SSL/TLS Checker MCP Server
SSLtest speaks the Model Context Protocol over the Streamable HTTP transport, so an AI agent can run an SSL/TLS scan as a native tool. No key, no signup.
European by default. Scanning servers in Germany and Finland, reports stored in an EU database. How the data is handled.
Endpoint
https://api.ssltest.com/mcpTool
| Tool | Input | Returns |
|---|---|---|
ssl_check |
host, port?, protocol? |
The full graded report (same shape as GET /v1/check) |
How it works
- Read-only. ssl_check connects to the named host and reads what comes back, the same way a browser's TLS handshake does.
- Cached. Results are keyed by host, port, and protocol, and cached for 24 hours, so repeated calls are fast.
- Blocking, up to ~90s. Unlike a poll-by-recall tool, ssl_check awaits the scan in the same call: a cold check typically returns in a few seconds. If a scan is still running after the wait budget, the tool returns an error asking for another call. The scan keeps running, so the retry lands on the cache.
- Rate-limited. No key is needed. Calls are rate-limited per client for abuse prevention.
Connect your client
Claude Code
claude mcp add --transport http ssltest https://api.ssltest.com/mcpCursor, Windsurf, Claude Desktop (MCP config)
{
"mcpServers": {
"ssltest": {
"url": "https://api.ssltest.com/mcp"
}
}
}VS Code (GitHub Copilot)
code --add-mcp '{"name":"ssltest","type":"http","url":"https://api.ssltest.com/mcp"}'Gemini CLI (~/.gemini/settings.json)
{
"mcpServers": {
"ssltest": {
"httpUrl": "https://api.ssltest.com/mcp"
}
}
}Codex (~/.codex/config.toml)
[mcp_servers.ssltest]
url = "https://api.ssltest.com/mcp"Raw protocol
Stateless JSON-RPC 2.0 over a single POST. List the tools:
curl -s https://api.ssltest.com/mcp \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'Spec and registry
The transport is Streamable HTTP, stateless (no
Mcp-Session-Id). Manifest:
server.json.
Frequently asked
No. The tool is free, needs no key and no account, and the limits are the same per-address limits the JSON API uses: six scans of one target a minute, sixty scans an hour. Repeated calls for the same host inside 24 hours are served from cache and count for nothing.
Nothing. ssl_check opens a TLS handshake to the named host and reads what comes back, the same connection a browser makes. There is no write path, no authentication and no state an agent can alter.
A scan is an ordinary connection to a public port, so checking a third-party host is fine and common. Owners preferring no scans publish a DNS record, and every call for the host is refused from then on.
A cold scan connects to every address the host resolves to, from five regions, and runs the full check set on each. Cached results come back immediately. A scan outrunning the wait budget returns an error asking for another call, and the scan keeps running, so the retry lands on the cache.
The same report the JSON API returns: the certificate chain, hostname match, expiry, TLS versions, cipher suites, key exchange, known vulnerabilities, client simulation, HSTS, CAA, revocation and a letter grade, per address, with the reason behind every finding.
The host refused every connection, answered something other than TLS, or took too long. The message carries the reason. A check unable to run is reported as untested rather than as a pass, so an agent never reads silence as a clean result.
Prefer plain HTTP?
The same scan returns a JSON report over a key-less REST endpoint, with live progress over Server-Sent Events.
Read the API docs