# crt.sh API

> crt.sh returns certificates and domain names for a search domain, available as a workflow and API.

crt.sh’s Search certificates method returns matching certificates and DNS names for a required domain. Search certificates returns newest certificates first; optionally include expired certificates or set a maximum result count.

- Page: https://fous.com/tools/crt-sh
- Handle: `@crt-sh`
- Category: [Security](https://fous.com/tools/category/security)
- Source website: https://crt.sh
- Last verified: Sep 29, 2026

## Methods

### Search certificates

Operation `search_certificates`, version 1. 1 credit per completed call. Failed calls without a completed billing receipt are free; completed work can remain charged if delivery is interrupted.

Find issued certificates and the domain names they reveal on crt.sh. Expired certificates are excluded by default; results are limited to the newest matching certificates.

**Input**

| Field | Type | Required | Example | Description |
|---|---|---|---|---|
| `domain` | string | yes | `"example.com"` | Domain to search, for example example.com. |
| `max_results` | integer | no | `100` | Maximum number of certificates to return, for example 100. |
| `include_expired` | boolean | no | `true` | Include expired certificates, for example true. |

**Input schema**

```json
{
  "type": "object",
  "required": [
    "domain"
  ],
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain to search, for example example.com.",
      "examples": [
        "example.com"
      ]
    },
    "max_results": {
      "type": "integer",
      "default": 100,
      "maximum": 1000,
      "minimum": 1,
      "description": "Maximum number of certificates to return, for example 100.",
      "x-fous-developer": true,
      "examples": [
        100
      ]
    },
    "include_expired": {
      "type": "boolean",
      "default": false,
      "description": "Include expired certificates, for example true.",
      "examples": [
        true
      ]
    }
  },
  "additionalProperties": false,
  "examples": [
    {
      "domain": "example.com",
      "max_results": 100,
      "include_expired": true
    },
    {
      "domain": "example.com"
    }
  ]
}
```

**Output**

| Field | Type | Example | Description |
|---|---|---|---|
| `subdomains` | array |  | Unique matching DNS names, sorted A-Z, including wildcards and the root domain when present. |
| `certificates` | array |  | Matching unique certificates, newest first. |
| `certificates[].link` | string | `"https://crt.sh/?id=29557945233"` | Certificate page on crt.sh. |
| `certificates[].crt_sh_id` | integer | `29557945233` |  |
| `certificates[].valid_from` | string or null | `"2026-09-24"` |  |
| `certificates[].valid_until` | string or null | `"2026-12-21"` |  |
| `certificates[].names_covered` | array |  | DNS names listed on the certificate. |
| `certificates[].serial_number` | string or null | `"2caeeaf0743459d7e5f82a75123c58f3"` |  |
| `certificates[].issuer_organization` | string or null | `"Sectigo Limited"` | Organization that issued the certificate. |

**Example input**

```json
{
  "domain": "example.com",
  "max_results": 100,
  "include_expired": true
}
```

**Example output**

```json
{
  "subdomains": [
    "*.example.com",
    "dev.example.com",
    "example.com"
  ],
  "certificates": [
    {
      "link": "https://crt.sh/?id=29557945233",
      "crt_sh_id": 29557945233,
      "valid_from": "2026-09-24",
      "valid_until": "2026-12-21",
      "names_covered": [
        "*.example.com",
        "example.com"
      ],
      "serial_number": "2caeeaf0743459d7e5f82a75123c58f3",
      "issuer_organization": "Sectigo Limited"
    },
    {
      "link": "https://crt.sh/?id=28361996564",
      "crt_sh_id": 28361996564,
      "valid_from": "2026-07-29",
      "valid_until": "2026-10-27",
      "names_covered": [
        "*.example.com",
        "example.com"
      ],
      "serial_number": "0624d0ab311558780b7d5213b9631831",
      "issuer_organization": "SSL Corporation"
    },
    {
      "link": "https://crt.sh/?id=28361996505",
      "crt_sh_id": 28361996505,
      "valid_from": "2026-07-29",
      "valid_until": "2026-10-27",
      "names_covered": [
        "*.example.com",
        "example.com"
      ],
      "serial_number": "62546d11b12882adbce18f65f9372286",
      "issuer_organization": "SSL Corporation"
    }
  ]
}
```

