# SSL/TLS Certificate Check **SSL/TLS Certificate Check** is an independently documented x402 Atlas bridge at https://ssl.use.x402atlas.com. This document describes only this bridge; it does not aggregate routes, schemas, or content from any other bridge. ## How payment works Paid operations use the [x402 payment protocol](https://x402.org) and settle in USDC. Atlas supports deployments on Base, Polygon, and Arbitrum, plus configured Solana networks. This bridge currently advertises Arbitrum One (`eip155:42161`), Base (`eip155:8453`), Polygon (`eip155:137`), Solana mainnet (`solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp`). 1. Send the HTTP request without a payment signature. 2. Read the `402 Payment Required` response. Its `accepts` entries are the authoritative network, asset, amount, and recipient options for that call. 3. Select an option, sign it with an x402-compatible wallet or SDK, and repeat the request with the `PAYMENT-SIGNATURE` header. The successful response is returned after verification and settlement. TypeScript clients can automate the challenge, signing, and retry flow with [`x402-fetch`](https://www.npmjs.com/package/x402-fetch) or [`x402-axios`](https://www.npmjs.com/package/x402-axios). Fund a dedicated wallet only with the working USDC balance it needs and keep that key separate from treasury accounts. ## Pricing Atlas route prices start at $0.005 per successful call. This bridge's fallback price is $0.005; operations below state their exact configured price in `x-x402` and `x-payment-info`. The live `402` challenge remains authoritative. ## Worked payment example Request one documented operation without a signature to inspect its live terms: ```bash curl -i 'https://ssl.use.x402atlas.com/check?host=example.com&port=443' # HTTP/1.1 402 Payment Required # Read accepts[].network, asset, amount, and payTo from this response. ``` Sign one accepted option and repeat the identical request with the `PAYMENT-SIGNATURE` header. Do not invent or cache payment terms; read them from the current challenge. ## Use this API - Interactive reference: https://ssl.use.x402atlas.com/docs - OpenAPI 3.1 specification: https://ssl.use.x402atlas.com/openapi.json - Agent-readable route corpus: https://ssl.use.x402atlas.com/llms.txt - Endpoint index: https://ssl.use.x402atlas.com/index.json Use the operation schemas and examples below to construct requests. Copy the server URL, path, method, parameters, and request body from the operation you want to call. Path and query examples are concrete and can be used directly. ## Atlas response metadata Successful JSON responses include an additive top-level `_atlas` block, kept separate from the bridge's data fields. `_atlas.docs` links this bridge's `/llms.txt` corpus. `_atlas.related` suggests adjacent APIs, each with a callable `url`, its own `docs` link, and a short `summary`. Suppress this block by sending `X-Atlas-Meta: none` or by adding `?_atlas=0` to the request. ## Errors and compatibility Validation failures use HTTP `400`. Paid operations may return `402` before dispatch. Upstream and internal failures use the documented `5xx` responses. Clients should rely on documented fields and tolerate additive response fields, including `_atlas` unless they explicitly opt out. ## Protocol reference - x402 protocol and SDKs: https://x402.org ## SSL/TLS Certificate Check Docs: https://ssl.use.x402atlas.com/docs · OpenAPI: https://ssl.use.x402atlas.com/openapi.json ### GET /check SSL/TLS certificate check: expiry, issuer, SANs, chain validity, hostname match, negotiated protocol/cipher, and weak-algo warnings for a public HTTPS host. Clean JSON. Opens a live TLS handshake to `host` (optional `port`, default 443, restricted to an allowlist) and returns a normalized certificate report: cert facts (subject/issuer/SANs/serial/validity), derived `chain` flags (`is_expired`, `is_self_signed`, `hostname_matches`, `chain_valid`, `days_until_expiry`), the negotiated `connection` protocol/cipher, and a `warnings[]` verdict — the grade is the product, and a weak or invalid cert is still a `200`, not an error (SHA-1/MD5 signatures, short RSA/ECDSA keys, self-signed, untrusted chain, and hostname mismatch surface as warnings). Only `host` is required. Gotcha: `chain_valid` is verified against the Debian root set using only the intermediates the server actually presents — there is no AIA fetching — so a host that omits its intermediates reads `chain_valid=false` even where a browser would repair the chain. **Price:** $0.01 per call. Parameters: - `host` (required, string) — Hostname to inspect (no scheme, no IP literal, not localhost or a reserved/internal suffix); example: `"example.com"` - `port` (optional, integer) — TLS port; restricted to an allowlist; allowed: [443,8443], default: `443`; example: `443` Example: ```sh curl 'https://ssl.use.x402atlas.com/check?host=example.com&port=443' ``` Response example: ```json { "certificate": { "issuer_cn": "DigiCert Global G3 TLS ECC SHA384 2020 CA1", "issuer_org": "DigiCert Inc", "key_algorithm": "ECDSA", "key_size": 256, "not_after": "2027-02-15T23:59:59Z", "not_before": "2026-01-15T00:00:00Z", "sans": [ "example.com", "www.example.com" ], "serial_number": "212351572002930070173044758915925313", "signature_algorithm": "ECDSA-SHA384", "subject_cn": "example.com" }, "chain": { "chain_valid": true, "days_until_expiry": 228, "hostname_matches": true, "is_expired": false, "is_self_signed": false }, "connection": { "cipher_suite": "TLS_AES_128_GCM_SHA256", "tls_version": "TLS 1.3" }, "host": "example.com", "port": 443, "queried_at": "2026-07-02T12:00:00Z", "warnings": [] } ```