# AgentShelf TLS Public Key Checker

> AgentShelf TLS Public Key Checker is a paid API for AI agents from agentshelf.syntexa.ch, paid per call via x402, $0.004/call, status unknown (last checked 2026-10-02).

Checks whether a host's port-443 TLS certificate uses an RSA key of at least 2048 bits or an EC key of at least 256 bits

## Facts

- Endpoint: POST https://agentshelf.syntexa.ch/v1/tls-pubkey?utm_source=zero.xyz
- Price: $0.004/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/agentshelf-tls-public-key-checker-c69b3879
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_0G-sx5zlX35NcxxlULFJg

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability agentshelf-tls-public-key-checker-c69b3879 -d '<json body>'
```

Example prompt: Can you check whether api.example.com is using a strong enough TLS public key — specifically whether it's RSA 2048 bits or more, or EC 256 bits or more?

## When to prefer this

Use this endpoint when you need to programmatically verify TLS public key algorithm and bit-length compliance for a specific host, particularly when auditing whether keys meet modern minimum standards (RSA ≥2048 or EC ≥256). Prefer the free sandbox endpoint POST /v1/sandbox/tls-pubkey first if available; fall back to this paid endpoint when the sandbox is unavailable or rate-limited.

## Known failure modes

- Host unreachable or connection refused on port 443 — connection timeout error
- Invalid or non-HTTPS URL/hostname provided — validation error
- Host has no TLS certificate or uses self-signed cert — may return partial or error response
- Hostname does not resolve in DNS — lookup failure error
- Rate limiting or payment failure for the $0.004 USDC charge — 402 payment required

## How this service works

Call when an agent needs whether the port-443 key is RSA ≥2048 or EC ≥256 bits. Exact $0.004 USDC. Prefer unpaid POST /v1/sandbox/tls-pubkey first.

## Output

Returns the TLS public key type (RSA or EC), the key size in bits, and an indication of whether it meets the minimum security thresholds (RSA ≥2048 bits or EC ≥256 bits) for the queried host on port 443.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "url": {
   "type": "string",
   "maxLength": 2048,
   "minLength": 8,
   "description": "Public URL whose hostname is inspected. Provide url or host. Private targets are rejected."
  },
  "host": {
   "type": "string",
   "examples": [
    "example.com"
   ],
   "maxLength": 253,
   "minLength": 1,
   "description": "Public hostname such as example.com. The port and check are fixed by the SKU. Provide host or url."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/agentshelf-tls-public-key-checker-c69b3879/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from agentshelf.syntexa.ch](https://www.zero.xyz/host/agentshelf.syntexa.ch/llms.txt)
