CertGuard

Free SSL/TLS certificate checker — expiry, chain & trust, hostname match, TLS version, key and signature. JSON API

What we don't check: sites hosted behind Cloudflare (a large share of the web) can't be checked live — they show “live check unavailable” and get no grade; certificate revocation (OCSP/CRL) — a revoked certificate can still get a passing grade here; whether the server also accepts old TLS 1.0/1.1; and full cipher-suite enumeration.

For AI agents (MCP)

CertGuard is also a remote Model Context Protocol (MCP) server with one read-only tool, check_certificate. Most MCP clients accept this config; some use a different format (for example, VS Code uses a servers key). Clients with a settings screen just need the URL https://certguard.mike-tusa.workers.dev/mcp.

{
  "mcpServers": {
    "certguard": {
      "type": "http",
      "url": "https://certguard.mike-tusa.workers.dev/mcp"
    }
  }
}

Same limits and optional free API key as the JSON API (send it as X-API-Key or Authorization: Bearer). Machine-readable docs: llms.txt · OpenAPI 3.1 spec · API docs