# SSL Certificate Monitor (`blackfalcondata/ssl-certificate-monitor`) Actor

Bulk SSL/TLS certificate monitor: issuer, validity window, days-to-expiry, chain validity, SANs and protocol for every domain, plus HTTP/HTTPS status, with expiring-soon and invalid-certificate flags and incremental change tracking. $1 per 1,000 domains.

- **URL**: https://apify.com/blackfalcondata/ssl-certificate-monitor.md
- **Developed by:** [Black Falcon Data](https://apify.com/blackfalcondata) (community)
- **Categories:** Developer tools, Lead generation, Automation
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $1.00 / 1,000 results

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are a software tools running on the Apify platform, for all kinds of web data extraction and automation use cases.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

In JavaScript/TypeScript projects, use official [JavaScript/TypeScript client](https://docs.apify.com/api/client/js/docs.md):

```bash
npm install apify-client
```

In Python projects, use official [Python client library](https://docs.apify.com/api/client/python/docs.md):

```bash
pip install apify-client
```

In shell scripts, use [Apify CLI](https://docs.apify.com/cli/docs.md):

````bash
# MacOS / Linux
curl -fsSL https://apify.com/install-cli.sh | bash
# Windows
irm https://apify.com/install-cli.ps1 | iex
```bash

In AI frameworks, you might use the [Apify MCP server](https://docs.apify.com/integrations/mcp.md).

If your project is in a different language, use the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).


# README

### What does SSL Certificate Monitor do?

SSL Certificate Monitor audits the TLS certificate of any list of domains in a single run. It checks issuer, validity window, days-to-expiry, chain validity, subject alternative names (SANs) and negotiated protocol, plus HTTP/HTTPS reachability. It flags certificates that are expired, expiring soon or invalid. Paste bare domains or full URLs — they're auto-cleaned to the apex. Turn on monitoring to catch renewals and upcoming expiries before they take a site down. DNS, WHOIS, email-auth and blacklist checks are available too for a full domain audit.

### How to use this actor

- 👉 **Register for a free Apify account** — no credit card required.
- 🎉 Just click **[Sign up free on Apify →](https://console.apify.com/sign-up?fpr=1h3gvi&fp_sid=ctarich)** and complete a quick signup.
- 💰 A free Apify account includes $5 in monthly credits — enough to test this actor.
- ⏳ Scrape during the free trial, with no commitment or upfront payment required.

### Key features

<!-- KEY_FEATURES:START -->
- **🔒 Full certificate detail** — issuer, subject, valid-from / valid-to, days-to-expiry, chain validity, SANs and negotiated TLS protocol, parsed for every domain.
- **⏰ Expiry & validity flags** — SSL_EXPIRED, SSL_EXPIRING_SOON (≤30 days) and SSL_INVALID surface the certificates that need attention now, so nothing lapses unnoticed.
- **🌐 HTTP/HTTPS status** — status codes for both schemes plus whether the site upgrades http to https, flagging domains with no HTTPS redirect.
- **♻️ Certificate monitoring** — incremental mode flags NEW / UPDATED domains and detects certificate renewals and fingerprint changes since the previous run.
- **🧩 Full audit option** — enable DNS, WHOIS, email-authentication and blacklist checks for complete domain data alongside the certificate signals.
- **🔔 Notifications** — push new findings to Telegram, Discord, Slack, WhatsApp or a generic webhook (n8n / Make / Zapier).
- **📦 Compact + MCP output** — a compact at-a-glance mode and MCP-connector export for AI-agent and automation workflows.
<!-- KEY_FEATURES:END -->

### What data can you get for each domain?

Each result includes Core domain fields (`domain`, `inputUrl`, `securityScore`, `flags`, `dns`, `whois`, `ssl`, and `http`, and more). In standard mode, all fields are always present — unavailable data points are returned as `null`, never omitted. In compact mode, only core fields are returned.

### Input

Configure the actor through the input schema in Apify Console.

