# Forest Infra TLS Preflight

> Forest Infra TLS Preflight is a paid API for AI agents from http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run, paid per call via x402, $0.002/call, status unknown (last checked 2026-10-02).

Inspects a public TLS endpoint on port 443 and returns certificate identity fields and validity window facts as a bounded preflight check.

## Facts

- Endpoint: POST https://http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run/tls/preflight?utm_source=zero.xyz
- Price: $0.002/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/forest-infra-tls-preflight-5866aa7b
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_wjqUat-DTU5e5J7Fur7O6

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability forest-infra-tls-preflight-5866aa7b -d '<json body>'
```

Example prompt: Can you do a TLS preflight check on api.stripe.com port 443 and tell me the certificate's subject, issuer, and when it expires?

## When to prefer this

Choose this endpoint when you need a quick, bounded preflight retrieval of TLS certificate identity and validity facts for a single public hostname — especially useful before deployments, integrations, or alerting pipelines. It is not a vulnerability scanner or full security audit tool; prefer it over heavier scanners when you only need cert identity and expiry metadata cheaply and quickly.

## Known failure modes

- Host does not resolve or is unreachable — connection error returned
- Host does not serve TLS on port 443 — handshake failure
- Hostname pattern validation fails (non-alphanumeric/dot/hyphen characters) — 400 bad request
- Certificate exists but is self-signed or uses an unexpected chain — facts returned but no interpretation
- Timeout if the remote host is slow to respond

## How this service works

Inspect one public TLS endpoint and return certificate identity and validity-window facts. This is a bounded preflight, not a vulnerability scanner or security guarantee. Base mainnet USDC

## Output

Returns certificate identity fields (subject, issuer, SANs) and the validity window (not-before and not-after timestamps) for the probed TLS endpoint. Does not perform vulnerability scanning or issue security guarantees — this is a lightweight preflight fact retrieval.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "host": {
   "type": "string",
   "pattern": "^[a-z0-9.-]+$",
   "maxLength": 253,
   "description": "Public DNS hostname to resolve."
  },
  "port": {
   "const": 443,
   "description": "TLS port to probe; only the public TLS endpoint is supported."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/forest-infra-tls-preflight-5866aa7b/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run](https://www.zero.xyz/host/http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run/llms.txt)
