Skip to content
We use cookies to improve the site and measure traffic. See our Cookie Policy. You can accept or reject non-essential cookies.
  • Free
  • No signup
  • Fast
  • Privacy-friendly

Back to Category

SSL/TLS Certificate Checker

Inspect a live HTTPS certificate or paste PEM/CSR offline for subject, expiry, and fingerprint.

Or paste PEM / CSR for offline decode (used instead of URL when filled)

Waiting for bot check… this usually takes a second.

What next?

Keep going with SSL/TLS Certificate Checker

Finish this check in the browser, then pick the path that matches how you work — another related tool, REST for apps, or MCP for agents.

  1. 1. Related check

    After this result, run DNS lookup for the next signal.

    DNS lookup
  2. 2. Automate with API

    Same job from your server with X-Api-Key. Free tier includes 500 credits/month.

    Create free account
  3. 3. Hand off to an agent

    Connect MCP and run playbook ship-gate, then verify until pass.

    ship gate

What is SSL/TLS Certificate Checker?

Check live TLS peer certificates or paste PEM/CSR for offline decode. Not a full SSL Labs grade. This check is part of ship-gate and full-security-audit playbooks — agents plan, run, and verify until certificate issues clear. See <a href="/developers/ship-gate">ship gate</a>. Related browser tools: DNS Lookup, HTTP Security Redirect Checker.

What are common questions about SSL/TLS Certificate Checker?

What does SSL/TLS Certificate Checker do?

Inspect a live HTTPS certificate or paste PEM/CSR offline for subject, expiry, and fingerprint.

Is this available via API and MCP?

Yes. Same route under /api/v1/security-apis/{slug} with one ToolYour API key.

What are the key features of SSL/TLS Certificate Checker?

Expiry countdown

Days remaining with warn under 30 days and fail when expired or under 14.

SAN and fingerprint

Subject alternative names and SHA-256 fingerprint for inventory and pinning notes.

How do you use SSL/TLS Certificate Checker?

Enter an https URL

Hostname is taken from the URL; custom ports are supported.

Review findings

Check expiry, issuer, and whether SANs match the host you expected.

Honest scope

Useful for renewal ops and quick host checks. Follow with your CA/ACME monitor and a periodic SSL Labs or similar deep scan for cipher policy.

Free · API · MCPToolYour platform

Use SSL/TLS Certificate Checker three ways

The free SSL/TLS Certificate Checker on this page works in your browser. The same workflow is available via REST API for apps and via the remote MCP server for Cursor, Claude, and other agents — one API key, one plan, one quota. This tool is part of the security-apis module under Security Tools.

Agents close the full job with run_playbook ship-gate, then verify until pass — see ship gate.

  1. 1Create a free accountGet an API key for REST and MCP — 500 credits/month on the free tier.
  2. 2Connect or callPaste the MCP URL into Cursor/Claude, or call REST with X-Api-Key.
  3. 3Same key & creditsBrowser smoke-checks stay free; API-backed runs share one monthly credit quota.