Key parameters:

- **`domains`** — Domains or full URLs to inspect — one per line, or paste a JSON array. Full URLs are auto-cleaned to the apex domain (https://www.example.com/path → example.com).
- **`checks`** — Which inspections to run per domain. Defaults to the SSL set (certificate + HTTP/HTTPS); enable DNS/WHOIS/email/blacklist too for a full audit. (default: `["ssl","http"]`)
- **`recordTypes`** — Which DNS record types to resolve when the DNS check is enabled. (default: `["A","AAAA","MX","TXT","CNAME","NS","SOA","CAA"]`)
- **`dkimSelectors`** — DKIM cannot be enumerated, so common selectors (default, google, selector1/2, k1…) are probed automatically. Add your ESP's selector here to catch custom setups. (default: `[]`)
- **`compact`** — At-a-glance verdict only (domain, security score, email grade, flags) — drops the raw record blocks. Ideal for AI-agent / MCP workflows. (default: `false`)
- **`excludeEmptyFields`** — Drop null, empty-string, and empty-array fields from each record before push. Smaller payloads for AI agents and dashboards. (default: `false`)
- **`incrementalMode`** — Compare each domain against the previous run and flag changes (NEW / UPDATED / UNCHANGED). Detects cert renewals, WHOIS expiry, DNS changes, email-auth drift and blacklist appearances over time. stateKey is optional — defaults to a stable key derived from the domain list + checks. (default: `false`)
- **`stateKey`** — Optional. Stable identifier for the monitored domain set. Leave empty to auto-generate from the domain list + checks.
- **`emitUnchanged`** — When monitoring, also output domains whose signals did not change since the last run. Off = only NEW and UPDATED domains are emitted. (default: `false`)
- **`telegramToken`** — Telegram bot token (from @BotFather). Required for Telegram notifications.
- **`telegramChatId`** — Telegram chat or channel ID (e.g. "-100123456789"). Required when telegramToken is set.
- ...and 12 more parameters

### Input examples

**Basic search** — Pick one or more checks from the supported taxonomy.

→ Full payload per result — all standard fields populated where the source provides them.

```json
{
  "checks": [
    "dns"
  ]
}
````

**Incremental tracking** — Only emit domains that changed since the previous run with this `stateKey`.

→ First run builds the baseline state. Subsequent runs emit only records that are new or whose tracked content changed. Set `emitUnchanged: true` to include unchanged records as well.

```json
{
  "checks": [
    "dns"
  ],
  "incrementalMode": true,
  "stateKey": "dns-tracker"
}
```

**Compact output for AI agents** — Return only core fields for AI-agent and MCP workflows.

→ Small payload with the most important fields — ideal for piping into LLMs without token overhead.

```json
{
  "checks": [
    "dns"
  ],
  "compact": true
}
```

### Output

Each run produces a dataset of structured domain records. Results can be downloaded as JSON, CSV, or Excel from the Dataset tab in Apify Console.

### Example domain record

```json
{
  "domain": "github.com",
  "inputUrl": "github.com",
  "securityScore": 100,
  "ssl": {
    "ok": true,
    "subject": "github.com",
    "issuer": "Sectigo Limited",
    "altNames": [
      "github.com",
      "www.github.com"
    ],
    "validFrom": "Jul  3 00:00:00 2026 GMT",
    "validTo": "Sep 30 23:59:59 2026 GMT",
    "daysToExpiry": 74,
    "expired": false,
    "certSha256": "17:F8:FD:2E:3F:D2:C1:13:FC:B9:77:2D:8A:4B:AB:B8:52:2D:D0:6D:D0:79:49:15:A4:FF:98:B1:B6:86:3A:00",
    "protocol": "TLSv1.3"
  },
  "http": {
    "http": {
      "status": 200,
      "finalUrl": "https://github.com/",
      "redirected": true,
      "server": "github.com"
    },
    "https": {
      "status": 200,
      "finalUrl": "https://github.com/",
      "redirected": false,
      "server": "github.com"
    },
    "upgradesToHttps": true
  },
  "checkedAt": "2026-07-18T13:05:18.587Z",
  "source": "ssl-certificate-monitor"
}
```

### Incremental fields

When incremental mode is on, each record also carries:

- `changeType` — one of `NEW`, `UPDATED`, `UNCHANGED`, `REAPPEARED`, `EXPIRED`. Default output covers `NEW` / `UPDATED` / `REAPPEARED`; set `emitUnchanged: true` to opt into the others.

