Skip to content

SSL/TLS Checker MCP Server

SSLtest speaks the Model Context Protocol over the Streamable HTTP transport, so an AI agent can run an SSL/TLS scan as a native tool. No key, no signup.

European by default. Scanning servers in Germany and Finland, reports stored in an EU database. How the data is handled.

Endpoint

https://api.ssltest.com/mcp

Tool

ToolInputReturns
ssl_check host, port?, protocol? The full graded report (same shape as GET /v1/check)

How it works

Connect your client

Claude Code

claude mcp add --transport http ssltest https://api.ssltest.com/mcp

Cursor, Windsurf, Claude Desktop (MCP config)

{
  "mcpServers": {
    "ssltest": {
      "url": "https://api.ssltest.com/mcp"
    }
  }
}

VS Code (GitHub Copilot)

code --add-mcp '{"name":"ssltest","type":"http","url":"https://api.ssltest.com/mcp"}'

Gemini CLI (~/.gemini/settings.json)

{
  "mcpServers": {
    "ssltest": {
      "httpUrl": "https://api.ssltest.com/mcp"
    }
  }
}

Codex (~/.codex/config.toml)

[mcp_servers.ssltest]
url = "https://api.ssltest.com/mcp"

Raw protocol

Stateless JSON-RPC 2.0 over a single POST. List the tools:

curl -s https://api.ssltest.com/mcp \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

Spec and registry

The transport is Streamable HTTP, stateless (no Mcp-Session-Id). Manifest: server.json.

Frequently asked

Is there a cost or a quota?

No. The tool is free, needs no key and no account, and the limits are the same per-address limits the JSON API uses: six scans of one target a minute, sixty scans an hour. Repeated calls for the same host inside 24 hours are served from cache and count for nothing.

What does the tool change?

Nothing. ssl_check opens a TLS handshake to the named host and reads what comes back, the same connection a browser makes. There is no write path, no authentication and no state an agent can alter.

Is scanning a host somebody else runs allowed?

A scan is an ordinary connection to a public port, so checking a third-party host is fine and common. Owners preferring no scans publish a DNS record, and every call for the host is refused from then on.

Why does a call sometimes take a minute?

A cold scan connects to every address the host resolves to, from five regions, and runs the full check set on each. Cached results come back immediately. A scan outrunning the wait budget returns an error asking for another call, and the scan keeps running, so the retry lands on the cache.

What comes back?

The same report the JSON API returns: the certificate chain, hostname match, expiry, TLS versions, cipher suites, key exchange, known vulnerabilities, client simulation, HSTS, CAA, revocation and a letter grade, per address, with the reason behind every finding.

What does a failed scan mean?

The host refused every connection, answered something other than TLS, or took too long. The message carries the reason. A check unable to run is reported as untested rather than as a pass, so an agent never reads silence as a clean result.

Prefer plain HTTP?

The same scan returns a JSON report over a key-less REST endpoint, with live progress over Server-Sent Events.

Read the API docs