# TLS Certificate Auditor (`phoenix2810/tls-certificate-auditor`) Actor

Connect to a public host over TLS and audit its certificate posture: expiry and days remaining, hostname/SAN matching, chain completeness and trust, protocol, cipher, and key strength. Returns a score, grade, issues, and recommendations.

- **URL**: https://apify.com/phoenix2810/tls-certificate-auditor.md
- **Developed by:** [Sanskar Jaiswal](https://apify.com/phoenix2810) (community)
- **Categories:** Developer tools, SEO tools, Open source
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

Pay per usage

This Actor is paid per platform usage. The Actor is free to use, and you only pay for the Apify platform usage, which gets cheaper the higher subscription plan you have.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-usage

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## TLS Certificate Auditor

Connects to any public host over TLS and audits its certificate posture in one API call. Checks validity dates and days until expiry, hostname and Subject Alternative Name matching, chain completeness and trust status, negotiated protocol and cipher, and public key strength. Returns a readiness score, letter grade, issues, and recommendations as structured JSON.

### Use cases

- DevOps and platform teams monitoring certificate expiry across endpoints and catching renewals that silently fail
- Security teams auditing chain completeness, self-signed certificates, weak keys, and deprecated TLS protocol versions
- Site migration QA verifying that every endpoint serves the right certificate for its hostname after a cutover
- Agency consultants running recurring certificate posture checks across client domains
- CI pipelines gating deployments on certificate regressions

### Input

| Field | Type | Default | Description |
| --- | --- | --- | --- |
| startUrl | string | (required) | Public HTTPS URL or bare hostname to audit. The actor opens one TLS connection to this host on port 443 (or the URL port) and inspects the served certificate chain. |
| timeoutSeconds | integer | 10 | TLS connection timeout, from 3 to 30 seconds. |
| expiryWarningDays | integer | 30 | Flag the certificate as expiring soon when it expires within this many days. |

### Output

One dataset item per run:

| Field | Type | Description |
| --- | --- | --- |
| inputUrl | string | URL as provided in the input. |
| normalizedInputUrl | string or null | URL after scheme normalization and validation. |
| host | string | Hostname that was audited. |
| port | integer or null | TLS port used (443 or the URL port). |
| ok | boolean | Whether the audit completed without a connection or validation error. |
| checkedAt | string | ISO 8601 timestamp of the check. |
| connected | boolean | Whether the TLS connection was established. |
| authorized | boolean | Whether the served chain is trusted by standard root stores. |
| authorizationError | string or null | Node trust validation error, when the chain is not authorized. |
| subjectCommonName | string or null | Leaf certificate subject common name. |
| issuerCommonName | string or null | Leaf certificate issuer common name. |
| issuerOrganization | string or null | Leaf certificate issuer organization. |
| subjectAltNames | array | DNS Subject Alternative Names on the leaf certificate. |
| hostnameMatch | boolean | Whether the audited hostname matches the certificate SAN list or CN. |
| matchedCertificateName | string or null | The SAN or CN entry that matched. |
| validFrom | string or null | Certificate validity start, ISO 8601. |
| validTo | string or null | Certificate expiry, ISO 8601. |
| daysUntilExpiry | integer or null | Whole days from now until expiry (negative when expired). |
| expiryStatus | string | One of: valid, expiring-soon, expired, not-yet-valid, unknown. |
| expired | boolean | Whether the certificate is currently expired. |
| expiringSoon | boolean | Whether the certificate expires within the configured warning window. |
| fingerprint256 | string or null | SHA-256 fingerprint of the leaf certificate. |
| serialNumber | string or null | Leaf certificate serial number. |
| keyType | string or null | Public key type (RSA or EC). |
| keyBits | integer or null | Public key size in bits. |
| weakKey | boolean | Whether the public key is below the recommended strength for its type. |
| protocol | string or null | Negotiated TLS protocol version (for example TLSv1.3). |
| cipherName | string or null | Negotiated cipher suite. |
| cipherVersion | string or null | Cipher version reported by the TLS stack. |
| weakCipher | boolean | Whether the negotiated cipher is a legacy or weak suite (NULL, RC4, 3DES, CBC-only). |
| chainDepth | integer | Number of certificates in the served chain. |
| chainSubjects | array | CN or organization of each certificate in the chain. |
| hasSelfSignedRoot | boolean | Whether the served chain ends in a self-signed root certificate. |
| selfSignedLeaf | boolean | Whether the leaf certificate itself is self-signed. |
| chainLikelyIncomplete | boolean | Whether the chain appears to be missing intermediate certificates. |
| score | integer | Certificate posture score from 0 to 100. |
| grade | string | Letter grade from A+ to F. |
| issues | array | Concrete problems found. |
| recommendations | array | Actionable fixes. |
| error | string or null | Error message when the audit could not complete. |

### Example input

```json
{
    "startUrl": "https://www.wikipedia.org/",
    "timeoutSeconds": 10,
    "expiryWarningDays": 30
}
```

### Example output

```json
{
    "host": "www.wikipedia.org",
    "port": 443,
    "ok": true,
    "authorized": true,
    "subjectCommonName": "*.wikipedia.org",
    "issuerCommonName": "Sectigo RSA Domain Validation Secure Server CA",
    "subjectAltNames": ["*.wikipedia.org", "wikipedia.org"],
    "hostnameMatch": true,
    "matchedCertificateName": "*.wikipedia.org",
    "daysUntilExpiry": 200,
    "expiryStatus": "valid",
    "protocol": "TLSv1.3",
    "cipherName": "TLS_AES_256_GCM_SHA384",
    "keyType": "RSA",
    "keyBits": 2048,
    "weakKey": false,
    "weakCipher": false,
    "chainDepth": 3,
    "score": 100,
    "grade": "A+",
    "issues": [],
    "recommendations": [
        "Certificate posture looks good. Re-run daily or weekly to catch renewals that silently fail."
    ],
    "error": null
}
```

### Security

- Connects to public hosts only; URLs with credentials are rejected.
- Private IPv4, private IPv6, and loopback targets are blocked, hostnames are DNS-resolved, and resolutions to private ranges are rejected (SSRF defense).
- One TLS connection per run to the validated host; no HTTP page content is fetched, no cookies are stored, no JavaScript is executed.
- Trust validation is performed and reported (authorized flag and trust error); deliberately broken certificates remain inspectable so the audit can explain exactly what is wrong.

### Pricing

| Event | Price |
| --- | --- |
| Actor start | $0.005 per run |
| Host audited | $0.01 per result |

A typical single-host audit costs $0.015.

### FAQ

**Why would a certificate that browsers trust still fail the trust check?**
The actor validates the served chain against standard root stores the way a strict client does. If the server omits an intermediate certificate, some browsers can fill the gap from cached intermediates or built-in knowledge while strict clients cannot. The audit reports the incomplete chain so it can be fixed at the origin.

**Does the actor fetch the website content?**
No. It opens a TLS connection and inspects the handshake and served certificate chain only, then closes the connection.

**What counts as a weak key?**
RSA keys below 2048 bits and EC keys below 256 bits. Anything below the browser baseline (RSA 2048 or EC P-256) is flagged.

**How should I use the expiry warning window?**
Set expiryWarningDays to match how long a renewal takes in your workflow (issuance, validation, CDN propagation). The default of 30 days fits ACME-automated setups; manual workflows may want 60 or more.

# Actor input Schema

## `startUrl` (type: `string`):

Public HTTPS URL (or bare hostname) of the host to audit. The actor opens one TLS connection to this host and inspects the served certificate chain.

## `timeoutSeconds` (type: `integer`):

TLS connection timeout from 3 to 30 seconds.

## `expiryWarningDays` (type: `integer`):

Flag the certificate as expiring soon when it expires within this many days.

## Actor input object example

```json
{
  "startUrl": "https://example.com/",
  "timeoutSeconds": 10,
  "expiryWarningDays": 30
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "startUrl": "https://example.com/"
};

// Run the Actor and wait for it to finish
const run = await client.actor("phoenix2810/tls-certificate-auditor").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "startUrl": "https://example.com/" }

# Run the Actor and wait for it to finish
run = client.actor("phoenix2810/tls-certificate-auditor").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "startUrl": "https://example.com/"
}' |
apify call phoenix2810/tls-certificate-auditor --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,phoenix2810/tls-certificate-auditor"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/im0uO9rlIdwmBlMYe/builds/E7JzQE4tn4lTORAC6/openapi.json
