Check a server's SSL/TLS certificate (expiry, chain, hostname, TLS version)
check_certificateRun a live TLS handshake against host:port and audit the certificate the server presents. Returns an A/B/C/F grade and summary, expiry (days remaining), hostname match, chain completeness and trust against Mozilla's root store, negotiated TLS version and cipher suite, key type/size, findings, and a link to the full report. Revocation (OCSP/CRL) is NOT checked. Hosts on Cloudflare's own network cannot be checked live (result: isError with code live_check_unavailable, no grade); a failed handshake returns check_failed with no grade. Read-only: it only opens a TLS connection to the public host. Same engine, cache and limits as the CertGuard JSON API (GET /api/v1/check).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| host | Yes | Hostname or public IP to check, e.g. example.com. An https:// URL is accepted and reduced to its host (and port). Private, internal and reserved addresses are rejected. | |
| port | No | TCP port (default 443). Allowed: 443, 8443, 465, 993, 995. | |
| include_raw | No | Also return the full /api/v1/check JSON (all chain certificates, SANs, handshake attempts) in structuredContent.raw. Larger output. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| raw | No | Full /api/v1/check response (only when include_raw is true) | |
| tls | No | ||
| host | Yes | ||
| plan | No | ||
| port | Yes | ||
| chain | No | ||
| grade | Yes | ||
| apiUrl | No | ||
| cached | No | ||
| expiry | No | ||
| issues | No | ||
| source | No | ||
| status | Yes | ||
| summary | Yes | ||
| version | No | ||
| hostname | No | ||
| checkedAt | No | ||
| reportUrl | Yes | ||
| notChecked | No | ||
| certificate | No | ||
| gradeEstimated | No | true when the result was inferred from Certificate Transparency logs instead of a live handshake | |
| revocation_checked | Yes | Always false: OCSP/CRL status is not queried |