SSL certificate and domain expiry check API for many domains
Check SSL certificate and domain registration expiry for one domain or a whole list in one call, with a warning window you choose. Pay per domain.
Expired certificates and lapsed domains are the most avoidable outages. The sweep takes one domain or a list and returns, for each, the certificate issuer, the validity dates, the days left and whether the certificate is trusted, plus the domain registration and expiry dates, the registrar and the nameservers. Anything that expires inside your warning window is flagged, so a scheduled job only has to look at the flags.
Registrant details are never returned. You pay per domain checked, and a domain that cannot be reached is listed with the reason and not charged.
The calls
Each call returns 402 with the price until a payment is attached; an x402 client pays and retries automatically. Calls that fail are not charged. See Get started and the guide for bots and agents for code.
domain-ssl-sweep $0.005 per call
Check SSL certificate and domain registration expiry for one domain or a whole list: certificate issuer, valid from and to, days left, trusted or not, domain registration and expiry dates, registrar and nameservers.
curl -i "https://api.ambolt.dev/v1/domain-ssl-sweep?domain=www.sitemaps.org&warnDays=30"Example response
{
"checked": 1,
"readable": 1,
"flagged": 0,
"warnDays": 30,
"billableResults": 1,
"checkedAt": "2026-10-03T14:58:44.626Z",
"note": "SSL data comes from the certificate the server presents; domain data from the registry RDAP service. Subdomains share their parent domain registration.",
"results": [
{
"domain": "www.sitemaps.org",
"ok": true,
"ssl": {
"subject": "www.sitemaps.org",
"issuer": "Microsoft Corporation",
"notBefore": "2026-08-29T12:16:28.000Z",
"notAfter": "2026-12-07T11:16:28.000Z",
"sans": [
"www.sitemaps.org"
],
"protocol": "TLSv1.3",
"trusted": true,
"trustError": null,
"daysLeft": 64,
"expired": false
},
"registration": {
"registered": true,
"registeredAt": "2001-08-12T23:51:55.459Z",
"expiresAt": "2027-08-12T23:51:55Z",
"daysToExpiry": 313,
"registrar": "MarkMonitor Inc.",
"nameservers": [
"ns3-02.azure-dns.org",
"ns1-02.azure-dns.com",
"ns2-02.azure-dns.net",
"ns4-02.azure-dns.info"
],
"status": [
"client delete prohibited",
"client transfer prohibited",
"client update prohibited"
]
},
"flags": []
}
]
}Questions
How do I set the warning window?
Pass warnDays, for example 30. Anything that expires sooner is flagged in the response.
Can I check a whole list?
Yes. Pass the domains parameter with a list, or run the Apify Actor on a schedule.
Does it return who owns the domain?
No. Registrant details are not returned.
Use it from an AI agent
Every call is also an MCP tool: add https://api.ambolt.dev/mcp to your agent's server list.