### How to audit domains

1. Go to [SSL Certificate Monitor](https://apify.com/blackfalcondata/ssl-certificate-monitor?fpr=1h3gvi) in Apify Console.
2. Configure the input.
3. Set `maxResults` to control how many results you need.
4. Click **Start** and wait for the run to finish.
5. Export the dataset as JSON, CSV, or Excel.

### Use cases

- Monitor a portfolio of domains for SSL/TLS certificates expiring soon and renew them before they lapse and break the site.
- Alert on certificate changes — a new issuer or fingerprint — across your domains as a security and change-management signal.
- Verify HTTPS is correctly configured (valid chain, http→https redirect) across many domains in one pass.
- Audit vendor or acquisition-target domains for certificate hygiene as part of due diligence.
- Combine with DNS, WHOIS and email-auth checks for a full security-posture review of a domain portfolio.

### How much does it cost to audit domains?

SSL Certificate Monitor uses [pay-per-event](https://docs.apify.com/platform/actors/paid-actors/pay-per-event) pricing. You pay a small fee when the run starts and then for each result that is actually produced.

- **Run start:** $0.00005 per run
- **Per result:** $0.001 per domain record

Example costs:

- 10 results: **$0.01**
- 25 results: **$0.025**
- 100 results: **$0.1**
- 200 results: **$0.2**
- 500 results: **$0.5**

#### Example: recurring monitoring savings

These examples compare full re-scrapes with incremental runs at different churn rates. Churn is the share of domains that are new or whose tracked content changed since the previous run. Actual churn depends on your query breadth, source activity, and polling frequency — the scenarios below are examples, not predictions.

Example setup: 250 results per run, daily polling (30 runs/month). Event-pricing examples scale linearly with result count.

| Churn rate | Full re-scrape run cost | Incremental run cost | Savings vs full re-scrape | Monthly cost after baseline |
|---|---:|---:|---:|---:|
| 5% — stable niche query | $0.25 | $0.01 | $0.24 (95%) | $0.38 |
| 15% — moderate broad query | $0.25 | $0.04 | $0.21 (85%) | $1.13 |
| 30% — high-volume aggregator | $0.25 | $0.08 | $0.17 (70%) | $2.25 |

Full re-scrape monthly cost at daily polling: $7.50. First month with incremental costs $0.61 / $1.34 / $2.43 for the 5% / 15% / 30% scenarios because the first run builds baseline state at full cost before incremental savings apply.

Platform usage is included in the per-result fee shown above.

### FAQ

#### How many domains can I check per run?

Every domain in your input list is checked — there is no fixed cap, so the number of domains per run is limited only by your list size and the run's time budget.

#### Does SSL Certificate Monitor support recurring monitoring?

Yes. Enable incremental mode to only receive new or changed domains on subsequent runs. This is ideal for scheduled monitoring where you want to track changes over time without re-processing the full dataset.

#### Can I integrate SSL Certificate Monitor with other apps?

Yes. SSL Certificate Monitor works with Apify's [integrations](https://apify.com/integrations?fpr=1h3gvi) to connect with tools like Zapier, Make, Google Sheets, Slack, and more. You can also use webhooks to trigger actions when a run completes.

#### Can I use SSL Certificate Monitor with the Apify API?

Yes. You can start runs, manage inputs, and retrieve results programmatically through the [Apify API](https://docs.apify.com/api/v2). Client libraries are available for JavaScript, Python, and other languages.

