# CertGuard > Free SSL/TLS certificate checker: a live TLS handshake reports expiry, chain completeness and trust, hostname match, TLS version, cipher suite and key, with an A/B/C/F grade and findings. Public JSON API plus a remote MCP server for AI agents. CertGuard connects to the host you name (ports 443, 8443, 465, 993, 995) from Cloudflare Workers, reads the certificate chain the server sends and verifies it against Mozilla's root store. Revocation (OCSP/CRL) is never checked; every result says `"revocation_checked": false`. Hosts served from Cloudflare's own network cannot be checked live (Workers can't open sockets to Cloudflare IPs): they get `live_unavailable` and no grade. A failed handshake returns `check_failed` and no grade. Private, internal and reserved addresses are refused. ## For AI agents - [MCP server](https://certguard.mike-tusa.workers.dev/mcp): remote MCP over Streamable HTTP at `https://certguard.mike-tusa.workers.dev/mcp` (POST only, stateless, JSON responses, no sessions). Protocol versions: 2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05 (2026-07-28 per-request `_meta`; older versions use `initialize`). One tool: `check_certificate` with `host` (required), `port` and `include_raw` (optional). Read-only. Client config (most MCP clients accept this; some use a different format, for example VS Code uses a `servers` key): `{"mcpServers":{"certguard":{"type":"http","url":"https://certguard.mike-tusa.workers.dev/mcp"}}}` - [OpenAPI 3.1 spec](https://certguard.mike-tusa.workers.dev/openapi.json): machine-readable description of the JSON API - [JSON API docs](https://certguard.mike-tusa.workers.dev/docs): human-readable API reference with examples ## JSON API - `GET https://certguard.mike-tusa.workers.dev/api/v1/check?host=example.com` (optional `&port=443`; allowed 443, 8443, 465, 993, 995), or `POST` with `{"host":"example.com","port":443}`: full result as JSON (`grade`, `summary`, `expiry`, `certificate`, `hostname`, `tls`, `chain`, `issues`, `notChecked`, `revocation_checked`, `cache`). CORS enabled. - `POST https://certguard.mike-tusa.workers.dev/api/v1/keys` with `{}` or `{"email":"you@example.com"}` (JSON, no CORS): free API key, shown once. - `GET https://certguard.mike-tusa.workers.dev/api/v1/usage` with your key: today's usage and quota. - `GET https://certguard.mike-tusa.workers.dev/health`: service status and `version` (0.2.0). - Errors: `{ "ok": false, "error": { "code", "message" } }` with HTTP 400 `invalid_host`/`invalid_port`/`port_not_allowed`/`invalid_json`, 401 `invalid_api_key`, 403 `blocked_target`, 413 `payload_too_large`, 422 `nxdomain`/`no_address`/`live_check_unavailable`, 429 `rate_limited`/`ip_daily_quota`/`key_quota_exceeded`/`issuer_quota_exceeded`/`daily_cap_reached` (see `Retry-After`), 502 `check_failed`/`dns_error`, 503 `not_configured`/`live_check_unavailable`. ## Limits and keys - Anonymous (no key): about 10 checks per minute and 200 per UTC day per IP (IPv6: per /64, and 600 per /48). - Free API key: about 60 checks per minute and 1,000 per UTC day; all keys issued to one IP share 1,000 checks per day. Send `X-API-Key: cg_…` or `Authorization: Bearer cg_…`. At most 3 new keys per IP per day. There is no paid plan. - Limits apply to every check request, including ones answered from the cache. Successful live results are cached for up to 10 minutes; failed checks are never cached. - The MCP endpoint uses the same keys and the same counters: each `tools/call` is one check. `initialize`, `tools/list` and other non-check messages don't count as checks, but have a light cap of about 120 per minute per IP (over it: HTTP 429 with `Retry-After`). Over a check limit, the tool result has `isError: true` with the reason and `retryAfterSeconds`. An invalid key returns HTTP 401. - MCP request caps: 65,536-byte body, JSON-RPC batches (legacy versions only) of at most 10 messages with at most one `tools/call`. ## Optional - [Homepage and checker](https://certguard.mike-tusa.workers.dev/) - Contact: digitalpromohub.support@gmail.com