Check a certificate by hostname (live connection on port 443 only, up to 20 checks/hour per visitor) or by pasting a PEM certificate directly (no network call). Shows expiry, issuer, fingerprint, OCSP/CRL URLs, and subject alternative names either way.
curl -sS "https://devops.majbase.com/certificate-expiry/api?domain=example.com"
curl -sS -X POST https://devops.majbase.com/certificate-expiry/api-pem --data-urlencode "pem@cert.pem"
Both return {"common_name", "issuer", "valid_from", "valid_until", "days_remaining", "is_expired", "is_expiring_soon", "subject_alt_names", "serial_number", "fingerprint_sha256", "signature_algorithm", "ocsp_urls", "ca_issuer_urls", "crl_urls"} (plus "hostname" for the hostname endpoint), or {"error": "..."}. The hostname endpoint is rate limited to 20 checks/hour per source IP, connects on port 443 only, and refuses to connect to a hostname that resolves to a private/internal address.
Want an AI agent (Claude Code, claude.ai, or anything else that supports the Agent Skills format) to use this tool for you on request? Download the skill below and add it:
~/.claude/skills/certificate-expiry/SKILL.md