#### Can I use SSL Certificate Monitor through an MCP Server?

Yes. Apify provides an [MCP Server](https://apify.com/apify/actors-mcp-server?fpr=1h3gvi) that lets AI assistants and agents call this actor directly. Use compact mode and `excludeEmptyFields` to keep payloads manageable for LLM context windows.

#### Is it legal to audit domains?

This actor queries publicly available DNS, WHOIS, certificate and reputation data for the domains you provide. Looking up public domain data is generally legal, but you should ensure your use complies with applicable laws and the queried services' terms, including GDPR where relevant.

#### Your feedback

If you have questions, need a feature, or found a bug, please [open an issue](https://apify.com/blackfalcondata/ssl-certificate-monitor/issues?fpr=1h3gvi) on the actor's page in Apify Console. Your feedback helps us improve.

### You might also like

- [Domain Intelligence Scraper](https://apify.com/blackfalcondata/domain-intelligence-scraper?fpr=1h3gvi) — All-in-one domain audit: DNS, WHOIS, SSL, HTTP, email authentication and blacklist checks with a.
- [Email Deliverability Checker](https://apify.com/blackfalcondata/email-deliverability-checker?fpr=1h3gvi) — SPF, DMARC, DKIM and DNSSEC audit with an A-F inbox-readiness grade for sending domains.
- [DNS Lookup](https://apify.com/blackfalcondata/dns-lookup?fpr=1h3gvi) — Bulk DNS record lookup: A, AAAA, MX, TXT, CNAME, NS, SOA, CAA and DNSSEC per domain.

### Getting started with Apify

New to Apify? [Create a free account with $5 credit](https://console.apify.com/sign-up?fpr=1h3gvi\&fp_sid=ctarich) — no credit card required.

1. Sign up — $5 platform credit included
2. Open this actor and configure your input
3. Click **Start** — export results as JSON, CSV, or Excel

Need more later? [See Apify pricing](https://apify.com/pricing?fpr=1h3gvi).

# Actor input Schema

## `domains` (type: `array`):

Domains or full URLs to inspect — one per line, or paste a JSON array. Full URLs are auto-cleaned to the apex domain (https://www.example.com/path → example.com).

## `checks` (type: `array`):

Which inspections to run per domain. Defaults to the SSL set (certificate + HTTP/HTTPS); enable DNS/WHOIS/email/blacklist too for a full audit.

## `recordTypes` (type: `array`):

Which DNS record types to resolve when the DNS check is enabled.

## `dkimSelectors` (type: `array`):

DKIM cannot be enumerated, so common selectors (default, google, selector1/2, k1…) are probed automatically. Add your ESP's selector here to catch custom setups.

## `timeoutMs` (type: `integer`):

Timeout for each individual DNS/WHOIS/SSL/HTTP lookup.

## `compact` (type: `boolean`):

At-a-glance verdict only (domain, security score, email grade, flags) — drops the raw record blocks. Ideal for AI-agent / MCP workflows.

## `excludeEmptyFields` (type: `boolean`):

Drop null, empty-string, and empty-array fields from each record before push. Smaller payloads for AI agents and dashboards.

## `incrementalMode` (type: `boolean`):

Compare each domain against the previous run and flag changes (NEW / UPDATED / UNCHANGED). Detects cert renewals, WHOIS expiry, DNS changes, email-auth drift and blacklist appearances over time. stateKey is optional — defaults to a stable key derived from the domain list + checks.

## `stateKey` (type: `string`):

Optional. Stable identifier for the monitored domain set. Leave empty to auto-generate from the domain list + checks.

## `emitUnchanged` (type: `boolean`):

When monitoring, also output domains whose signals did not change since the last run. Off = only NEW and UPDATED domains are emitted.

## `telegramToken` (type: `string`):

Telegram bot token (from @BotFather). Required for Telegram notifications.

## `telegramChatId` (type: `string`):

Telegram chat or channel ID (e.g. "-100123456789"). Required when telegramToken is set.

## `discordWebhookUrl` (type: `string`):

Discord incoming webhook URL. Server Settings → Integrations → Webhooks → New Webhook.

