Skip to main content
SSL / TLS Analysis

Certificate healthin one API call

Validation, chain, protocols, ciphers, expiry, and CT-log monitoring. Free tier with no credit card.

check

Free analysis · 100 free checks/month · No credit card

Inspection layers

What we check on every certificate

Six layers of inspection — designed to surface issues before users see browser warnings.

Certificate validation

Verify validity, issuer trust, signature algorithm, and proper configuration.

Chain verification

Walk the full chain from leaf to root, flagging missing intermediates and broken links.

Protocol audit

Detect supported TLS versions; flag deprecated SSL 3.0, TLS 1.0, TLS 1.1.

Cipher suite audit

Identify weak ciphers (RC4, 3DES, CBC) and recommend AEAD alternatives.

Expiration monitoring

Track expiry across your fleet and alert before browser warnings hit users.

CT log monitoring

Watch Certificate Transparency logs for unauthorized issuance against your domains.

API output

What the API returns field by field

Sample shape from GET /api/check/certificates?domain=example.com.

Certificate analysis

example.comvalid
SubjectCN=example.comIssuerLet's Encrypt R3Expires2026-07-11Days left69
FieldValueSourceAgeConf.
Certificate
low severitysubjectCN=example.comtls-probe2 min1.00
low severityissuerC=US, O=Let's Encrypt, CN=R3tls-probe2 min1.00
not applicableserialNumber03:5c:98:1d:a3:…tls-probe2 min1.00
low severitysignatureAlgorithmSHA256-RSAtls-probe2 min1.00
not applicablefingerprintSha256a4:71:…:8ctls-probe2 min1.00
Validity
low severityvalidFrom2026-04-12tls-probe2 min1.00
low severityvalidTo2026-07-11tls-probe2 min1.00
low severitydaysRemaining69tls-probe2 min1.00
Chain
low severitychainLength3tls-probe2 min1.00
low severitychainCompletetruetls-probe2 min1.00
not applicablesanDomains["example.com", "*.example.com"]tls-probe2 min1.00
TLS configuration
low severityprotocols["TLSv1.2", "TLSv1.3"]tls-probe2 min1.00
low severityweakCipherSuites[]tls-probe2 min1.00
low severityhstsMaxAge31536000tls-probe2 min1.00
Fleet statusvalidexpiring soonexpired

Monitor the domain to receive expiry and CT-log alerts via webhooks or the SSE stream.

Use cases

Who runs this and why

DevOps teams

Track expiry across hundreds of domains and avoid pages caused by silent renewals.

Security teams

Audit TLS posture, hunt weak ciphers, and detect rogue CT-log entries early.

Compliance

Meet PCI DSS, HIPAA, and ISO requirements for TLS configuration with auditable reports.

Third-party risk

Vet vendor TLS posture before integration; spot expired certs that signal neglected systems.

FAQ

Frequently asked questions

What SSL/TLS issues do you detect?

Certificate validity and expiration, chain completeness, supported protocol versions (flagging SSL 3.0 / TLS 1.0 / TLS 1.1 as deprecated), cipher suites (flagging RC4, 3DES, weak CBC modes), missing HSTS, hostname mismatches, weak signature algorithms (SHA-1), self-signed certificates in production, and CT-log entries that indicate unauthorized issuance.

Can I monitor certificate expiration?

Yes. Monitor domains to track expiration and receive email, webhook, or SSE alerts 30, 14, 7, and 1 day before expiry; each asset can use a different schedule.

Do you check Certificate Transparency logs?

Yes. We monitor public CT logs and alert when a certificate is issued for a monitored domain. This catches CA misissuance and unauthorized internal certificates that could enable man-in-the-middle attacks.

What TLS versions should I support?

TLS 1.2 (with secure cipher suites) and TLS 1.3 only. Disable TLS 1.0 and 1.1 — they are deprecated and have known vulnerabilities. Our analyzer flags any deprecated protocol detected on your endpoint.

Is the analysis API public?

Yes. The certificate analysis endpoint is available with a free API key (rate-limited at 100 requests/month on the Free tier). Higher-volume monitoring with continuous tracking, webhooks, and SSE alerts is included on Basic and Pro plans.

How do you compare to SSL Labs?

SSL Labs is excellent for one-shot interactive testing. We focus on continuous monitoring across an asset inventory, machine-readable JSON output, programmatic alerts, and CT-log surveillance — designed to drop into SOC and DevOps pipelines, not just web browsers.

Monitoring

Get notified before certs expire

Free API key, 100 checks/month, no credit card. Continuous monitoring on Basic and Pro.

No credit card required · 100 free checks/month