CertGuard

Free SSL/TLS certificate checker: expiry, chain trust, hostname match, TLS version, A/B/C/F grade.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
100%
Naming quality
100%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~905Tokens (tool definitions)
~8.9 KBTypical response size
Moderate attention impact (0.71% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "certguard": {
      "url": "https://certguard.mike-tusa.workers.dev/mcp"
    }
  }
}

Remote endpoints

https://certguard.mike-tusa.workers.dev/mcpstreamable-http

What it can do

Tool inventory

Tools (1)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢check_certificate(host, port, include_raw)

Run a live TLS handshake against host:port and audit the certificate the server presents. Returns an A/B/C/F grade and summary, expiry (days remaining), hostname match, chain completeness and trust against Mozilla's root store, negotiated TLS version and cipher suite, key type/size, findings, and a link to the full report. Revocation (OCSP/CRL) is NOT checked. Hosts on Cloudflare's own network cannot be checked live (result: isError with code live_check_unavailable, no grade); a failed handshake returns check_failed with no grade. Read-only: it only opens a TLS connection to the public host. Same engine, cache and limits as the CertGuard JSON API (GET /api/v1/check).

Input Schema

{
  "type": "object",
  "properties": {
    "host": {
      "type": "string",
      "minLength": 1,
      "maxLength": 300,
      "description": "Hostname or public IP to check, e.g. example.com. An https:// URL is accepted and reduced to its host (and port). Private, internal and reserved addresses are rejected."
    },
    "port": {
      "type": "integer",
      "enum": [
        443,
        8443,
        465,
        993,
        995
      ],
      "default": 443,
      "description": "TCP port (default 443). Allowed: 443, 8443, 465, 993, 995."
    },
    "include_raw": {
      "type": "boolean",
      "default": false,
      "description": "Also return the full /api/v1/check JSON (all chain certificates, SANs, handshake attempts) in structuredContent.raw. Larger output."
    }
  },
  "required": [
    "host"
  ],
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "properties": {
    "host": {
      "type": "string"
    },
    "port": {
      "type": "integer"
    },
    "status": {
      "type": "string",
      "enum": [
        "checked"
      ]
    },
    "grade": {
      "type": "string",
      "enum": [
        "A",
        "B",
        "C",
        "F"
      ]
    },
    "gradeEstimated": {
      "type": "boolean",
      "description": "true when the result was inferred from Certificate Transparency logs instead of a live handshake"
    },
    "summary": {
      "type": "string"
    },
    "revocation_checked": {
      "type": "boolean",
      "description": "Always false: OCSP/CRL status is not queried"
    },
    "source": {
      "type": "object",
      "properties": {
        "method": {
          "type": "string",
          "enum": [
            "live_tls_handshake",
            "certificate_transparency"
          ]
        },
        "live": {
          "type": "boolean"
        },
        "ip": {
          "type": "string"
        }
      }
    },
    "expiry": {
      "type": "object",
      "properties": {
        "notBefore": {
          "type": "string"
        },
        "notAfter": {
          "type": "string"
        },
        "daysRemaining": {
          "type": "integer"
        },
        "status": {
          "type": "string",
          "enum": [
            "ok",
            "warning",
            "critical",
            "expired",
            "not_yet_valid"
          ]
        }
      }
    },
    "hostname": {
      "type": "object",
      "properties": {
        "matches": {
          "type": "boolean"
        },
        "matchedName": {
          "type": "string"
        },
        "note": {
          "type": "string"
        }
      }
    },
    "certificate": {
      "type": "object",
      "properties": {
        "subject": {
          "type": "string"
        },
        "issuer": {
          "type": "string"
        },
        "issuerOrg": {
          "type": "string"
        },
        "sans": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "First 20 DNS names"
        },
        "sanCount": {
          "type": "integer"
        },
        "key": {
          "type": "string"
        },
        "signatureAlgorithm": {
          "type": "string"
        },
        "validationType": {
          "type": "string"
        },
        "sha256Fingerprint": {
          "type": "string"
        }
      }
    },
    "tls": {
      "type": "object",
      "properties": {
        "version": {
          "type": "string"
        },
        "cipherSuite": {
          "type": "string"
        },
        "keyExchangeGroup": {
          "type": "string"
        },
        "ocspStapled": {
          "type": "boolean"
        }
      }
    },
    "chain": {
      "type": "object",
      "properties": {
        "presented": {
          "type": "integer"
        },
        "complete": {
          "type": "boolean"
        },
        "trusted": {
          "type": "boolean"
        },
        "trustAnchor": {
          "type": "string"
        }
      }
    },
    "issues": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string",
            "enum": [
              "critical",
              "warning",
              "info"
            ]
          },
          "code": {
            "type": "string"
          },
          "message": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "code",
          "message"
        ]
      }
    },
    "notChecked": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "checkedAt": {
      "type": "string"
    },
    "cached": {
      "type": "boolean"
    },
    "plan": {
      "type": "string",
      "enum": [
        "anonymous",
        "key"
      ]
    },
    "reportUrl": {
      "type": "string"
    },
    "apiUrl": {
      "type": "string"
    },
    "version": {
      "type": "string"
    },
    "raw": {
      "type": "object",
      "description": "Full /api/v1/check response (only when include_raw is true)"
    }
  },
  "required": [
    "host",
    "port",
    "status",
    "grade",
    "summary",
    "revocation_checked",
    "reportUrl"
  ]
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded1 tools