TLS Radar
What this MCP does
Scans SSL/TLS certificates, issues and renews free Let's Encrypt certificates, and monitors certificate expiration and scan history.
Tools
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Hostname to monitor (e.g. example.com). No scheme, no path.'}}}
Output schema
{'type': 'object', 'properties': {'address': {'type': 'string'}, 'host_id': {'type': 'string'}, 'team_id': {'type': 'string'}, 'scan_group_id': {'type': 'string'}}, 'additionalProperties': True}
Input schema
{'type': 'object', 'required': ['domains'], 'properties': {'domains': {'type': 'array', 'items': {'type': 'string'}, 'maxItems': 100, 'minItems': 1, 'description': 'List of hostnames to monitor'}}}
Output schema
{'type': 'object', 'required': ['requested', 'added', 'results'], 'properties': {'added': {'type': 'integer'}, 'results': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Per-domain add status.'}, 'team_id': {'type': 'string'}, 'requested': {'type': 'integer'}, 'scan_group_id': {'type': 'string'}}}
Input schema
{'type': 'object', 'required': ['order_id'], 'properties': {'order_id': {'type': 'string', 'description': 'The order_id from create_certificate.'}}}
Output schema
{'type': 'object', 'properties': {'records': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Per-record propagation status.'}, 'all_found': {'type': 'boolean', 'description': 'True when every challenge record/file is in place.'}}, 'additionalProperties': True}
Input schema
{'type': 'object', 'required': ['domain', 'email'], 'properties': {'email': {'type': 'string', 'description': "Contact email for Let's Encrypt expiry notices and the monitoring handoff."}, 'domain': {'type': 'string', 'description': 'Apex domain, no scheme/www (e.g. example.com).'}, 'challenge': {'enum': ['dns-01', 'http-01'], 'type': 'string', 'description': 'Validation method: dns-01 (default) or http-01.'}, 'client_id': {'type': 'string', 'description': "Optional anonymous install id from ~/.config/tlsradar/install_id (funnel attribution). If omitted, the response's install_id is a fresh one to save there."}, 'marketing_consent': {'type': 'boolean', 'description': 'Only true if the user explicitly opts in to a free account + reminder email. Default false.'}}}
Output schema
{'type': 'object', 'required': ['order_id', 'domain', 'challenge'], 'properties': {'domain': {'type': 'string'}, 'order_id': {'type': 'string'}, 'challenge': {'type': 'string'}, 'http_files': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Files to serve for http-01.'}, 'install_id': {'type': 'string'}, 'dns_records': {'type': 'array', 'items': {'type': 'object'}, 'description': 'TXT records to publish for dns-01.'}, 'next_action': {'type': 'string'}, 'resume_token': {'type': 'string', 'description': "Signed token to finalize past the backend's order TTL."}}}
Input schema
{'type': 'object', 'required': [], 'properties': {}}
Output schema
{'type': 'object', 'required': ['version', 'exported_at', 'teams'], 'properties': {'teams': {'type': 'array', 'items': {'type': 'object'}}, 'version': {'type': 'string'}, 'exported_at': {'type': 'string', 'format': 'date-time'}}}
Input schema
{'type': 'object', 'required': ['order_id'], 'properties': {'csr_pem': {'type': 'string', 'description': 'PEM CERTIFICATE REQUEST covering exactly {domain, www.domain}. Preferred - key stays local.'}, 'order_id': {'type': 'string', 'description': 'The order_id from create_certificate.'}, 'passphrase': {'type': 'string', 'description': 'Fallback only: ≥8 chars, protects a returned PKCS#12 bundle. Omit when using csr_pem.'}, 'resume_token': {'type': 'string', 'description': 'Optional. The resume_token from create_certificate; pass it to finalize an order whose row Beacon already purged (~24h).'}, 'max_wait_seconds': {'type': 'integer', 'description': 'How long to wait for validation server-side. Default 60, capped at 75.'}}}
Output schema
{'type': 'object', 'properties': {'mode': {'type': 'string'}, 'state': {'type': 'string'}, 'handoff': {'type': 'object', 'description': 'Cert->monitoring handoff; relay handoff.message and do not call add_monitor.'}, 'leaf_pem': {'type': 'string'}, 'chain_pem': {'type': 'string'}, 'not_after': {'type': 'string', 'format': 'date-time'}, 'fullchain_pem': {'type': 'string', 'description': 'Full certificate chain (PEM), present on success.'}}, 'additionalProperties': True}
Input schema
{'type': 'object', 'required': [], 'properties': {}}
Output schema
{'type': 'object', 'required': ['email'], 'properties': {'plan': {'type': 'object', 'description': 'Plan tier and limits.'}, 'email': {'type': 'string'}, 'usage': {'type': 'object', 'description': 'Current usage against the plan limits.'}}, 'additionalProperties': True}
Input schema
{'type': 'object', 'required': ['order_id'], 'properties': {'order_id': {'type': 'string', 'description': 'The order_id from create_certificate.'}}}
Output schema
{'type': 'object', 'properties': {'state': {'type': 'string'}, 'challenge': {'type': 'string'}, 'fullchain_pem': {'type': 'string', 'description': 'Present once the order is completed.'}}, 'additionalProperties': True}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'limit': {'type': 'integer', 'default': 10, 'maximum': 50, 'minimum': 1, 'description': 'Max results to return'}, 'domain': {'type': 'string', 'description': 'Domain name as it appears in list_monitors'}}}
Output schema
