SSL Cert Info API
Fetches the TLS certificate a host presents: issuer, subject, SAN list, validity window, days to expiry and the full chain.
- Endpoint
POST /v1/ssl-cert-info- Price
- $0.002 per call
- Family
- Domain, DNS & network
01When to use it
- Reading a live certificate needs a TLS handshake against the host, which an agent may be unable to make; the days-to-expiry and chain view are what you monitor across a fleet of domains.
When not to use it
- The destination needs more than 10 s to answer: the call ends with upstream_timeout (424).
- The destination is on a private or local network: the network guard refuses it with blocked_target (403).
02Parameters
| Field | Type | Required | Description |
|---|---|---|---|
| domain | string | no | Public fully qualified domain name to connect to and send as SNI. Give exactly one of domain or url. |
| url | string | no | An http(s) URL whose host is probed; an explicit port in the URL overrides the port field, and the path is ignored. Give exactly one of domain or url. |
| port | integer | no | TLS port for the handshake, one of 443, 465, 636, 990, 993, 995, 8443; defaults to 443. Default: 443. |
03Limits
| Limit | Value |
|---|---|
| Size cap | 2 MB (2,097,152 bytes) |
| Timeout | 10 s |
04Example
The published example of ssl-cert-info, verbatim: the request body and the response it returns.
Request
POST /v1/ssl-cert-info
content-type: application/json
payment-signature: <base64 x402 payload>
{
"domain": "example.com"
}Response
200 OK
payment-response: <base64 settlement receipt>
{
"host": "example.com",
"port": 443,
"issuer": "CN=R3, O=Let's Encrypt, C=US",
"subject": "CN=example.com, O=Example Inc, C=US",
"san": [
"example.com",
"www.example.com"
],
"valid_from": "2026-08-01T00:00:00.000Z",
"valid_to": "2026-10-30T23:59:59.000Z",
"days_to_expiry": 65,
"self_signed": false,
"chain": [
{
"issuer": "CN=R3, O=Let's Encrypt, C=US",
"subject": "CN=example.com, O=Example Inc, C=US",
"valid_from": "2026-08-01T00:00:00.000Z",
"valid_to": "2026-10-30T23:59:59.000Z"
},
{
"issuer": "CN=ISRG Root X1, O=Internet Security Research Group, C=US",
"subject": "CN=R3, O=Let's Encrypt, C=US",
"valid_from": "2020-09-04T00:00:00.000Z",
"valid_to": "2025-09-15T16:00:00.000Z"
}
],
"queried_at": "2026-08-26T18:00:00.000Z"
}This example is illustrative: it shows the exact shape the handler returns, but it was not produced by a reproducible call, because the real answer depends on live network data that changes over time.
| Response field | Type | In the example |
|---|---|---|
| host | string | "example.com" |
| port | number | 443 |
| issuer | string | "CN=R3, O=Let's Encrypt, C=US" |
| subject | string | "CN=example.com, O=Example Inc, C=US" |
| san | array | 2 items |
| valid_from | string | "2026-08-01T00:00:00.000Z" |
| valid_to | string | "2026-10-30T23:59:59.000Z" |
| days_to_expiry | number | 65 |
| self_signed | boolean | false |
| chain | array | 2 items, each with issuer, subject, valid_from and valid_to |
| queried_at | string | "2026-08-26T18:00:00.000Z" |
05Call it from code
JavaScript
// ssl-cert-info: $0.002 per call, paid in USD Coin on eip155:8453 via x402
// Install: npm install @x402/fetch@2 @x402/evm@2 viem@2
// Save as client.mjs (ES module, Node 18+), export EVM_PRIVATE_KEY with the paying wallet's key in your shell, then run: node client.mjs
// The wrapper reads the 402 (payment-required), signs and retries with payment-signature.
import { wrapFetchWithPayment, x402Client, decodePaymentResponseHeader } from '@x402/fetch'
import { ExactEvmScheme } from '@x402/evm/exact/client'
import { privateKeyToAccount } from 'viem/accounts'
const account = privateKeyToAccount(process.env.EVM_PRIVATE_KEY)
const client = new x402Client().register('eip155:8453', new ExactEvmScheme(account))
const fetchWithPayment = wrapFetchWithPayment(fetch, client)
const body = {
"domain": "example.com"
}
const res = await fetchWithPayment('https://grist.tools/v1/ssl-cert-info', {
method: 'POST',
headers: { 'content-type': 'application/json' },
body: JSON.stringify(body),
})
console.log(res.status, await res.json())
const settle = res.headers.get('payment-response')
if (settle) console.log(decodePaymentResponseHeader(settle).transaction)Python
# ssl-cert-info: $0.002 per call, paid in USD Coin on eip155:8453 via x402
# Install: pip install "x402[requests,evm]>=2.24,<3"
# The session reads the 402 (payment-required), signs and retries with payment-signature.
import os
from eth_account import Account
from x402 import x402ClientSync
from x402.http import decode_payment_response_header
from x402.http.clients.requests import x402_requests
from x402.mechanisms.evm.exact import register_exact_evm_client
from x402.mechanisms.evm.signers import EthAccountSigner
account = Account.from_key(os.environ["EVM_PRIVATE_KEY"])
client = x402ClientSync()
register_exact_evm_client(client, EthAccountSigner(account), networks="eip155:8453")
session = x402_requests(client)
payload = {
"domain": "example.com"
}
res = session.post("https://grist.tools/v1/ssl-cert-info", json=payload)
print(res.status_code, res.json())
settle = res.headers.get("payment-response")
if settle:
print(decode_payment_response_header(settle).transaction)curl
# ssl-cert-info: $0.002 per call, paid in USD Coin on eip155:8453 via x402
# 1. Unpaid call: HTTP 402, the requirements in the payment-required header (base64 JSON) and in the body.
curl -i -X POST 'https://grist.tools/v1/ssl-cert-info' -H 'content-type: application/json' -d '{"domain":"example.com"}'
# 2. Same call with the signed payment (an EIP-3009 authorization, EIP-712 signed: it cannot be
# typed by hand). x-payment is accepted as the v1 alternative. HTTP 200 carries payment-response.
curl -i -X POST 'https://grist.tools/v1/ssl-cert-info' -H 'content-type: application/json' -H 'payment-signature: <base64 x402 payload>' -d '{"domain":"example.com"}'06Errors
| Code | HTTP | For this service |
|---|---|---|
| invalid_input | 400 | The body does not match the schema; its fields are domain, url and port. |
| blocked_target | 403 | |
| unreachable_target | 424 | |
| upstream_timeout | 424 | |
| internal | 500 |
Input that is rejected before the tool runs (malformed JSON, schema mismatch, body over the size limit) is never charged.
When each code is raised, and what it means for payment: /docs/ssl-cert-info.
07Questions
- How much does a ssl-cert-info call cost?
- $0.002 per call, paid in USDC on Base via x402, with no account and no API key.
- What does ssl-cert-info return?
- A JSON object with 11 top-level fields: host, port, issuer, subject, san, valid_from, valid_to, days_to_expiry, self_signed, chain and queried_at. The example on this page is illustrative, not a recorded call.
- What happens when a ssl-cert-info call fails?
- The tool answers with a typed JSON error from the errors table. Payment is settled only after the tool has produced its result; a call that fails inside the tool is never settled. A 503 upstream_unavailable can follow a settled call; the x402 payments guide covers it, 429, 402 and an uncertain 500.