CertGuard
Free SSL/TLS certificate checker — expiry, chain & trust, hostname match, TLS version, key and signature. JSON API
What we don't check: sites hosted behind Cloudflare (a large share of the web) can't be checked live — they show “live check unavailable” and get no grade; certificate revocation (OCSP/CRL) — a revoked certificate can still get a passing grade here; whether the server also accepts old TLS 1.0/1.1; and full cipher-suite enumeration.
For AI agents (MCP)
CertGuard is also a remote Model Context Protocol (MCP) server with one read-only tool, check_certificate. Most MCP clients accept this config; some use a different format (for example, VS Code uses a servers key). Clients with a settings screen just need the URL https://certguard.mike-tusa.workers.dev/mcp.
{
"mcpServers": {
"certguard": {
"type": "http",
"url": "https://certguard.mike-tusa.workers.dev/mcp"
}
}
}
Same limits and optional free API key as the JSON API (send it as X-API-Key or Authorization: Bearer). Machine-readable docs: llms.txt · OpenAPI 3.1 spec · API docs