Post-Quantum TLS Readiness
pqc_readinessCheck whether a website's public TLS 1.3 endpoint is ready for post-quantum cryptography by testing hybrid X25519MLKEM768 key exchange and identifying origin vs CDN support.
Instructions
Check whether a website's public TLS endpoint is ready for post-quantum cryptography: does it complete a TLS 1.3 handshake that offers only the hybrid X25519MLKEM768 key exchange (ML-KEM), and does the organisation's own server provide it or a CDN edge in front of it. Also reports what the certificate chain is signed with (tracked, not scored: public CAs do not issue post-quantum certificates yet). Verdicts: ready (the origin server supports it), partial (a CDN edge provides it; the CDN-to-origin leg is invisible), not_ready (the hybrid-only handshake was refused), unknown (inconclusive; do not report it as "no"). Scope: only the public endpoint on port 443. Internal systems, VPNs, code, and Korean PQC algorithms (no standard TLS codepoints yet) are not observable, so present the result as an external indicator of migration progress, not a full PQC audit. Read-only; requires no API key; rate-limited. Returns the verdict, a 0-100 readiness score and grade, per-check statuses, and a shareable report link.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | Domain whose HTTPS endpoint to check (e.g., 'example.com'). Scheme and path are stripped. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| grade | No | ||
| score | No | 0-100 post-quantum readiness; null when inconclusive | |
| checks | No | ||
| verdict | Yes | 'ready' | 'partial' | 'not_ready' | 'unknown' | |
| reportUrl | Yes | Human-facing interactive report on dechonet.com | |
| tlsVersion | No | ||
| keyExchange | No | Hybrid group accepted (e.g. X25519MLKEM768), null if none | |
| terminatedBy | No | 'origin' or the CDN name whose edge answered |