# TLS Certificate Inspector

> TLS Certificate Inspector is a paid API for AI agents from 49112-hjhjtioxvirqvcvo.splox.app, paid per call via x402, $0.0005/call, status unknown (last checked 2026-10-02).

Retrieves and validates TLS/SSL certificate details for a given hostname, including validity, expiry, issuer, cipher, and SAN information.

## Facts

- Endpoint: GET https://49112-hjhjtioxvirqvcvo.splox.app/tls-certificate?utm_source=zero.xyz
- Price: $0.0005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/tls-certificate-inspector-7db3e4fb
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_D0MYkRS_s-8v-J9eTuFdA

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability tls-certificate-inspector-7db3e4fb
```

Example prompt: Can you check whether api.stripe.com has a valid TLS certificate, and tell me how many days are left before it expires and who issued it?

## When to prefer this

Use this endpoint when an AI agent needs to programmatically check TLS certificate health, expiry countdown, issuer trust, or cipher/TLS version details for any hostname — particularly useful for automated certificate monitoring, security audits, or pre-integration vendor checks. Prefer this over manual curl-based inspection when you need structured, machine-readable output at low cost ($0.0005 per call) with x402 micropayment support.

## Known failure modes

- Host unreachable or DNS resolution failure returns an error field
- Invalid or malformed hostname returns an error
- Host does not support TLS on port 443 returns an error
- Self-signed or unrecognized CA returns valid=false
- Expired certificate returns valid=false with days_left <= 0
- Network timeout from the service side returns an error field

## How this service works

Paid per-call web tools for AI agents: DNS, TLS, robots.txt, hashing, JavaScript rendering and screenshots. Payment over x402 (USDC on Base).

## Output

Returns a JSON object with the hostname and port checked, a boolean indicating whether the certificate chain is verified and within its validity window, the cipher suite, issuer name, subject name, days remaining until expiry, the expiry datetime, TLS version string, count of Subject Alternative Names, and a sample list of SANs. On error, an error field is included instead.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "required": [
  "host"
 ],
 "properties": {
  "host": {
   "type": "string",
   "description": "host to check TLS for, e.g. example.com"
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "object",
 "required": [
  "host"
 ],
 "properties": {
  "host": {
   "type": "string"
  },
  "port": {
   "type": "integer"
  },
  "error": {
   "type": "string"
  },
  "valid": {
   "type": "boolean",
   "description": "certificate chain verified and inside its validity window"
  },
  "cipher": {
   "type": "string"
  },
  "issuer": {
   "type": "string"
  },
  "subject": {
   "type": "string"
  },
  "days_left": {
   "type": "integer",
   "description": "days until not_after"
  },
  "not_after": {
   "type": "string",
   "format": "date-time"
  },
  "san_count": {
   "type": "integer"
  },
  "san_sample": {
   "type": "array",
   "items": {
    "type": "string"
   }
  },
  "tls_version": {
   "type": "string"
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/tls-certificate-inspector-7db3e4fb/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from 49112-hjhjtioxvirqvcvo.splox.app](https://www.zero.xyz/host/49112-hjhjtioxvirqvcvo.splox.app/llms.txt)
