# crt.sh API

> crt.sh returns certificates and domain names for a search domain, available as a workflow and API.

crt.sh’s Search certificates method returns matching certificates and DNS names for a required domain. Search certificates returns newest certificates first; optionally include expired certificates or set a maximum result count.

- Page: https://fous.com/workflows/crt-sh
- Handle: `@crt-sh`
- Category: [Security](https://fous.com/workflows/category/security)
- Source website: https://crt.sh
- Last verified: Sep 29, 2026
- Fous is not affiliated with crt.sh.

## Methods

### Search certificates

Operation `search_certificates`, version 1. 1 credit per call.

Find issued certificates and the domain names they reveal on crt.sh. Expired certificates are excluded by default; results are limited to the newest matching certificates.

**Input**

| Field | Type | Required | Example | Description |
|---|---|---|---|---|
| `domain` | string | yes | `"example.com"` | Domain to search, for example example.com. |
| `max_results` | integer | no | `100` | Maximum number of certificates to return, for example 100. |
| `include_expired` | boolean | no | `true` | Include expired certificates, for example true. |

**Input schema**

```json
{
  "type": "object",
  "required": [
    "domain"
  ],
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain to search, for example example.com.",
      "examples": [
        "example.com"
      ]
    },
    "max_results": {
      "type": "integer",
      "default": 100,
      "maximum": 1000,
      "minimum": 1,
      "description": "Maximum number of certificates to return, for example 100.",
      "x-fous-developer": true,
      "examples": [
        100
      ]
    },
    "include_expired": {
      "type": "boolean",
      "default": false,
      "description": "Include expired certificates, for example true.",
      "examples": [
        true
      ]
    }
  },
  "additionalProperties": false,
  "examples": [
    {
      "domain": "example.com",
      "max_results": 100,
      "include_expired": true
    },
    {
      "domain": "example.com"
    }
  ]
}
```

**Output**

| Field | Type | Example | Description |
|---|---|---|---|
| `subdomains` | array |  | Unique matching DNS names, sorted A-Z, including wildcards and the root domain when present. |
| `certificates` | array |  | Matching unique certificates, newest first. |
| `certificates[].link` | string | `"https://crt.sh/?id=29557945233"` | Certificate page on crt.sh. |
| `certificates[].crt_sh_id` | integer | `29557945233` |  |
| `certificates[].valid_from` | string or null | `"2026-09-24"` |  |
| `certificates[].valid_until` | string or null | `"2026-12-21"` |  |
| `certificates[].names_covered` | array |  | DNS names listed on the certificate. |
| `certificates[].serial_number` | string or null | `"2caeeaf0743459d7e5f82a75123c58f3"` |  |
| `certificates[].issuer_organization` | string or null | `"Sectigo Limited"` | Organization that issued the certificate. |

**Example input**

```json
{
  "domain": "example.com"
}
```

**Example output**

```json
{
  "subdomains": [
    "*.example.com",
    "example.com",
    "www.example.com"
  ],
  "certificates": [
    {
      "link": "https://crt.sh/?id=29557945233",
      "crt_sh_id": 29557945233,
      "valid_from": "2026-09-24",
      "valid_until": "2026-12-21",
      "names_covered": [
        "*.example.com",
        "example.com"
      ],
      "serial_number": "2caeeaf0743459d7e5f82a75123c58f3",
      "issuer_organization": "Sectigo Limited"
    },
    {
      "link": "https://crt.sh/?id=28361996564",
      "crt_sh_id": 28361996564,
      "valid_from": "2026-07-29",
      "valid_until": "2026-10-27",
      "names_covered": [
        "*.example.com",
        "example.com"
      ],
      "serial_number": "0624d0ab311558780b7d5213b9631831",
      "issuer_organization": "SSL Corporation"
    },
    {
      "link": "https://crt.sh/?id=28361996505",
      "crt_sh_id": 28361996505,
      "valid_from": "2026-07-29",
      "valid_until": "2026-10-27",
      "names_covered": [
        "*.example.com",
        "example.com"
      ],
      "serial_number": "62546d11b12882adbce18f65f9372286",
      "issuer_organization": "SSL Corporation"
    }
  ]
}
```