{'type': 'object', 'required': ['domain', 'results', 'count'], 'properties': {'count': {'type': 'integer'}, 'domain': {'type': 'string'}, 'results': {'type': 'array', 'items': {'type': 'object', 'properties': {'grade': {'type': ['string', 'null']}, 'issuer': {'type': ['string', 'null']}, 'scanned_at': {'type': 'string', 'format': 'date-time'}, 'scan_status': {'type': 'string'}, 'expiration_date': {'type': ['string', 'null'], 'format': 'date-time'}}}}}}
Input schema
{'type': 'object', 'required': ['payload'], 'properties': {'payload': {'type': 'object', 'description': 'Export payload, version 1.0. Use the `export` tool to generate one.'}}}
Output schema
{'type': 'object', 'properties': {'added': {'type': 'integer'}, 'results': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Per-domain import status.'}, 'requested': {'type': 'integer'}}, 'additionalProperties': True}
Input schema
{'type': 'object', 'required': ['email'], 'properties': {'role': {'enum': ['guest', 'admin'], 'type': 'string', 'default': 'guest', 'description': 'Invitee role: guest or admin. Defaults to guest.'}, 'email': {'type': 'string', 'description': 'Email address of the person to invite'}, 'team_id': {'type': 'string', 'description': 'Team UUID; defaults to the current team'}}}
Output schema
{'type': 'object', 'required': ['team_id', 'invited_email', 'role'], 'properties': {'role': {'type': 'string'}, 'team_id': {'type': 'string'}, 'team_name': {'type': 'string'}, 'invited_email': {'type': 'string'}}}
Input schema
{'type': 'object', 'required': [], 'properties': {'within': {'type': 'integer', 'default': 30, 'maximum': 365, 'minimum': 1, 'description': 'Days from now to look ahead'}}}
Output schema
{'type': 'object', 'required': ['entries', 'within_days', 'count'], 'properties': {'count': {'type': 'integer'}, 'nudge': {'type': 'object', 'description': 'Present only when an upgrade nudge is warranted.'}, 'entries': {'type': 'array', 'items': {'type': 'object'}}, 'within_days': {'type': 'integer'}}}
Input schema
{'type': 'object', 'required': [], 'properties': {}}
Output schema
{'type': 'object', 'required': ['monitors', 'count'], 'properties': {'count': {'type': 'integer'}, 'nudge': {'type': 'object', 'description': 'Present only when an upgrade nudge is warranted.'}, 'monitors': {'type': 'array', 'items': {'type': 'object', 'properties': {'address': {'type': 'string'}, 'host_id': {'type': 'string'}, 'team_id': {'type': 'string'}, 'scan_group_id': {'type': 'string'}, 'expiration_date': {'type': ['string', 'null'], 'format': 'date-time'}, 'days_until_expiration': {'type': ['integer', 'null']}}}}}}
Input schema
{'type': 'object', 'properties': {'domain': {'type': 'string', 'description': 'Domain to stop monitoring'}, 'host_id': {'type': 'string', 'description': 'UUID of the host (alternative to domain)'}}}
Output schema
{'type': 'object', 'required': ['removed_address'], 'properties': {'removed_address': {'type': 'string'}}}
Input schema
{'type': 'object', 'required': ['order_id'], 'properties': {'order_id': {'type': 'string', 'description': "The original order_id to clone. If you don't have one, use create_certificate instead."}}}
Output schema
{'type': 'object', 'properties': {'state': {'type': 'string'}, 'order_id': {'type': 'string'}, 'challenge': {'type': 'string'}, 'http_files': {'type': 'array', 'items': {'type': 'object'}}, 'dns_records': {'type': 'array', 'items': {'type': 'object'}}}, 'additionalProperties': True}
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Hostname to scan (e.g. example.com). No scheme, no path.'}, 'client_id': {'type': 'string', 'description': "Optional anonymous install id from ~/.config/tlsradar/install_id. Pass it for funnel attribution. If you omit it, the response's install_id is a fresh one to save there."}}}
Output schema
{'type': 'object', 'required': ['domain', 'status', 'share_token', 'share_url'], 'properties': {'domain': {'type': 'string'}, 'status': {'enum': ['pending', 'completed'], 'type': 'string'}, 'share_url': {'type': 'string', 'format': 'uri'}, 'install_id': {'type': 'string', 'description': 'Anonymous install id to persist locally and reuse.'}, 'scanned_at': {'type': ['string', 'null'], 'format': 'date-time'}, 'share_token': {'type': 'string'}, 'expiration_date': {'type': ['string', 'null'], 'format': 'date-time'}}}
Recent tool changes
Similar MCP servers
BorealHost
Provides web hosting and infrastructure management, including site deployment, DNS, domains, containers, compute, backups, cachin…
BlackVeil DNS & Email Security Scanner
Audits domain, DNS, email, certificate, HTTP, brand-impersonation, and agent-discovery security controls.
Hackertarget
Performs passive DNS, ASN, IP geolocation, HTTP header, ping, link, and network-path reconnaissance and diagnostics.
Busymate DevTools
Captures, inspects, exports, and debugs HTTPS traffic from devices and applications, with request and response inspection, proxy …
Ripe Stat
Provides RIPE registry and routing data for IP addresses, prefixes, ASNs, BGP state and neighbors, network ownership, geolocation…
Cloudflare Radar
Provides Cloudflare Radar internet observatory data on DDoS attacks, BGP leaks, domain popularity, internet quality, and traffic …
Domains
Checks domain registration status and availability and searches certificate-transparency records for certificates and subdomains.
Rdap
Looks up authoritative RDAP registration records for domains, IP addresses, autonomous systems, entities, and nameservers.