TLS Certificate Auditor
Pricing
Pay per usage
TLS Certificate Auditor
Connect to a public host over TLS and audit its certificate posture: expiry and days remaining, hostname/SAN matching, chain completeness and trust, protocol, cipher, and key strength. Returns a score, grade, issues, and recommendations.
Pricing
Pay per usage
Rating
0.0
(0)
Developer
Sanskar Jaiswal
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
3 days ago
Last modified
Categories
Share
Connects to any public host over TLS and audits its certificate posture in one API call. Checks validity dates and days until expiry, hostname and Subject Alternative Name matching, chain completeness and trust status, negotiated protocol and cipher, and public key strength. Returns a readiness score, letter grade, issues, and recommendations as structured JSON.
Use cases
- DevOps and platform teams monitoring certificate expiry across endpoints and catching renewals that silently fail
- Security teams auditing chain completeness, self-signed certificates, weak keys, and deprecated TLS protocol versions
- Site migration QA verifying that every endpoint serves the right certificate for its hostname after a cutover
- Agency consultants running recurring certificate posture checks across client domains
- CI pipelines gating deployments on certificate regressions
Input
| Field | Type | Default | Description |
|---|---|---|---|
| startUrl | string | (required) | Public HTTPS URL or bare hostname to audit. The actor opens one TLS connection to this host on port 443 (or the URL port) and inspects the served certificate chain. |
| timeoutSeconds | integer | 10 | TLS connection timeout, from 3 to 30 seconds. |
| expiryWarningDays | integer | 30 | Flag the certificate as expiring soon when it expires within this many days. |
Output
One dataset item per run:
| Field | Type | Description |
|---|---|---|
| inputUrl | string | URL as provided in the input. |
| normalizedInputUrl | string or null | URL after scheme normalization and validation. |
| host | string | Hostname that was audited. |
| port | integer or null | TLS port used (443 or the URL port). |
| ok | boolean | Whether the audit completed without a connection or validation error. |
| checkedAt | string | ISO 8601 timestamp of the check. |
| connected | boolean | Whether the TLS connection was established. |
| authorized | boolean | Whether the served chain is trusted by standard root stores. |
| authorizationError | string or null | Node trust validation error, when the chain is not authorized. |
| subjectCommonName | string or null | Leaf certificate subject common name. |
| issuerCommonName | string or null | Leaf certificate issuer common name. |
| issuerOrganization | string or null | Leaf certificate issuer organization. |
| subjectAltNames | array | DNS Subject Alternative Names on the leaf certificate. |
| hostnameMatch | boolean | Whether the audited hostname matches the certificate SAN list or CN. |
| matchedCertificateName | string or null | The SAN or CN entry that matched. |
| validFrom | string or null | Certificate validity start, ISO 8601. |
| validTo | string or null | Certificate expiry, ISO 8601. |
| daysUntilExpiry | integer or null | Whole days from now until expiry (negative when expired). |
| expiryStatus | string | One of: valid, expiring-soon, expired, not-yet-valid, unknown. |
| expired | boolean | Whether the certificate is currently expired. |
| expiringSoon | boolean | Whether the certificate expires within the configured warning window. |
| fingerprint256 | string or null | SHA-256 fingerprint of the leaf certificate. |
| serialNumber | string or null | Leaf certificate serial number. |
| keyType | string or null | Public key type (RSA or EC). |
| keyBits | integer or null | Public key size in bits. |
| weakKey | boolean | Whether the public key is below the recommended strength for its type. |
| protocol | string or null | Negotiated TLS protocol version (for example TLSv1.3). |
| cipherName | string or null | Negotiated cipher suite. |
| cipherVersion | string or null | Cipher version reported by the TLS stack. |
| weakCipher | boolean | Whether the negotiated cipher is a legacy or weak suite (NULL, RC4, 3DES, CBC-only). |
| chainDepth | integer | Number of certificates in the served chain. |
| chainSubjects | array | CN or organization of each certificate in the chain. |
| hasSelfSignedRoot | boolean | Whether the served chain ends in a self-signed root certificate. |
| selfSignedLeaf | boolean | Whether the leaf certificate itself is self-signed. |
| chainLikelyIncomplete | boolean | Whether the chain appears to be missing intermediate certificates. |
| score | integer | Certificate posture score from 0 to 100. |
| grade | string | Letter grade from A+ to F. |
| issues | array | Concrete problems found. |
| recommendations | array | Actionable fixes. |
| error | string or null | Error message when the audit could not complete. |
Example input
{"startUrl": "https://www.wikipedia.org/","timeoutSeconds": 10,"expiryWarningDays": 30}
Example output
{"host": "www.wikipedia.org","port": 443,"ok": true,"authorized": true,"subjectCommonName": "*.wikipedia.org","issuerCommonName": "Sectigo RSA Domain Validation Secure Server CA","subjectAltNames": ["*.wikipedia.org", "wikipedia.org"],"hostnameMatch": true,"matchedCertificateName": "*.wikipedia.org","daysUntilExpiry": 200,"expiryStatus": "valid","protocol": "TLSv1.3","cipherName": "TLS_AES_256_GCM_SHA384","keyType": "RSA","keyBits": 2048,"weakKey": false,"weakCipher": false,"chainDepth": 3,"score": 100,"grade": "A+","issues": [],"recommendations": ["Certificate posture looks good. Re-run daily or weekly to catch renewals that silently fail."],"error": null}
Security
- Connects to public hosts only; URLs with credentials are rejected.
- Private IPv4, private IPv6, and loopback targets are blocked, hostnames are DNS-resolved, and resolutions to private ranges are rejected (SSRF defense).
- One TLS connection per run to the validated host; no HTTP page content is fetched, no cookies are stored, no JavaScript is executed.
- Trust validation is performed and reported (authorized flag and trust error); deliberately broken certificates remain inspectable so the audit can explain exactly what is wrong.
Pricing
| Event | Price |
|---|---|
| Actor start | $0.005 per run |
| Host audited | $0.01 per result |
A typical single-host audit costs $0.015.
FAQ
Why would a certificate that browsers trust still fail the trust check? The actor validates the served chain against standard root stores the way a strict client does. If the server omits an intermediate certificate, some browsers can fill the gap from cached intermediates or built-in knowledge while strict clients cannot. The audit reports the incomplete chain so it can be fixed at the origin.
Does the actor fetch the website content? No. It opens a TLS connection and inspects the handshake and served certificate chain only, then closes the connection.
What counts as a weak key? RSA keys below 2048 bits and EC keys below 256 bits. Anything below the browser baseline (RSA 2048 or EC P-256) is flagged.
How should I use the expiry warning window? Set expiryWarningDays to match how long a renewal takes in your workflow (issuance, validation, CDN propagation). The default of 30 days fits ACME-automated setups; manual workflows may want 60 or more.