## `slackWebhookUrl` (type: `string`):

Slack incoming webhook URL. api.slack.com/messaging/webhooks.

## `notificationLimit` (type: `integer`):

Maximum number of domains included in each notification message (1–20).

## `notifyOnlyChanges` (type: `boolean`):

When monitoring is on, only send notifications for NEW and UPDATED domains. No effect otherwise.

## `whatsappAccessToken` (type: `string`):

WhatsApp Cloud API permanent access token (System User token from Meta Business). Recipient must have messaged the business number within the last 24h (service-conversation window — free since Nov 2024).

## `whatsappPhoneNumberId` (type: `string`):

Your WhatsApp Business phone-number ID (numeric, from Meta dashboard). Required when whatsappAccessToken is set.

## `whatsappTo` (type: `string`):

Recipient phone in E.164 format without + (e.g. "436641234567"). Recipient must have messaged your business number within last 24h.

## `webhookUrl` (type: `string`):

Receives a JSON POST with {metadata, items} after each run. Universal escape hatch for n8n / Make / Zapier / custom backends.

## `webhookHeaders` (type: `object`):

Optional JSON object of custom headers (e.g. {"Authorization":"Bearer ..."}).

## `appConnector` (type: `string`):

Optional. Pick a connected app under Settings → API & Integrations to receive your results. Best-effort across MCP connectors as Apify expands its catalog.

## `mcpIssueTeam` (type: `string`):

Only when the connected app is an issue tracker: the team (name or ID) the summary issue is created under, if that app requires one.

## Actor input object example

```json
{
  "domains": [
    "github.com",
    "badssl.com"
  ],
  "checks": [
    "ssl",
    "http"
  ],
  "recordTypes": [
    "A",
    "AAAA",
    "MX",
    "TXT",
    "CNAME",
    "NS",
    "SOA",
    "CAA"
  ],
  "dkimSelectors": [],
  "timeoutMs": 8000,
  "compact": false,
  "excludeEmptyFields": false,
  "incrementalMode": false,
  "emitUnchanged": false,
  "notificationLimit": 5,
  "notifyOnlyChanges": false
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "domains": [
        "github.com",
        "badssl.com"
    ],
    "excludeEmptyFields": false
};

// Run the Actor and wait for it to finish
const run = await client.actor("blackfalcondata/ssl-certificate-monitor").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {
    "domains": [
        "github.com",
        "badssl.com",
    ],
    "excludeEmptyFields": False,
}

# Run the Actor and wait for it to finish
run = client.actor("blackfalcondata/ssl-certificate-monitor").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "domains": [
    "github.com",
    "badssl.com"
  ],
  "excludeEmptyFields": false
}' |
apify call blackfalcondata/ssl-certificate-monitor --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=blackfalcondata/ssl-certificate-monitor",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

