Skip to main content
Glama

Server Details

Free SSL/TLS certificate checker: expiry, chain trust, hostname match, TLS version, A/B/C/F grade.

If you are the author of this connector, you can claim ownership by verifying the domain or GitHub account it belongs to. Claimed connector authors can inspect health checks, view analytics, and manage their listing.
Status
Healthy
Last Tested
Transport
Streamable HTTP · MCP 2025-11-25
URL

TDQS

Score is being calculated.

Available Tools

1 tool
check_certificateCheck a server's SSL/TLS certificate (expiry, chain, hostname, TLS version)
Read-onlyIdempotent
Inspect

Run a live TLS handshake against host:port and audit the certificate the server presents. Returns an A/B/C/F grade and summary, expiry (days remaining), hostname match, chain completeness and trust against Mozilla's root store, negotiated TLS version and cipher suite, key type/size, findings, and a link to the full report. Revocation (OCSP/CRL) is NOT checked. Hosts on Cloudflare's own network cannot be checked live (result: isError with code live_check_unavailable, no grade); a failed handshake returns check_failed with no grade. Read-only: it only opens a TLS connection to the public host. Same engine, cache and limits as the CertGuard JSON API (GET /api/v1/check).

ParametersJSON Schema
NameRequiredDescriptionDefault
hostYesHostname or public IP to check, e.g. example.com. An https:// URL is accepted and reduced to its host (and port). Private, internal and reserved addresses are rejected.
portNoTCP port (default 443). Allowed: 443, 8443, 465, 993, 995.
include_rawNoAlso return the full /api/v1/check JSON (all chain certificates, SANs, handshake attempts) in structuredContent.raw. Larger output.

Output Schema

ParametersJSON Schema
NameRequiredDescription
rawNoFull /api/v1/check response (only when include_raw is true)
tlsNo
hostYes
planNo
portYes
chainNo
gradeYes
apiUrlNo
cachedNo
expiryNo
issuesNo
sourceNo
statusYes
summaryYes
versionNo
hostnameNo
checkedAtNo
reportUrlYes
notCheckedNo
certificateNo
gradeEstimatedNotrue when the result was inferred from Certificate Transparency logs instead of a live handshake
revocation_checkedYesAlways false: OCSP/CRL status is not queried

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool update
    • First observedcheck_certificate

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables live TLS/SSL certificate health checks for any hostname, providing expiry, hostname match, trust verdict, and a health score. Supports both free and paid deep tiers with protocol/cipher analysis.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Free SSL/TLS scanning and Let's Encrypt certificate issuance (private key stays local), plus certificate-expiry monitoring via one MCP server. Public scan and cert tools need no account.
    3
    MIT
  • A
    license
    Not graded
    quality
    F
    maintenance
    Enables comprehensive TLS security audits for any domain, including certificate validity, expiry warnings, cipher suite weaknesses, deprecated protocols, and HSTS checks. Supports single and bulk domain inspection via MCP tools or a CLI for CI/CD integration.
    387 npm
    MIT
Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources