# TLS Certificate Expiry Checker | HTTPS Renewal Audit (`sbio-apps/tls-certificate-expiry-checker`) Actor

Check verified HTTPS certificates for supplied hosts and export expiry dates, days remaining, issuer, subject, SHA-256 fingerprint and negotiated TLS version. Flag certificates within your renewal window for scheduled domain maintenance.

- **URL**: https://apify.com/sbio-apps/tls-certificate-expiry-checker.md
- **Developed by:** [Austin Aryain](https://apify.com/sbio-apps) (community)
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

$5.00 / 1,000 completed checks

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

### TLS Certificate Expiry Checker | HTTPS Renewal Audit

Check verified HTTPS certificates for supplied hosts and export expiry dates, days remaining, issuer, subject, SHA-256 fingerprint and negotiated TLS version. Flag certificates within your renewal window for scheduled domain maintenance.

### How it works

Provide HTTPS URLs for domains you maintain. The Actor connects to each supplied origin on port 443, requests its root with HEAD, validates the certificate using Node normal trust and hostname checks, and returns the leaf certificate metadata. Set warningDays between 1 and 365; the default is 30. Run it on a schedule and route expiryWarning=true records into your own maintenance workflow. Paths are ignored and redirects are not followed, so the reported certificate belongs to the requested host rather than a redirect destination.

### Quick start

1. Enter one or more public URLs in the Input tab, beginning with the supplied example.
2. Set a maximum run charge. A completed check costs $0.005; checking 10 sources once costs $0.05.
3. Start the Actor and inspect the dataset. Download JSON, CSV or Excel, or consume results through the Apify API.
4. Inspect the OUTPUT run summary as well as the dataset: failed or unprocessed inputs appear there. Save the input as a task if you want to schedule future runs.

### Pricing

**$0.005 per completed check ($5 per 1,000), with platform usage included.** There are no separate Actor-start or dataset-item fees. Empty and unchanged successful checks are charged. The maximum charge is checked before each source request and again before output. Failed network or format checks are free; see the specific HTTP-response cases below. Billing is per completed source check, not per nested array item, extracted URL, change or schema block.

### Limits and interpretation

Only certificates that pass normal TLS validation and return an HTTP response produce charged records. Expired, untrusted, hostname-mismatched certificates and handshake/network failures are free errors in OUTPUT, and must also be handled by your monitoring workflow. This cannot inspect the dates of an already-invalid certificate. It reports one observed edge certificate, not every address or certificate chain, revocation status, a cipher-suite scan or a guarantee of future availability. A completed certificate check is charged regardless of the HTTP status returned after the valid handshake.

A run accepts 1-50 unique input URLs and requests them sequentially. Each check has an 18-second network deadline; new checks stop after 160 seconds. Use a 240-second run timeout and 512 MB memory. If the time or charge limit stops a batch, OUTPUT lists uncheckedUrls for a later run. No response exceeding the configured byte limit is accepted, and a complete record must fit within 6 MB. The Actor permits only public HTTP(S) destinations on standard ports, pins a validated DNS address per request, and refuses redirects into private networks or from HTTPS to HTTP.

The Actor uses direct HTTP requests, without a browser, residential proxy, login, CAPTCHA solving or access-control bypass. Rate limits and blocks may prevent checks. Avoid secret-bearing URLs. Results describe the source and network observed at check time.

### Integrations and support

Connect the dataset and OUTPUT summary to your own n8n, Make, Zapier or API workflow. This Actor produces data; it does not automatically send email, Slack messages or webhooks to third parties. No external account credentials are needed for the supplied public examples. Report reproducible issues in the Actor Issues tab, including a non-sensitive input and run link. This is an independent utility and is not endorsed by the websites, standards bodies or services it reads.

### Input example

```json
{
  "urls": [
    "https://example.com/"
  ],
  "warningDays": 30
}
```

See the Input tab for all supported fields. Results are available through the dataset API and can be downloaded as JSON, CSV or Excel.

### Output fields

| Field | Meaning |
|---|---|
| inputUrl | Normalized supplied URL. |
| checkedAt | Check time in ISO format. |
| hostname | Supplied HTTPS hostname. |
| checkedUrl | Origin root used for the HEAD request; redirects are not followed. |
| httpStatus | Observed response status. |
| subject | Certificate subject. |
| issuer | Certificate issuer. |
| validFrom | Not-before date in ISO format. |
| validTo | Not-after date in ISO format. |
| fingerprint256 | SHA-256 leaf certificate fingerprint. |
| subjectAltName | Certificate alternative names. |
| protocol | Negotiated TLS protocol. |
| verified | True: normal Node trust and hostname validation succeeded. |
| daysRemaining | Whole days remaining, rounded down. |
| warningDays | Configured renewal warning threshold. |
| expiryWarning | True when daysRemaining is at or below warningDays. |

### Output example

Example from a public source check; live values vary. Long items, changes, groups and blocks arrays are shortened to two entries here for readability; the actual record contains the complete arrays within the documented limits.

```json
{
  "inputUrl": "https://example.com/",
  "checkedAt": "2026-09-07T21:05:12.949Z",
  "hostname": "example.com",
  "checkedUrl": "https://example.com/",
  "httpStatus": 200,
  "subject": {
    "CN": "example.com"
  },
  "issuer": {
    "C": "US",
    "O": "SSL Corporation",
    "CN": "Cloudflare TLS Issuing ECC CA 3"
  },
  "validFrom": "2026-07-29T22:10:08.000Z",
  "validTo": "2026-10-27T22:17:21.000Z",
  "fingerprint256": "61:53:A9:6F:D1:A6:AB:7F:4D:43:8F:C3:49:32:48:42:99:D0:72:9D:91:40:B3:A1:26:BB:2F:9C:07:B0:22:00",
  "subjectAltName": "DNS:example.com, DNS:*.example.com",
  "protocol": "TLSv1.3",
  "verified": true,
  "daysRemaining": 50,
  "warningDays": 30,
  "expiryWarning": false
}
```

# Actor input Schema

## `urls` (type: `array`):

1-50 explicit public URLs on standard ports. Exact duplicate input URLs are checked once.

## `warningDays` (type: `integer`):

Flag certificates with this many whole days remaining or fewer.

## Actor input object example

```json
{
  "urls": [
    "https://example.com/"
  ],
  "warningDays": 30
}
```

# Actor output Schema

## `checks` (type: `string`):

Priced dataset records, including observed unchanged checks or HTTP audit errors as documented.

## `summary` (type: `string`):

Free errors, spending/time stops and unprocessed inputs.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "urls": [
        "https://example.com/"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("sbio-apps/tls-certificate-expiry-checker").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "urls": ["https://example.com/"] }

# Run the Actor and wait for it to finish
run = client.actor("sbio-apps/tls-certificate-expiry-checker").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "urls": [
    "https://example.com/"
  ]
}' |
apify call sbio-apps/tls-certificate-expiry-checker --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,sbio-apps/tls-certificate-expiry-checker"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/pgTLR0e8iOjVGGO6g/builds/AgOfqno1smNmVYjj0/openapi.json