## Quick start

Replace `YOUR_API_KEY` with a Fous API key. To create one, open Developers at the bottom of Fous Studio, turn on Developer mode, then go to API keys (https://app.fous.com/keys). Change the values in `input` to run the same tool on new data.

```bash
curl 'https://api.fous.com/v1/query' \
  --fail-with-body --silent --show-error --max-time 180 \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H 'Content-Type: application/json' \
  --data-raw '{
  "api": "@crt-sh",
  "visibility": "public",
  "operation": "search_certificates",
  "version": 1,
  "input": {
    "domain": "example.com",
    "max_results": 100,
    "include_expired": true
  },
  "response": {
    "format": "json"
  }
}'
```

```python
# Save as fous.py and run with python3 fous.py. No packages needed.
import json
import urllib.error
import urllib.request

api_key = "YOUR_API_KEY"

body = json.loads("{\n  \"api\": \"@crt-sh\",\n  \"visibility\": \"public\",\n  \"operation\": \"search_certificates\",\n  \"version\": 1,\n  \"input\": {\n    \"domain\": \"example.com\",\n    \"max_results\": 100,\n    \"include_expired\": true\n  },\n  \"response\": {\n    \"format\": \"json\"\n  }\n}")
request = urllib.request.Request(
    "https://api.fous.com/v1/query",
    data=json.dumps(body).encode("utf-8"),
    headers={
        "Authorization": f"Bearer {api_key}",
        "Content-Type": "application/json",
    },
    method="POST",
)
try:
    with urllib.request.urlopen(request, timeout=180) as response:
        result = json.load(response)
except urllib.error.HTTPError as error:
    raise RuntimeError(f"HTTP {error.code}: {error.read().decode('utf-8', errors='replace')}") from error
if result.get("success") is False:
    raise RuntimeError(result.get("error", {}).get("message", "Request failed"))
print(json.dumps(result["data"]["output"], indent=2))
```

```typescript
// Save as fous.mts and run with npx tsx fous.mts.
const apiKey = "YOUR_API_KEY";

const response = await fetch("https://api.fous.com/v1/query", {
  method: "POST",
  headers: {
    "Authorization": `Bearer ${apiKey}`,
    "Content-Type": "application/json",
  },
  signal: AbortSignal.timeout(180_000),
  body: JSON.stringify({
  "api": "@crt-sh",
  "visibility": "public",
  "operation": "search_certificates",
  "version": 1,
  "input": {
    "domain": "example.com",
    "max_results": 100,
    "include_expired": true
  },
  "response": {
    "format": "json"
  }
}),
});
type ApiResult = { success: boolean; data?: { output: unknown }; error?: { message: string } };
const result: ApiResult = await response.json();
if (!response.ok || result.success === false) {
  throw new Error(result.error?.message ?? `HTTP ${response.status}`);
}
if (!result.data) throw new Error("Missing API response data");
console.log(result.data.output);
```

## Use from an AI assistant

Connect this tool to Claude Code, Claude Desktop, Cursor, VS Code, Codex and any MCP client as its own MCP server. Each method is a typed tool whose arguments are the method’s input.

- Server URL: `https://api.fous.com/mcp/tools/crt-sh`
- Authorization: `Authorization: Bearer <Fous API key>`

**Tools**

- `search_certificates`: Search certificates. 1 credit per completed call. Failed calls without a completed billing receipt are free; completed work can remain charged if delivery is interrupted.
- `fous_get_run`: the result of a run that was still going, by its `request_id`. Free.

Claude Code:

```bash
claude mcp add --scope user --transport http fous-crt-sh https://api.fous.com/mcp/tools/crt-sh --header "Authorization: Bearer ${FOUS_API_KEY:?Set FOUS_API_KEY to your Fous API key}"
```

To give the assistant every tool, connect `https://api.fous.com/mcp`: it finds one with `fous_search_tools` and runs it with `fous_run_tool`. Setup for other clients: https://fous.com/llms-full.txt.

## Use cases

- Review certificates issued for a domain
- Identify subdomains revealed by certificates
- Check certificate validity dates
- Compare certificate issuer organizations
- Review names covered by certificates

## FAQ

### Can I run it with my own inputs?

Yes. Change the inputs in Studio and press Run, or send new inputs from your code, or ask a connected AI assistant.

### Can I call this crt.sh tool as an API?

Yes. Send a POST request to /v1/query with your Fous API key and the inputs, and get JSON back.

### How much does it cost?

Each completed run costs 1 credit. Failed runs without a completed receipt are free; completed work can remain charged if delivery is interrupted. With pay as you go, a credit costs 1¢. Monthly plans cost less per credit.

### Do I need a crt.sh account?

No. You only need a Fous account.

### How current is the data?

Fous gets the data from crt.sh when you run it. Some results are reused for up to 24 hours, and results that use your account or key are never reused. It was last verified on Sep 29, 2026.

### What certificates were issued for a domain?

Search certificates returns matching certificates for the required domain, newest first.

### Which subdomains do certificates reveal?

Search certificates returns unique matching DNS names, including wildcards and the root domain when present.

## Related

- [SSL Labs API](https://fous.com/tools/ssl-labs.md): Qualys SSL Labs tests the security of public HTTPS servers.
- [ICANN Lookup API](https://fous.com/tools/icann-lookup.md): Public domain registration lookup using ICANN registration data.
- [Have I Been Pwned API](https://fous.com/tools/have-i-been-pwned.md): Find public records of known data breaches.
- [Coursera API](https://fous.com/tools/coursera.md): Coursera offers courses, certificates, projects, and degrees; search results follow Coursera’s order, and publicly displayed prices and availability may vary by location.
- [DuckDuckGo API](https://fous.com/tools/duckduckgo.md): Private web search and instant answers.
- [Chrome Web Store API](https://fous.com/tools/chrome-web-store.md): Chrome Web Store finds extensions by keywords or name and returns public listing details, with some listings omitting developer, user, or rating information.
- [Google Search API](https://fous.com/tools/google-search.md): Google Search returns public web, image, job, event, related-question, and autocomplete results in Google’s order, with answers and details when available; results may be fewer, omit information, or be empty.
- [National Vulnerability Database API](https://fous.com/tools/national-vulnerability-database.md): The U.S. National Vulnerability Database provides publicly reported security vulnerabilities, with recent product matches and CVE details, including CISA catalog status and affected versions when reported.
- [All Security tools](https://fous.com/tools/category/security)
