CertGuard
Free SSL/TLS certificate checker: expiry, chain trust, hostname match, TLS version, A/B/C/F grade.
Should I use this
Quality & Safety
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"certguard": {
"url": "https://certguard.mike-tusa.workers.dev/mcp"
}
}
}Remote endpoints
https://certguard.mike-tusa.workers.dev/mcpstreamable-httpWhat it can do
Tool inventory
Tools (1)
🟢check_certificate(host, port, include_raw)
Run a live TLS handshake against host:port and audit the certificate the server presents. Returns an A/B/C/F grade and summary, expiry (days remaining), hostname match, chain completeness and trust against Mozilla's root store, negotiated TLS version and cipher suite, key type/size, findings, and a link to the full report. Revocation (OCSP/CRL) is NOT checked. Hosts on Cloudflare's own network cannot be checked live (result: isError with code live_check_unavailable, no grade); a failed handshake returns check_failed with no grade. Read-only: it only opens a TLS connection to the public host. Same engine, cache and limits as the CertGuard JSON API (GET /api/v1/check).
Input Schema
{
"type": "object",
"properties": {
"host": {
"type": "string",
"minLength": 1,
"maxLength": 300,
"description": "Hostname or public IP to check, e.g. example.com. An https:// URL is accepted and reduced to its host (and port). Private, internal and reserved addresses are rejected."
},
"port": {
"type": "integer",
"enum": [
443,
8443,
465,
993,
995
],
"default": 443,
"description": "TCP port (default 443). Allowed: 443, 8443, 465, 993, 995."
},
"include_raw": {
"type": "boolean",
"default": false,
"description": "Also return the full /api/v1/check JSON (all chain certificates, SANs, handshake attempts) in structuredContent.raw. Larger output."
}
},
"required": [
"host"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"properties": {
"host": {
"type": "string"
},
"port": {
"type": "integer"
},
"status": {
"type": "string",
"enum": [
"checked"
]
},
"grade": {
"type": "string",
"enum": [
"A",
"B",
"C",
"F"
]
},
"gradeEstimated": {
"type": "boolean",
"description": "true when the result was inferred from Certificate Transparency logs instead of a live handshake"
},
"summary": {
"type": "string"
},
"revocation_checked": {
"type": "boolean",
"description": "Always false: OCSP/CRL status is not queried"
},
"source": {
"type": "object",
"properties": {
"method": {
"type": "string",
"enum": [
"live_tls_handshake",
"certificate_transparency"
]
},
"live": {
"type": "boolean"
},
"ip": {
"type": "string"
}
}
},
"expiry": {
"type": "object",
"properties": {
"notBefore": {
"type": "string"
},
"notAfter": {
"type": "string"
},
"daysRemaining": {
"type": "integer"
},
"status": {
"type": "string",
"enum": [
"ok",
"warning",
"critical",
"expired",
"not_yet_valid"
]
}
}
},
"hostname": {
"type": "object",
"properties": {
"matches": {
"type": "boolean"
},
"matchedName": {
"type": "string"
},
"note": {
"type": "string"
}
}
},
"certificate": {
"type": "object",
"properties": {
"subject": {
"type": "string"
},
"issuer": {
"type": "string"
},
"issuerOrg": {
"type": "string"
},
"sans": {
"type": "array",
"items": {
"type": "string"
},
"description": "First 20 DNS names"
},
"sanCount": {
"type": "integer"
},
"key": {
"type": "string"
},
"signatureAlgorithm": {
"type": "string"
},
"validationType": {
"type": "string"
},
"sha256Fingerprint": {
"type": "string"
}
}
},
"tls": {
"type": "object",
"properties": {
"version": {
"type": "string"
},
"cipherSuite": {
"type": "string"
},
"keyExchangeGroup": {
"type": "string"
},
"ocspStapled": {
"type": "boolean"
}
}
},
"chain": {
"type": "object",
"properties": {
"presented": {
"type": "integer"
},
"complete": {
"type": "boolean"
},
"trusted": {
"type": "boolean"
},
"trustAnchor": {
"type": "string"
}
}
},
"issues": {
"type": "array",
"items": {
"type": "object",
"properties": {
"severity": {
"type": "string",
"enum": [
"critical",
"warning",
"info"
]
},
"code": {
"type": "string"
},
"message": {
"type": "string"
}
},
"required": [
"severity",
"code",
"message"
]
}
},
"notChecked": {
"type": "array",
"items": {
"type": "string"
}
},
"checkedAt": {
"type": "string"
},
"cached": {
"type": "boolean"
},
"plan": {
"type": "string",
"enum": [
"anonymous",
"key"
]
},
"reportUrl": {
"type": "string"
},
"apiUrl": {
"type": "string"
},
"version": {
"type": "string"
},
"raw": {
"type": "object",
"description": "Full /api/v1/check response (only when include_raw is true)"
}
},
"required": [
"host",
"port",
"status",
"grade",
"summary",
"revocation_checked",
"reportUrl"
]
}Community
Evidence