security header specifics are the primary concern.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T10:28:21.078Z","isFirstParty":false}