Security & Trust · DomScan product

SSL Certificates API

Get SSL certificate information including issuer, validity, and security grade.

What you get

Get SSL certificate information including issuer, validity, and security grade.

SynchronousBulkRESTMCPSDKInteractive tool

Choose this product when

Who it is for

Use bounded passive checks to enrich triage and investigation, not to replace authorized testing or human review.

Choose this product when

Choose this to inspect public TLS certificate evidence, validity, names, and chain-related signals where available.

What you get

Get SSL certificate information including issuer, validity, and security grade.

Endpoints

Review the supported operations, inputs, outputs, execution modes, and response limits before integrating.

GET /v1/certificates View API reference
POST /v1/certificates/bulk View API reference
GET /v1/ssl/audit View API reference
GET /v1/ssl/deep-scan View API reference
GET /v1/ssl/grade View API reference
GET /v1/ssl/chain View API reference
GET /v1/ssl/expiring View API reference

Credits and authentication

1-10 Authentication required. Check the operation reference for the exact cost and any per-item pricing.

Example operation

Use documented operations to collect, assess, enrich, verify, compare, protect, or monitor public evidence.

GET /v1/certificates

Query Parameters

Parameter Type required
domain string required
include_subdomains boolean
Default true
optional
include_expired boolean
Default false
optional
limit integer
Default 100
optional
cursor string optional

Response Fields

Field Type
domain string
certificates[] object[]
certificates[] object
certificates[].id string
certificates[].issuer object
certificates[].common_name string
certificates[].san[] string[]
certificates[].not_before string
certificates[].not_after string
certificates[].is_expired boolean
certificates[].is_wildcard boolean
certificates[].fingerprint_sha256 string
summary object
summary.total_found integer
summary.returned integer
summary.unique_subdomains integer
summary.issuers[] string[]
summary.earliest_cert string | null
summary.latest_cert string | null
pagination object
pagination.limit integer
pagination.offset integer
pagination.returned integer
pagination.total integer
pagination.has_more boolean
pagination.next_cursor string | null
intelligence_summary object
intelligence_summary.data_source string
intelligence_summary.ct_log_sources[] string[]
intelligence_summary.source_count integer
intelligence_summary.cache_status string
intelligence_summary.returned_count integer
intelligence_summary.total_found integer
intelligence_summary.truncated boolean
intelligence_summary.limit integer
intelligence_summary.include_subdomains boolean
intelligence_summary.include_expired boolean
intelligence_summary.unique_name_count integer
intelligence_summary.unique_subdomains integer
intelligence_summary.issuer_count integer
intelligence_summary.wildcard_cert_count integer
intelligence_summary.active_cert_count integer
intelligence_summary.expired_cert_count integer
intelligence_summary.expiring_within_30_days_count integer
intelligence_summary.earliest_cert string | null
intelligence_summary.latest_cert string | null
intelligence_summary.latest_expiry string | null
intelligence_summary.has_more boolean
intelligence_summary.next_cursor string | null
intelligence_summary.warning_code string | null
meta object

Example Request

curl -H "X-API-Key: $DOMSCAN_API_KEY" "https://domscan.net/v1/certificates?domain=example.com&include_subdomains=true&include_expired=false&limit=25&cursor=100"

Example Response

{
  "domain": "example.com",
  "certificates": [
    {
      "id": "example-id",
      "issuer": {},
      "common_name": "example",
      "san": [
        "example"
      ],
      "not_before": "2026-08-27T12:00:00Z",
      "not_after": "2026-08-27T12:00:00Z",
      "is_expired": false,
      "is_wildcard": false,
      "fingerprint_sha256": "example"
    }
  ],
  "summary": {
    "total_found": 1,
    "returned": 1,
    "unique_subdomains": 1,
    "issuers": [
      "example"
    ],
    "earliest_cert": "example",
    "latest_cert": "example"
  },
  "pagination": {
    "limit": 1,
    "offset": 1,
    "returned": 1,
    "total": 1,
    "has_more": false,
    "next_cursor": "example"
  },
  "intelligence_summary": {
    "data_source": "public_data",
    "ct_log_sources": [
      "example"
    ],
    "source_count": 1,
    "cache_status": "live",
    "returned_count": 1,
    "total_found": 1,
    "truncated": false,
    "limit": 1,
    "include_subdomains": false,
    "include_expired": false,
    "unique_name_count": 1,
    "unique_subdomains": 1,
    "issuer_count": 1,
    "wildcard_cert_count": 1,
    "active_cert_count": 1,
    "expired_cert_count": 1,
    "expiring_within_30_days_count": 1,
    "earliest_cert": "example",
    "latest_cert": "example",
    "latest_expiry": "example",
    "has_more": false,
    "next_cursor": "example",
    "warning_code": "example"
  },
  "meta": {}
}

Limits and evidence boundaries

Results describe observed public evidence and its provenance.
Coverage is bounded by the documented inputs, budgets, sources, and response limits.
Bulk operations process multiple supported inputs while preserving documented item-level outcomes.
Unknown means the requested fact could not be determined from the available evidence.
Evidence can change over time; use timestamps and freshness fields when provided.

Reviewed 2026-08-22

Frequently asked questions

Where can I find the SSL Certificates request and response reference?

Use the API reference for SSL Certificates to review parameters, response fields, examples, status codes, and supported operation modes.

How should I interpret unknown or incomplete results from SSL Certificates?

Unknown or partial results mean that the requested evidence could not be fully determined. Keep the result state, confidence, freshness, and limitations in downstream decisions.

How is SSL Certificates priced?

Pricing depends on the operation and execution mode. Check the endpoint reference for the current credit cost, authentication requirement, and per-item rules.

Used by people at amazing companies

InstantOutseerMongoDBRespondentSage Expense ManagementInstantlyD.R. HortonWhatConvertsAdobeMotionElementsLLM Pulse