Certificate transparency search

$0.005 per call · USDC via x402 · POST /api/cert-transparency

Search public Certificate Transparency logs for every cert issued to a domain. Send POST /api/cert-transparency with the required field domain and pay $0.005 per call over x402 or MPP (there is no free tier). It returns a JSON object with domain, count, truncated, subdomains, certs and 2 more.

Two independent public CT search services are queried, the second only if the first is slow or fails, and `source` names the one that answered (their coverage windows differ). Returns the cert list plus a deduped subdomain set extracted from the SANs - the fastest way to enumerate subdomains for a security audit. No key required.

Category: Network & domains · Tags: security ssl tls certificates subdomain-discovery audit · Also found as: certificate-transparency-search certificate-transparency

TRY IN PLAYGROUND →

Parameters

NameTypeRequiredDescription
domainstringyesDomain to search (also accepts host/hostname/url/email) Also accepted as host, hostname, site.
includeExpiredbooleannoInclude expired certs (default false)
limitintegernoMax certs to return (1–500, default 50)

Example request

curl -i -X POST https://agent402.tools/api/cert-transparency \
  -H "Content-Type: application/json" \
  -d '{"domain":"agent402.tools"}'

Without payment this returns HTTP 402 Payment Required with the exact price for cert-transparency; any x402 v2 or MPP client pays it and retries.

Example response

{
  "domain": "agent402.tools",
  "count": 2,
  "truncated": false,
  "subdomains": [
    "agent402.tools"
  ],
  "certs": [
    {
      "id": 1234567890,
      "serial": "0a:1b:2c",
      "issuer": "C=US, O=Let's Encrypt, CN=E5",
      "commonName": "agent402.tools",
      "sans": [
        "agent402.tools"
      ],
      "notBefore": "2026-01-15T00:00:00",
      "notAfter": "2027-02-14T23:59:59"
    }
  ],
  "source": "crt.sh",
  "queriedAt": "2026-06-19T22:00:00.000Z"
}
FieldTypeAlways presentIn the example
domainstringyesagent402.tools
countnumberyes2
truncatedbooleanyesfalse
subdomainsarray of stringyes1 item in the example
certsarray of objectsyes1 item in the example
sourcestringyescrt.sh
queriedAtstringyes2026-06-19T22:00:00.000Z

From an MCP client

catalog.call {
  "slug": "cert-transparency",
  "params": {
    "domain": "agent402.tools"
  }
}

The hosted connector at https://agent402.tools/mcp needs a payment for cert-transparency; the stdio package pays it from a wallet or from AGENT402_CREDITS_KEY. Local install: npx -y agent402-mcp.

Errors and behavior

Paid call (JavaScript agent)

import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);

const res = await payFetch("https://agent402.tools/api/cert-transparency", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({
    "domain": "agent402.tools"
  }),
});

Part of these workflows

Certificate transparency search is one step in these 2 skill packs, each sold as a single call:

Related tools

TLS certificate

$0.001 · POST /api/tls-cert

Inspect the TLS certificate of any public host: subject, issuer, validity window, days remaining, SANs, and SHA-256 fing…

HTTP headers + security analysis

$0.003 · POST /api/http-headers

Fetch a URL and return every response header plus a security analysis: HSTS, CSP, X-Frame-Options, X-Content-Type-Option…

Tech stack detection

$0.005 · POST /api/tech-stack

Detect the technology stack of a public website: CDN, web server, language/runtime, frontend framework (Next.js, Nuxt, S…

Domain security & deliverability audit (graded)

$0.60 · POST /v1/domain-audit

Hand over a domain and get one graded security & email-deliverability audit: SPF, DMARC, DKIM and MX (why your mail land…

Domain security audit - PRO (attack surface + stack)

$0.85 · POST /v1/domain-audit/pro

The deeper tier: everything in the standard audit plus the attack surface from Certificate Transparency logs (subdomains…

x402 security audit

$0.01 · GET /api/x402-audit

Grade any x402 seller's payment-security posture from the outside - a read-only black-box check mapped to the 'Five Atta…