# TLS/SSL Certificate Inspector

> TLS/SSL Certificate Inspector is a paid API for AI agents from twin.unykorn.org, paid per call via x402, $0.002/call, status unknown (last checked 2026-10-02).

Checks a hostname's TLS/SSL certificate and returns issuer, expiry date, days remaining, SANs, trust status, and protocol version

## Facts

- Endpoint: POST https://twin.unykorn.org/web/tls-cert?utm_source=zero.xyz
- Price: $0.002/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/tls-ssl-certificate-inspector-315fee2b
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_OXQnSAlQw_4kOCKFEL9z8

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability tls-ssl-certificate-inspector-315fee2b -d '<json body>'
```

Example prompt: Can you check the TLS certificate for api.stripe.com — I want to know who issued it, when it expires, how many days are left, what domains it covers, and whether it's trusted?

## When to prefer this

Use this endpoint when you need to programmatically inspect TLS/SSL certificate details for any hostname — particularly for certificate expiry monitoring, security audits, compliance checks, or verifying SANs coverage. It is ideal for AI agents that need structured certificate metadata (issuer, days left, SANs, trust, protocol) without spinning up custom TLS inspection tooling. Prefer this over manual certificate checks or generic web scraping when you need machine-readable certificate data at low cost ($0.002/call).

## Known failure modes

- Host not reachable or DNS resolution failure for the provided hostname
- Host does not support TLS/SSL (plain HTTP only)
- Self-signed or untrusted certificate that cannot be verified
- Connection timeout when the host is slow to respond
- Invalid or malformed hostname input
- Certificate already expired — returned with 0 or negative days remaining

## How this service works

TLS/SSL certificate check: issuer, expiry, days left, SANs, trust, protocol — Genesis402 / UnyKorn Operator Network

## Output

Returns structured details about the hostname's TLS/SSL certificate including the certificate issuer (CA name), expiry date and timestamp, number of days remaining until expiry, Subject Alternative Names (SANs) listing all covered domains, whether the certificate chain is trusted, and the TLS/SSL protocol version in use.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "params": {
   "type": "object",
   "properties": {
    "host": {
     "type": "string",
     "description": "required: hostname"
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "ok": true,
  "type": "tls-certificate",
  "receipt": {
   "tx_hash": "0x<64hex>",
   "amount_usd": 0.002,
   "receipt_id": "g402-<16hex>"
  },
  "sources": [
   {
    "ok": true,
    "name": "<source>"
   }
  ],
  "limitations": "<text>",
  "generated_at": "<iso time>",
  "evidence_hash": "sha256:<64hex>"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/tls-ssl-certificate-inspector-315fee2b/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from twin.unykorn.org](https://www.zero.xyz/host/twin.unykorn.org/llms.txt)
