{
  "name": "ssl-cert-info",
  "summary": "Fetches the TLS certificate a host presents: issuer, subject, SAN list, validity window, days to expiry and the full chain.",
  "rationale": "Reading a live certificate needs a TLS handshake against the host, which an agent may be unable to make; the days-to-expiry and chain view are what you monitor across a fleet of domains.",
  "family": "domain",
  "price_usd": "0.002",
  "free": false,
  "timeout_ms": 10000,
  "max_timeout_seconds": 31,
  "input_schema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "type": "object",
    "properties": {
      "domain": {
        "description": "Public fully qualified domain name to connect to and send as SNI. Give exactly one of domain or url.",
        "type": "string",
        "minLength": 1
      },
      "url": {
        "description": "An http(s) URL whose host is probed; an explicit port in the URL overrides the port field, and the path is ignored. Give exactly one of domain or url.",
        "type": "string",
        "minLength": 1
      },
      "port": {
        "default": 443,
        "description": "TLS port for the handshake, one of 443, 465, 636, 990, 993, 995, 8443; defaults to 443.",
        "type": "integer",
        "minimum": -9007199254740991,
        "maximum": 9007199254740991
      }
    },
    "additionalProperties": false
  },
  "input_example": {
    "domain": "example.com"
  },
  "output_example": {
    "host": "example.com",
    "port": 443,
    "issuer": "CN=R3, O=Let's Encrypt, C=US",
    "subject": "CN=example.com, O=Example Inc, C=US",
    "san": [
      "example.com",
      "www.example.com"
    ],
    "valid_from": "2026-08-01T00:00:00.000Z",
    "valid_to": "2026-10-30T23:59:59.000Z",
    "days_to_expiry": 65,
    "self_signed": false,
    "chain": [
      {
        "issuer": "CN=R3, O=Let's Encrypt, C=US",
        "subject": "CN=example.com, O=Example Inc, C=US",
        "valid_from": "2026-08-01T00:00:00.000Z",
        "valid_to": "2026-10-30T23:59:59.000Z"
      },
      {
        "issuer": "CN=ISRG Root X1, O=Internet Security Research Group, C=US",
        "subject": "CN=R3, O=Let's Encrypt, C=US",
        "valid_from": "2020-09-04T00:00:00.000Z",
        "valid_to": "2025-09-15T16:00:00.000Z"
      }
    ],
    "queried_at": "2026-08-26T18:00:00.000Z"
  },
  "errors": [
    "invalid_input",
    "blocked_target",
    "unreachable_target",
    "upstream_timeout",
    "internal"
  ]
}