```json
{
    "openapi": "3.0.1",
    "info": {
        "title": "SSL Certificate Monitor",
        "description": "Bulk SSL/TLS certificate monitor: issuer, validity window, days-to-expiry, chain validity, SANs and protocol for every domain, plus HTTP/HTTPS status, with expiring-soon and invalid-certificate flags and incremental change tracking. $1 per 1,000 domains.",
        "version": "0.1",
        "x-build-id": "QF0hRaEiZ0kSaiNuQ"
    },
    "servers": [
        {
            "url": "https://api.apify.com/v2"
        }
    ],
    "paths": {
        "/acts/blackfalcondata~ssl-certificate-monitor/run-sync-get-dataset-items": {
            "post": {
                "operationId": "run-sync-get-dataset-items-blackfalcondata-ssl-certificate-monitor",
                "x-openai-isConsequential": false,
                "summary": "Executes an Actor, waits for its completion, and returns Actor's dataset items in response.",
                "tags": [
                    "Run Actor"
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/inputSchema"
                            }
                        }
                    }
                },
                "parameters": [
                    {
                        "name": "token",
                        "in": "query",
                        "required": true,
                        "schema": {
                            "type": "string"
                        },
                        "description": "Enter your Apify token here"
                    }
                ],
                "responses": {
                    "200": {
                        "description": "OK"
                    }
                }
            }
        },
        "/acts/blackfalcondata~ssl-certificate-monitor/runs": {
            "post": {
                "operationId": "runs-sync-blackfalcondata-ssl-certificate-monitor",
                "x-openai-isConsequential": false,
                "summary": "Executes an Actor and returns information about the initiated run in response.",
                "tags": [
                    "Run Actor"
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/inputSchema"
                            }
                        }
                    }
                },
                "parameters": [
                    {
                        "name": "token",
                        "in": "query",
                        "required": true,
                        "schema": {
                            "type": "string"
                        },
                        "description": "Enter your Apify token here"
                    }
                ],
                "responses": {
                    "200": {
                        "description": "OK",
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/runsResponseSchema"
                                }
                            }
                        }
                    }
                }
            }
        },
        "/acts/blackfalcondata~ssl-certificate-monitor/run-sync": {
            "post": {
                "operationId": "run-sync-blackfalcondata-ssl-certificate-monitor",
                "x-openai-isConsequential": false,
                "summary": "Executes an Actor, waits for completion, and returns the OUTPUT from Key-value store in response.",
                "tags": [
                    "Run Actor"
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/inputSchema"
                            }
                        }
                    }
                },
                "parameters": [
                    {
                        "name": "token",
                        "in": "query",
                        "required": true,
                        "schema": {
                            "type": "string"
                        },
                        "description": "Enter your Apify token here"
                    }
                ],
                "responses": {
                    "200": {
                        "description": "OK"
                    }
                }
            }
        }
    },
    "components": {
        "schemas": {
            "inputSchema": {
                "type": "object",
                "required": [
                    "domains"
                ],
                "properties": {
                    "domains": {
                        "title": "🌐 Domains",
                        "type": "array",
                        "description": "Domains or full URLs to inspect — one per line, or paste a JSON array. Full URLs are auto-cleaned to the apex domain (https://www.example.com/path → example.com).",
                        "items": {
                            "type": "string"
                        }
                    },
                    "checks": {
                        "title": "✅ Checks to run",
                        "type": "array",
                        "description": "Which inspections to run per domain. Defaults to the SSL set (certificate + HTTP/HTTPS); enable DNS/WHOIS/email/blacklist too for a full audit.",
                        "items": {
                            "type": "string",
                            "enum": [
                                "dns",
                                "whois",
                                "ssl",
                                "http",
                                "emailAuth",
                                "blacklist"
                            ],
                            "enumTitles": [
                                "DNS records",
                                "WHOIS (registrar, expiry)",
                                "SSL/TLS certificate",
                                "HTTP/HTTPS status",
                                "Email auth (SPF/DMARC/DKIM)",
                                "Domain blacklist"
                            ]
                        },
                        "default": [
                            "ssl",
                            "http"
                        ]
                    },
                    "recordTypes": {
                        "title": "📇 DNS record types",
                        "type": "array",
                        "description": "Which DNS record types to resolve when the DNS check is enabled.",
                        "items": {
                            "type": "string",
                            "enum": [
                                "A",
                                "AAAA",
                                "MX",
                                "TXT",
                                "CNAME",
                                "NS",
                                "SOA",
                                "CAA"
                            ]
                        },
                        "default": [
                            "A",
                            "AAAA",
                            "MX",
                            "TXT",
