crtsh-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@crtsh-mcpenumerate subdomains for example.com"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
crt.sh MCP Server
MCP server wrapping crt.sh — Certificate Transparency log search. Every SSL/TLS certificate ever publicly issued, searchable by domain, wildcard, or organisation.
Tools
search_certificates(query, limit=50) — Search CT logs for certificates matching a domain, wildcard (
%.example.com), or organisation name. Returns an object withcount,total_found,truncated, an optionalnote, and thecertificateslist (issuer, common name, SANs, validity dates, serial number).discover_subdomains(domain) — Enumerate all known subdomains for a domain from cert history. Input is normalized automatically (
*.example.com,%.example.com,example.com., and mixed case all work). Returns{domain, subdomain_count, subdomains, truncated}.get_certificate_details(domain) — Detailed certificate info for a domain, most recently logged first (up to 20).
Related MCP server: Certificate Search MCP Server
Features
No API key required — crt.sh is free and unauthenticated
Automatic retry with exponential backoff (crt.sh is frequently overloaded — 502s, 404s, and timeouts are retried)
In-memory TTL cache (5 min) to avoid hammering the service
Wildcard subdomain discovery with input normalization
Result truncation with an explicit
truncatedflag — crt.sh caps queries at ~999 rows with no pagination, so the server tells you when results may be incomplete
Install
cd crtsh-mcp
pip install -e .Configure (Hermes)
Add to your Hermes config.yaml under mcp_servers:
mcp_servers:
crtsh:
command: /absolute/path/to/crtsh-mcp/.venv/bin/python3
args: ["-m", "crtsh_mcp.server"]The server is stdlib-only (zero runtime dependencies) and speaks the 2026-07-28
stateless era (server/discover; a legacy initialize answers -32601); retry/
backoff/TTL-cache/redirect semantics are documented in the src/crtsh_mcp/client.py
header. Set up the venv once:
cd crtsh-mcp
python3 -m venv .venv
.venv/bin/pip install -e .Or for Claude Desktop / other MCP clients:
{
"mcpServers": {
"crtsh": {
"command": "python3",
"args": ["-m", "crtsh_mcp.server"]
}
}
}Development
pip install -e ".[dev]"
python -m pytestRun python -m pytest from the repo root — the suite covers both tests/ and the
root-level test_stateless_era.py era suite.
API Notes
Source: https://crt.sh (
?q=<identity>&output=json)Auth: None
Rate limits: ~60 req/min per IP (unpublished)
Reliability: Flaky — a free community resource that is often overloaded. Expect intermittent 502s, 404s, and timeouts; this server retries transient failures automatically with backoff (1s, 2s, 4s).
Result cap: ~999 rows per query, no pagination. The
truncatedflag signals when this cap (or yourlimit) cut results off.Wildcards:
%is the SQL LIKE wildcard (%.example.commatches all subdomains). Only identity/org searches support JSON output; fingerprint, serial, and crt.sh-ID lookups are HTML-only and unsupported here.
Note: crt.sh is rate-limited and flaky. The server retries automatically, but if it reports the service as unavailable, wait a moment and try again.
Migration note (2026-09-14, card B.3)
The server shed its MCP framework layer: it is now stdlib-only (zero runtime
dependencies) and speaks the stateless 2026-07-28 era; pre-migration/20260914 is
the rollback anchor for the old code. The User-Agent in client.py remains the
legacy literal crtsh-mcp/0.1.0; pinned by tests.
MIGRATION-NOTES (cutover hand-off — card B.3 / T10; NOT executed here)
server key: crtsh — config.yaml:970-975 today:
command: <venv-root>/crtsh-mcp/bin/python3 ; args: [-m, crtsh_mcp.server]
target after cutover (D.1 flips, ONE restart window; keep old venv until D.1b):
command: ${PROD_PY} # e.g. <venv-root>/crtsh-mcp-v2/bin/python3
args: [-m, crtsh_mcp.server] ; protocol: statelessThis server cannot be deployed
Maintenance
Related MCP Connectors
Certificate Transparency search: subdomains, certificate history and hostname keyword search.
SSL/TLS scanning, free Let's Encrypt issuance, and certificate-expiry monitoring.
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
Related MCP Servers
- -licenseNot gradedqualityNot gradedmaintenanceEnables ethical security testing and attack surface management through SSL certificate validation, CVE queries, subdomain enumeration, security header analysis, and comprehensive reconnaissance capabilities. Designed for authorized penetration testing workflows with responsible disclosure practices.-
- FlicenseNot gradedqualityDmaintenanceEnables SSL/TLS certificate search and analysis using crt.sh data, supporting domain certificate discovery, subdomain enumeration, and security auditing through Cloudflare Workers deployment.-
- AlicenseAqualityAmaintenanceEnables named-entity attribution from Certificate Transparency logs (OV/EV only) for mapping legal-entity digital footprints and domain discovery via LLM-driven workflows.734 npmMIT
- FlicenseNot gradedqualityDmaintenanceEnables external reconnaissance activities including DNS enumeration, subdomain discovery, email security analysis, and SSL certificate inspection against a target domain.13-