# Bulk URL Status & SSL Checker: Redirects & Expiry (`tiktop/url-status-ssl-checker`) Actor

Check thousands of URLs at once: final HTTP status, full redirect chain, response time, HTTPS, security headers, and SSL certificate issuer, expiry date and days left. Find broken links, bad redirects and expiring certificates.

- **URL**: https://apify.com/tiktop/url-status-ssl-checker.md
- **Developed by:** [Khaled](https://apify.com/tiktop) (community)
- **Categories:** SEO tools, Developer tools
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $0.75 / 1,000 url checkeds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.
Since this Actor supports Apify Store discounts, the price gets lower the higher subscription plan you have.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

Check thousands of URLs in one run. For each one you get the **final HTTP status**, the full **redirect chain**, **response time**, whether it ends on **HTTPS**, the **server**, which **security headers** are present or missing, and the **SSL certificate**: issuer, expiry date, **days left**, and whether it's trusted.

**Price: $1.00 per 1,000 URLs checked.** URLs that can't be reached at all (DNS failure, timeout) are free. A 404, a 500 or an expired certificate is a result, so it's counted. Apify's free plan ($5 monthly credit) covers about 5,000 URLs a month.

[![Bulk URL Status & SSL Checker output: final status, redirects, response time, SSL days left and missing security headers per URL](https://raw.githubusercontent.com/TikTop-Data/apify-store-assets/main/images/url-status-ssl-checker-output.png)](https://console.apify.com/actors/lh5S5AARb7zderOdc)

### Questions it answers

- Which of these links are broken (404/410/500) or redirect somewhere unexpected?
- Which of our domains have SSL certificates expiring in the next 30 days, or already expired?
- Do old URLs 301-redirect to the right new pages after a migration?
- Which sites are missing HSTS or a Content-Security-Policy header?
- How fast does each page respond?

### Who uses this

- 🔍 **SEO teams:** check redirect chains and dead links after a site migration or in backlink lists.
- 🔐 **IT and DevOps:** monitor certificate expiry across many domains on a schedule.
- 🛡️ **Security reviews:** spot missing security headers across a portfolio of sites.
- 🧹 **Data cleaning:** validate URL columns in lead lists before outreach or enrichment.

### How to use the Bulk URL Status & SSL Checker

1. Click **Try for free** (a free Apify account is enough).
2. Paste URLs or bare domains, one per line.
3. Click **Start**. Hundreds of URLs take about a minute.
4. Sort by `finalStatus` or `sslDaysLeft`, then download as JSON, CSV or Excel. Put it on a schedule with a change alert name to hear about expiring certificates and new errors.

### Input

| Field | Default | What it does |
|---|---|---|
| `urls` | – | URLs or bare domains, one per line. |
| `maxConcurrency` | 20 | URLs checked in parallel. |
| `requestTimeoutSecs` | 30 | Give up on a URL after this long. |

Example (the input behind the table above):

```json
{ "urls": ["http://github.com", "apify.com", "http://wikipedia.org", "https://github.com/this-page-does-not-exist", "https://expired.badssl.com", "stripe.com"] }
```

### Output

One row per URL. The real row for `http://github.com` from that run, shortened:

```json
{
  "inputUrl": "http://github.com",
  "url": "https://github.com/",
  "domain": "github.com",
  "httpStatus": 200,
  "finalStatus": 200,
  "redirects": 1,
  "redirectChain": [{"url": "http://github.com/", "status": 301}, {"url": "https://github.com/", "status": 200}],
  "responseTimeMs": 157,
  "https": true,
  "server": "github.com",
  "securityHeadersPresent": [
    "strict-transport-security",
    "content-security-policy",
    "x-frame-options",
    "x-content-type-options",
    "..."
  ],
  "securityHeadersMissing": ["permissions-policy"],
  "sslValid": true,
  "sslError": null,
  "sslIssuer": "Sectigo Limited",
  "sslSubject": "github.com",
  "sslValidFrom": "2026-09-01T00:00:00.000Z",
  "sslValidTo": "2026-11-29T23:59:59.000Z",
  "sslDaysLeft": 54,
  "sslAltNames": ["github.com", "www.github.com"],
  "tlsProtocol": "TLSv1.3",
  "error": null,
  "checkedAt": "2026-10-06T11:45:28.597Z"
}
```

A site whose certificate a browser would reject (expired, self-signed, wrong host) still gets a full row: `sslValid: false`, the reason in `sslError` (e.g. `CERT_HAS_EXPIRED`), the expiry date and negative `sslDaysLeft`. The HTTP status stays empty, because the page isn't loaded over an untrusted connection.