                            "CNAME",
                            "NS",
                            "SOA",
                            "CAA"
                        ]
                    },
                    "dkimSelectors": {
                        "title": "🔑 Extra DKIM selectors",
                        "type": "array",
                        "description": "DKIM cannot be enumerated, so common selectors (default, google, selector1/2, k1…) are probed automatically. Add your ESP's selector here to catch custom setups.",
                        "default": [],
                        "items": {
                            "type": "string"
                        }
                    },
                    "timeoutMs": {
                        "title": "⏱️ Per-lookup timeout (ms)",
                        "minimum": 2000,
                        "maximum": 30000,
                        "type": "integer",
                        "description": "Timeout for each individual DNS/WHOIS/SSL/HTTP lookup.",
                        "default": 8000
                    },
                    "compact": {
                        "title": "📦 Compact Output",
                        "type": "boolean",
                        "description": "At-a-glance verdict only (domain, security score, email grade, flags) — drops the raw record blocks. Ideal for AI-agent / MCP workflows.",
                        "default": false
                    },
                    "excludeEmptyFields": {
                        "title": "Exclude empty fields from output",
                        "type": "boolean",
                        "description": "Drop null, empty-string, and empty-array fields from each record before push. Smaller payloads for AI agents and dashboards.",
                        "default": false
                    },
                    "incrementalMode": {
                        "title": "♻️ Incremental / drift monitoring",
                        "type": "boolean",
                        "description": "Compare each domain against the previous run and flag changes (NEW / UPDATED / UNCHANGED). Detects cert renewals, WHOIS expiry, DNS changes, email-auth drift and blacklist appearances over time. stateKey is optional — defaults to a stable key derived from the domain list + checks.",
                        "default": false
                    },
                    "stateKey": {
                        "title": "🔑 State Key",
                        "type": "string",
                        "description": "Optional. Stable identifier for the monitored domain set. Leave empty to auto-generate from the domain list + checks."
                    },
                    "emitUnchanged": {
                        "title": "🔁 Emit unchanged domains",
                        "type": "boolean",
                        "description": "When monitoring, also output domains whose signals did not change since the last run. Off = only NEW and UPDATED domains are emitted.",
                        "default": false
                    },
                    "telegramToken": {
                        "title": "🔑 Telegram Bot Token",
                        "type": "string",
                        "description": "Telegram bot token (from @BotFather). Required for Telegram notifications."
                    },
                    "telegramChatId": {
                        "title": "💬 Telegram Chat ID",
                        "type": "string",
                        "description": "Telegram chat or channel ID (e.g. \"-100123456789\"). Required when telegramToken is set."
                    },
                    "discordWebhookUrl": {
                        "title": "🎮 Discord Webhook URL",
                        "type": "string",
                        "description": "Discord incoming webhook URL. Server Settings → Integrations → Webhooks → New Webhook."
                    },
                    "slackWebhookUrl": {
                        "title": "💼 Slack Webhook URL",
                        "type": "string",
                        "description": "Slack incoming webhook URL. api.slack.com/messaging/webhooks."
                    },
                    "notificationLimit": {
                        "title": "📊 Max Domains Per Notification",
                        "minimum": 1,
                        "maximum": 20,
                        "type": "integer",
                        "description": "Maximum number of domains included in each notification message (1–20).",
                        "default": 5
                    },
                    "notifyOnlyChanges": {
                        "title": "🔄 Notify Only New/Updated",
                        "type": "boolean",
                        "description": "When monitoring is on, only send notifications for NEW and UPDATED domains. No effect otherwise.",
                        "default": false
                    },
                    "whatsappAccessToken": {
                        "title": "📱 WhatsApp Access Token",
                        "type": "string",
                        "description": "WhatsApp Cloud API permanent access token (System User token from Meta Business). Recipient must have messaged the business number within the last 24h (service-conversation window — free since Nov 2024)."
                    },
                    "whatsappPhoneNumberId": {
                        "title": "📞 WhatsApp Phone Number ID",
                        "type": "string",
                        "description": "Your WhatsApp Business phone-number ID (numeric, from Meta dashboard). Required when whatsappAccessToken is set."
                    },
                    "whatsappTo": {
                        "title": "📲 WhatsApp Recipient",
                        "type": "string",
                        "description": "Recipient phone in E.164 format without + (e.g. \"436641234567\"). Recipient must have messaged your business number within last 24h."
                    },
                    "webhookUrl": {
                        "title": "🪝 Generic Webhook URL",
                        "type": "string",
                        "description": "Receives a JSON POST with {metadata, items} after each run. Universal escape hatch for n8n / Make / Zapier / custom backends."
                    },
                    "webhookHeaders": {
                        "title": "📋 Webhook Headers",
                        "type": "object",
                        "description": "Optional JSON object of custom headers (e.g. {\"Authorization\":\"Bearer ...\"})."
                    },
                    "appConnector": {
                        "title": "Send results to a connected app",
                        "type": "string",
                        "description": "Optional. Pick a connected app under Settings → API & Integrations to receive your results. Best-effort across MCP connectors as Apify expands its catalog."
