SSL and Domain Expiry Sweep: Renewal Dates for Many Domains
Check SSL certificate and domain registration expiry for one domain or a whole list: certificate issuer, valid from and to, days left, trusted or not, domain registration and expiry dates, registrar and nameservers. Flags what expires within your warning window. Registrant details are never returned.
x402: $0.005 per callMCP tool: domain_ssl_sweepApify Actor: $0.005 per event
Input
| Parameter | Type | Default | Description |
|---|---|---|---|
domain | string | One domain, for example example.com. Use this or domains. | |
domains | array | Up to 100 domains in one run (Apify Actor only). Each domain that returns a result is one billable result. | |
warnDays | integer | 30 | Flag certificates and registrations that expire within this many days. |
checks | string both | ssl | domain | both | Which checks to run for each domain. |
* required
Source and freshness
- Source and licence
- Stated in every response (field source).
- Last verified
- 2026-10-03 (hourly check against the live source)
Use it
HTTP (x402)
curl -i "https://api.ambolt.dev/v1/domain-ssl-sweep?domain=www.sitemaps.org&warnDays=30"Returns 402 Payment Required with the price until an x402 payment is attached; @x402/fetch does this for you. See Get started.
MCP
{ "mcpServers": { "ambolt": { "url": "https://api.ambolt.dev/mcp" } } }
# then call the tool: domain_ssl_sweep
Apify
Run the Actor ($0.005 per domain, free trial credits for new accounts).
Example response
{
"checked": 1,
"readable": 1,
"flagged": 0,
"warnDays": 30,
"billableResults": 1,
"checkedAt": "2026-10-03T14:58:44.626Z",
"note": "SSL data comes from the certificate the server presents; domain data from the registry RDAP service. Subdomains share their parent domain registration.",
"results": [
{
"domain": "www.sitemaps.org",
"ok": true,
"ssl": {
"subject": "www.sitemaps.org",
"issuer": "Microsoft Corporation",
"notBefore": "2026-08-29T12:16:28.000Z",
"notAfter": "2026-12-07T11:16:28.000Z",
"sans": [
"www.sitemaps.org"
],
"protocol": "TLSv1.3",
"trusted": true,
"trustError": null,
"daysLeft": 64,
"expired": false
},
"registration": {
"registered": true,
"registeredAt": "2001-08-12T23:51:55.459Z",
"expiresAt": "2027-08-12T23:51:55Z",
"daysToExpiry": 313,
"registrar": "MarkMonitor Inc.",
"nameservers": [
"ns3-02.azure-dns.org",
"ns1-02.azure-dns.com",
"ns2-02.azure-dns.net",
"ns4-02.azure-dns.info"
],
"status": [
"client delete prohibited",
"client transfer prohibited",
"client update prohibited"
]
},
"flags": []
}
]
}
Good to know
- You are charged only when the call succeeds. Invalid input or an unavailable source costs nothing.
- Every response states its source and the time it was fetched.
- Informational only; not financial, legal or tax advice.
- Something wrong or missing? Open an issue on the repository (ambolt-mcp) and a reply follows under the Ambolt name.