### Example tasks

Ready-made inputs you can open and run:

- [SSL certificate expiry checker for many domains](https://apify.com/tiktop/url-status-ssl-checker/examples/ssl-certificate-expiry-checker)
- [Bulk broken link and HTTP status checker](https://apify.com/tiktop/url-status-ssl-checker/examples/broken-link-status-checker)
- [Redirect chain checker (301/302) in bulk](https://apify.com/tiktop/url-status-ssl-checker/examples/redirect-chain-checker)
- [Security headers checker (HSTS, CSP, X-Frame-Options)](https://apify.com/tiktop/url-status-ssl-checker/examples/security-headers-checker)
- [Check that HTTP redirects to HTTPS](https://apify.com/tiktop/url-status-ssl-checker/examples/http-to-https-redirect-checker)
- [SSL certificate and redirect change monitor](https://apify.com/tiktop/url-status-ssl-checker/examples/ssl-and-redirect-change-monitor)

### Check websites from another Actor (Google Maps leads, lead lists)

Have a list from Google Maps Scraper or any other Actor? Pick its dataset under **Websites from another Actor**. This Actor reads the `website` field (or the field you name, e.g. `url`, `domain` or `contact.website`) and checks every site. No copy and paste.

To run it automatically after every scrape, add an Actor-to-Actor integration to the source Actor or task with this input:

```json
{ "datasetId": "{{resource.defaultDatasetId}}", "datasetUrlField": "website" }
```

### Change alerts

Give the run a **Change alert name** (e.g. `clients-weekly`) and put it on an Apify schedule. Each row then gets `changeStatus` (`new`, `changed` or `unchanged`) and `changedFields`, compared with the previous run of the same name, so you see when a status code, redirect chain, certificate or security header changes. Turn on **Only new and changed sites** and each run's dataset is just the change report; unchanged sites are still checked and charged as usual. Add Apify's Slack or email integration to get the report delivered.

### Notes

- Up to 10 redirects are followed. The status is what the server returns to a normal browser request; some sites answer bots differently.
- Certificate data comes from a standard TLS handshake with the final host.

### How much does it cost?

- **URL checked:** $0.001 per URL that answers ($1.00 per 1,000), including 4xx/5xx and certificate errors.
- **Actor start:** $0.00005 per GB of memory (default 1 GB = $0.00005 per run).
- URLs that can't be reached at all (DNS failure, timeout): free.

| URLs | Cost |
|---|---|
| 100 | about $0.10 |
| 1,000 | about $1 |
| 10,000 | about $10 |

Apify's free plan includes $5 of credit every month, enough for about 5,000 URLs. Paid Apify plans get Store discounts of up to 25%. You can set a maximum cost per run; the Actor stops cleanly when it's reached.

### FAQ

**Is this legal?** It makes one normal request to each URL you list and reads the public certificate, like a browser does. No personal data is collected.

**Why is a URL I know works marked 403?** Some sites block automated visitors. The status shown is what the server returned to this check.

**Can I check certificates every day?** Yes. Schedule it with a change alert name, and the `sslDaysLeft` column tells you how long each certificate has left.

### Related Actors

- [SEO Meta Tag & Schema Checker](https://apify.com/tiktop/seo-meta-checker): titles, meta tags and schema for the same pages.
- [Website Tech Stack Detector](https://apify.com/tiktop/tech-stack-detector): what a site is built with.

# Actor input Schema

## `urls` (type: `array`):

URLs or bare domains, one per line. Or use "Websites from another Actor" below.

## `datasetId` (type: `string`):

Check the websites in another Actor run's results, e.g. Google Maps Scraper or any lead list. Pick the dataset here, or in an Actor-to-Actor integration set it to {{resource.defaultDatasetId}}. Its websites are added to the list above.

## `datasetUrlField` (type: `string`):

The dataset field that holds the website or URL, e.g. website (Google Maps Scraper), url or domain. Dot paths like contact.website work. If it is empty, website, url and domain are tried.

## `maxDatasetItems` (type: `integer`):

Read at most this many rows from that dataset.

## `monitorName` (type: `string`):

Name this list (e.g. "clients-weekly") to compare each run with the previous run of the same name. Every row then gets changeStatus (new, changed or unchanged) and changedFields. Best on an Apify schedule.

## `onlyChanges` (type: `boolean`):

Needs a change alert name. Unchanged sites are still checked and charged as usual, but left out of the results, so each run's dataset is your change report.

## `maxConcurrency` (type: `integer`):

How many sites to check at once.

## `requestTimeoutSecs` (type: `integer`):

Give up on a site after this long.

## Actor input object example

```json
{
  "urls": [
    "http://github.com",
    "https://apify.com",
    "https://httpbin.org/status/404"
  ],
  "datasetUrlField": "website",
  "maxDatasetItems": 10000,
  "onlyChanges": false,
  "maxConcurrency": 20,
  "requestTimeoutSecs": 30
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "urls": [
        "http://github.com",
        "https://apify.com",
        "https://httpbin.org/status/404"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("tiktop/url-status-ssl-checker").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "urls": [
        "http://github.com",
        "https://apify.com",
        "https://httpbin.org/status/404",
    ] }

# Run the Actor and wait for it to finish
run = client.actor("tiktop/url-status-ssl-checker").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "urls": [
    "http://github.com",
    "https://apify.com",
    "https://httpbin.org/status/404"
  ]
}' |
apify call tiktop/url-status-ssl-checker --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,tiktop/url-status-ssl-checker"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/lh5S5AARb7zderOdc/builds/6S1XG4o99uguFQsaP/openapi.json