                    },
                    "mcpIssueTeam": {
                        "title": "Issue tracker team",
                        "type": "string",
                        "description": "Only when the connected app is an issue tracker: the team (name or ID) the summary issue is created under, if that app requires one."
                    }
                }
            },
            "runsResponseSchema": {
                "type": "object",
                "properties": {
                    "data": {
                        "type": "object",
                        "properties": {
                            "id": {
                                "type": "string"
                            },
                            "actId": {
                                "type": "string"
                            },
                            "userId": {
                                "type": "string"
                            },
                            "startedAt": {
                                "type": "string",
                                "format": "date-time",
                                "example": "2025-01-08T00:00:00.000Z"
                            },
                            "finishedAt": {
                                "type": "string",
                                "format": "date-time",
                                "example": "2025-01-08T00:00:00.000Z"
                            },
                            "status": {
                                "type": "string",
                                "example": "READY"
                            },
                            "meta": {
                                "type": "object",
                                "properties": {
                                    "origin": {
                                        "type": "string",
                                        "example": "API"
                                    },
                                    "userAgent": {
                                        "type": "string"
                                    }
                                }
                            },
                            "stats": {
                                "type": "object",
                                "properties": {
                                    "inputBodyLen": {
                                        "type": "integer",
                                        "example": 2000
                                    },
                                    "rebootCount": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "restartCount": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "resurrectCount": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "computeUnits": {
                                        "type": "integer",
                                        "example": 0
                                    }
                                }
                            },
                            "options": {
                                "type": "object",
                                "properties": {
                                    "build": {
                                        "type": "string",
                                        "example": "latest"
                                    },
                                    "timeoutSecs": {
                                        "type": "integer",
                                        "example": 300
                                    },
                                    "memoryMbytes": {
                                        "type": "integer",
                                        "example": 1024
                                    },
                                    "diskMbytes": {
                                        "type": "integer",
                                        "example": 2048
                                    }
                                }
                            },
                            "buildId": {
                                "type": "string"
                            },
                            "defaultKeyValueStoreId": {
                                "type": "string"
                            },
                            "defaultDatasetId": {
                                "type": "string"
                            },
                            "defaultRequestQueueId": {
                                "type": "string"
                            },
                            "buildNumber": {
                                "type": "string",
                                "example": "1.0.0"
                            },
                            "containerUrl": {
                                "type": "string"
                            },
                            "usage": {
                                "type": "object",
                                "properties": {
                                    "ACTOR_COMPUTE_UNITS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_WRITES": {
                                        "type": "integer",
                                        "example": 1
                                    },
                                    "KEY_VALUE_STORE_LISTS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_INTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_EXTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_RESIDENTIAL_TRANSFER_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_SERPS": {
                                        "type": "integer",
                                        "example": 0
                                    }
                                }
                            },
                            "usageTotalUsd": {
                                "type": "number",
                                "example": 0.00005
                            },
                            "usageUsd": {
                                "type": "object",
                                "properties": {
                                    "ACTOR_COMPUTE_UNITS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_WRITES": {
                                        "type": "number",
                                        "example": 0.00005
                                    },
                                    "KEY_VALUE_STORE_LISTS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_INTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_EXTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_RESIDENTIAL_TRANSFER_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_SERPS": {
                                        "type": "integer",
                                        "example": 0
                                    }
                                }
                            }
                        }
                    }
                }
            }
        }
    }
}
```
