ambolt

All guides

SSL certificate and domain expiry check API for many domains

Check SSL certificate and domain registration expiry for one domain or a whole list in one call, with a warning window you choose. Pay per domain.

Expired certificates and lapsed domains are the most avoidable outages. The sweep takes one domain or a list and returns, for each, the certificate issuer, the validity dates, the days left and whether the certificate is trusted, plus the domain registration and expiry dates, the registrar and the nameservers. Anything that expires inside your warning window is flagged, so a scheduled job only has to look at the flags.

Registrant details are never returned. You pay per domain checked, and a domain that cannot be reached is listed with the reason and not charged.

The calls

Each call returns 402 with the price until a payment is attached; an x402 client pays and retries automatically. Calls that fail are not charged. See Get started and the guide for bots and agents for code.

domain-ssl-sweep $0.005 per call

Check SSL certificate and domain registration expiry for one domain or a whole list: certificate issuer, valid from and to, days left, trusted or not, domain registration and expiry dates, registrar and nameservers.

curl -i "https://api.ambolt.dev/v1/domain-ssl-sweep?domain=www.sitemaps.org&warnDays=30"
Example response
{
  "checked": 1,
  "readable": 1,
  "flagged": 0,
  "warnDays": 30,
  "billableResults": 1,
  "checkedAt": "2026-10-03T14:58:44.626Z",
  "note": "SSL data comes from the certificate the server presents; domain data from the registry RDAP service. Subdomains share their parent domain registration.",
  "results": [
    {
      "domain": "www.sitemaps.org",
      "ok": true,
      "ssl": {
        "subject": "www.sitemaps.org",
        "issuer": "Microsoft Corporation",
        "notBefore": "2026-08-29T12:16:28.000Z",
        "notAfter": "2026-12-07T11:16:28.000Z",
        "sans": [
          "www.sitemaps.org"
        ],
        "protocol": "TLSv1.3",
        "trusted": true,
        "trustError": null,
        "daysLeft": 64,
        "expired": false
      },
      "registration": {
        "registered": true,
        "registeredAt": "2001-08-12T23:51:55.459Z",
        "expiresAt": "2027-08-12T23:51:55Z",
        "daysToExpiry": 313,
        "registrar": "MarkMonitor Inc.",
        "nameservers": [
          "ns3-02.azure-dns.org",
          "ns1-02.azure-dns.com",
          "ns2-02.azure-dns.net",
          "ns4-02.azure-dns.info"
        ],
        "status": [
          "client delete prohibited",
          "client transfer prohibited",
          "client update prohibited"
        ]
      },
      "flags": []
    }
  ]
}

Questions

How do I set the warning window?

Pass warnDays, for example 30. Anything that expires sooner is flagged in the response.

Can I check a whole list?

Yes. Pass the domains parameter with a list, or run the Apify Actor on a schedule.

Does it return who owns the domain?

No. Registrant details are not returned.

Use it from an AI agent

Every call is also an MCP tool: add https://api.ambolt.dev/mcp to your agent's server list.