# Delx Commerce TLS Inspect

> Delx Commerce TLS Inspect is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-01).

Inspects the TLS/SSL certificate of a given HTTPS URL, returning issuer, SAN DNS entries, subject, and days until expiry.

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/tls-inspect?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-tls-inspect-414a55cd
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_8mgZ1E6r24w-0EE-q_OlG

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-tls-inspect-414a55cd -d '<json body>'
```

Example prompt: Can you inspect the TLS certificate for https://api.mycompany.com and tell me how many days it has left before it expires, plus who issued it? Use a 10-second timeout.

## When to prefer this

Use this endpoint when an AI agent needs programmatic, structured TLS certificate metadata (issuer, SAN, expiry days) for a specific HTTPS URL without setting up custom tooling. It is ideal for certificate monitoring workflows, security audits, and vendor vetting tasks where no signup overhead is acceptable. Prefer it over general web-scraping tools when you specifically need certificate-layer information rather than page content.

## Known failure modes

- Host unreachable or DNS resolution failure — returns an error with no result object
- Timeout exceeded if the remote host is slow to respond — use the timeout parameter (1–15 seconds) to control this
- Non-HTTPS URL provided — endpoint is specific to TLS and will fail on plain HTTP or non-existent hosts
- Invalid URL format — missing scheme or malformed domain causes a parsing error
- Self-signed or untrusted certificates may cause handshake failures depending on implementation

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

A JSON object containing the host, port, issuer organization and common name, SAN DNS entries, certificate subject common name, and the number of days remaining until the certificate expires.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "url": {
   "type": "string"
  },
  "timeout": {
   "type": "integer",
   "maximum": 15,
   "minimum": 1,
   "description": "Per-network-phase cap; the whole tool shares a 10-second active budget including resolution and fallbacks. Not an end-to-end latency SLA."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "result": {
   "host": "example.com",
   "port": 443,
   "issuer": [
    "organizationName=DigiCert Inc",
    "commonName=DigiCert Global G3 TLS ECC SHA384 2020 CA1"
   ],
   "san_dns": [
    "example.com",
    "*.example.com"
   ],
   "subject": [
    "commonName=*.example.com"
   ],
   "days_until_expiry": 30
  },
  "tool_name": "util_tls_inspect"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-tls-inspect-414a55cd/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
