Skip to main content
Glama

Check a server's SSL/TLS certificate (expiry, chain, hostname, TLS version)

check_certificate
Read-onlyIdempotent

Run a live TLS handshake against host:port and audit the certificate the server presents. Returns an A/B/C/F grade and summary, expiry (days remaining), hostname match, chain completeness and trust against Mozilla's root store, negotiated TLS version and cipher suite, key type/size, findings, and a link to the full report. Revocation (OCSP/CRL) is NOT checked. Hosts on Cloudflare's own network cannot be checked live (result: isError with code live_check_unavailable, no grade); a failed handshake returns check_failed with no grade. Read-only: it only opens a TLS connection to the public host. Same engine, cache and limits as the CertGuard JSON API (GET /api/v1/check).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
hostYesHostname or public IP to check, e.g. example.com. An https:// URL is accepted and reduced to its host (and port). Private, internal and reserved addresses are rejected.
portNoTCP port (default 443). Allowed: 443, 8443, 465, 993, 995.
include_rawNoAlso return the full /api/v1/check JSON (all chain certificates, SANs, handshake attempts) in structuredContent.raw. Larger output.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
rawNoFull /api/v1/check response (only when include_raw is true)
tlsNo
hostYes
planNo
portYes
chainNo
gradeYes
apiUrlNo
cachedNo
expiryNo
issuesNo
sourceNo
statusYes
summaryYes
versionNo
hostnameNo
checkedAtNo
reportUrlYes
notCheckedNo
certificateNo
gradeEstimatedNotrue when the result was inferred from Certificate Transparency logs instead of a live handshake
revocation_checkedYesAlways false: OCSP/CRL status is not queried

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

Score is being calculated.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources