Certificate healthin one API call
Validation, chain, protocols, ciphers, expiry, and CT-log monitoring. Free tier with no credit card.
Free analysis · 100 free checks/month · No credit card
What we check on every certificate
Six layers of inspection — designed to surface issues before users see browser warnings.
Certificate validation
Verify validity, issuer trust, signature algorithm, and proper configuration.
Chain verification
Walk the full chain from leaf to root, flagging missing intermediates and broken links.
Protocol audit
Detect supported TLS versions; flag deprecated SSL 3.0, TLS 1.0, TLS 1.1.
Cipher suite audit
Identify weak ciphers (RC4, 3DES, CBC) and recommend AEAD alternatives.
Expiration monitoring
Track expiry across your fleet and alert before browser warnings hit users.
CT log monitoring
Watch Certificate Transparency logs for unauthorized issuance against your domains.
What the API returns field by field
Sample shape from GET /api/check/certificates?domain=example.com.
Certificate analysis
| Field | Value | Source | Age | Conf. |
|---|---|---|---|---|
| Certificate | ||||
| low severitysubject | CN=example.com | tls-probe | 2 min | 1.00 |
| low severityissuer | C=US, O=Let's Encrypt, CN=R3 | tls-probe | 2 min | 1.00 |
| not applicableserialNumber | 03:5c:98:1d:a3:… | tls-probe | 2 min | 1.00 |
| low severitysignatureAlgorithm | SHA256-RSA | tls-probe | 2 min | 1.00 |
| not applicablefingerprintSha256 | a4:71:…:8c | tls-probe | 2 min | 1.00 |
| Validity | ||||
| low severityvalidFrom | 2026-04-12 | tls-probe | 2 min | 1.00 |
| low severityvalidTo | 2026-07-11 | tls-probe | 2 min | 1.00 |
| low severitydaysRemaining | 69 | tls-probe | 2 min | 1.00 |
| Chain | ||||
| low severitychainLength | 3 | tls-probe | 2 min | 1.00 |
| low severitychainComplete | true | tls-probe | 2 min | 1.00 |
| not applicablesanDomains | ["example.com", "*.example.com"] | tls-probe | 2 min | 1.00 |
| TLS configuration | ||||
| low severityprotocols | ["TLSv1.2", "TLSv1.3"] | tls-probe | 2 min | 1.00 |
| low severityweakCipherSuites | [] | tls-probe | 2 min | 1.00 |
| low severityhstsMaxAge | 31536000 | tls-probe | 2 min | 1.00 |
Monitor the domain to receive expiry and CT-log alerts via webhooks or the SSE stream.
Who runs this and why
DevOps teams
Track expiry across hundreds of domains and avoid pages caused by silent renewals.
Security teams
Audit TLS posture, hunt weak ciphers, and detect rogue CT-log entries early.
Compliance
Meet PCI DSS, HIPAA, and ISO requirements for TLS configuration with auditable reports.
Third-party risk
Vet vendor TLS posture before integration; spot expired certs that signal neglected systems.
Frequently asked questions
What SSL/TLS issues do you detect?
Certificate validity and expiration, chain completeness, supported protocol versions (flagging SSL 3.0 / TLS 1.0 / TLS 1.1 as deprecated), cipher suites (flagging RC4, 3DES, weak CBC modes), missing HSTS, hostname mismatches, weak signature algorithms (SHA-1), self-signed certificates in production, and CT-log entries that indicate unauthorized issuance.
Can I monitor certificate expiration?
Yes. Monitor domains to track expiration and receive email, webhook, or SSE alerts 30, 14, 7, and 1 day before expiry; each asset can use a different schedule.
Do you check Certificate Transparency logs?
Yes. We monitor public CT logs and alert when a certificate is issued for a monitored domain. This catches CA misissuance and unauthorized internal certificates that could enable man-in-the-middle attacks.
What TLS versions should I support?
TLS 1.2 (with secure cipher suites) and TLS 1.3 only. Disable TLS 1.0 and 1.1 — they are deprecated and have known vulnerabilities. Our analyzer flags any deprecated protocol detected on your endpoint.
Is the analysis API public?
Yes. The certificate analysis endpoint is available with a free API key (rate-limited at 100 requests/month on the Free tier). Higher-volume monitoring with continuous tracking, webhooks, and SSE alerts is included on Basic and Pro plans.
How do you compare to SSL Labs?
SSL Labs is excellent for one-shot interactive testing. We focus on continuous monitoring across an asset inventory, machine-readable JSON output, programmatic alerts, and CT-log surveillance — designed to drop into SOC and DevOps pipelines, not just web browsers.
Get notified before certs expire
Free API key, 100 checks/month, no credit card. Continuous monitoring on Basic and Pro.
No credit card required · 100 free checks/month