## Quick start

Call the API with a Fous API key (`FOUS_API_KEY`). To create one, turn on Developer mode in Fous Studio, then open Keys & connections → API keys (https://app.fous.com/keys).

```bash
# First set your key: export FOUS_API_KEY='YOUR_FOUS_API_KEY'
: "${FOUS_API_KEY:?Set FOUS_API_KEY before running this example}"

curl 'https://api.fous.com/v1/query' \
  --fail-with-body --silent --show-error --max-time 120 \
  -H "Authorization: Bearer $FOUS_API_KEY" \
  -H 'Content-Type: application/json' \
  --data-raw '{
  "api": "@crt-sh",
  "visibility": "public",
  "operation": "search_certificates",
  "version": 1,
  "input": {
    "domain": "example.com",
    "max_results": 100,
    "include_expired": true
  },
  "response": {
    "format": "json"
  }
}'
```

```python
# Save as fous.py and run with python3 fous.py. No packages needed.
# First set your key: export FOUS_API_KEY='YOUR_FOUS_API_KEY'
import json
import os
import urllib.error
import urllib.request

api_key = os.environ.get("FOUS_API_KEY")
if not api_key:
    raise RuntimeError("Set FOUS_API_KEY before running this example")

body = json.loads("{\n  \"api\": \"@crt-sh\",\n  \"visibility\": \"public\",\n  \"operation\": \"search_certificates\",\n  \"version\": 1,\n  \"input\": {\n    \"domain\": \"example.com\",\n    \"max_results\": 100,\n    \"include_expired\": true\n  },\n  \"response\": {\n    \"format\": \"json\"\n  }\n}")
request = urllib.request.Request(
    "https://api.fous.com/v1/query",
    data=json.dumps(body).encode("utf-8"),
    headers={
        "Authorization": f"Bearer {api_key}",
        "Content-Type": "application/json",
    },
    method="POST",
)
try:
    with urllib.request.urlopen(request, timeout=120) as response:
        result = json.load(response)
except urllib.error.HTTPError as error:
    raise RuntimeError(f"HTTP {error.code}: {error.read().decode('utf-8', errors='replace')}") from error
if result.get("success") is False:
    raise RuntimeError(result.get("error", {}).get("message", "Request failed"))
print(json.dumps(result["data"]["output"], indent=2))
```

```typescript
// Save as fous.mts and run with npx tsx fous.mts.
// First set your key: export FOUS_API_KEY='YOUR_FOUS_API_KEY'
const apiKey = process.env.FOUS_API_KEY;
if (!apiKey) throw new Error("Set FOUS_API_KEY before running this example");

const response = await fetch("https://api.fous.com/v1/query", {
  method: "POST",
  headers: {
    "Authorization": `Bearer ${apiKey}`,
    "Content-Type": "application/json",
  },
  signal: AbortSignal.timeout(120_000),
  body: JSON.stringify({
  "api": "@crt-sh",
  "visibility": "public",
  "operation": "search_certificates",
  "version": 1,
  "input": {
    "domain": "example.com",
    "max_results": 100,
    "include_expired": true
  },
  "response": {
    "format": "json"
  }
}),
});
type ApiResult = { success: boolean; data?: { output: unknown }; error?: { message: string } };
const result: ApiResult = await response.json();
if (!response.ok || result.success === false) {
  throw new Error(result.error?.message ?? `HTTP ${response.status}`);
}
if (!result.data) throw new Error("Missing API response data");
console.log(result.data.output);
```

Or describe the data in plain language: send `{"api":"@crt-sh","prompt":"Describe the data you need, with every detail"}` to the same URL. Fous fills in the input, runs the method that fits and returns only the fields you asked for; `data.route.calls[].request` is the exact call it made. Routing is free; the run costs the same.

## Use cases

- Review certificates issued for a domain
- Identify subdomains revealed by certificates
- Check certificate validity dates
- Compare certificate issuer organizations
- Review names covered by certificates

## FAQ

### Is Fous affiliated with crt.sh?

No. Fous is not affiliated with crt.sh. This workflow reads the public crt.sh website and returns its data.

### How much does it cost?

Each run costs 1 credit. With pay-as-you-go, a credit costs 1¢; monthly plans cost less per credit.

### Do I need a crt.sh account?

No. You only need a Fous account.

### How current is the data?

Fous gets the data from crt.sh when you run it; repeating the same request within a day may return the saved result. Fous checks this workflow automatically; it last passed a check on Sep 29, 2026.

### What certificates were issued for a domain?

Search certificates returns matching certificates for the required domain, newest first.

### Which subdomains do certificates reveal?

Search certificates returns unique matching DNS names, including wildcards and the root domain when present.

## Related

- [SSL Labs API](https://fous.com/workflows/ssl-labs.md): Qualys SSL Labs tests the security of public HTTPS servers.
- [ICANN Lookup API](https://fous.com/workflows/icann-lookup.md): Public domain registration lookup using ICANN registration data.
- [Have I Been Pwned API](https://fous.com/workflows/have-i-been-pwned.md): Find public records of known data breaches.
- [Coursera API](https://fous.com/workflows/coursera.md): Coursera offers courses, certificates, projects, and degrees; search results follow Coursera’s order, and publicly displayed prices and availability may vary by location.
- [DuckDuckGo API](https://fous.com/workflows/duckduckgo.md): Private web search and instant answers.
- [Chrome Web Store API](https://fous.com/workflows/chrome-web-store.md): Chrome Web Store finds extensions by keywords or name and returns public listing details, with some listings omitting developer, user, or rating information.
- [Google Search API](https://fous.com/workflows/google-search.md): Google Search returns public web, image, job, event, related-question, and autocomplete results in Google’s order, with answers and details when available; results may be fewer, omit information, or be empty.
- [National Vulnerability Database API](https://fous.com/workflows/national-vulnerability-database.md): The U.S. National Vulnerability Database provides publicly reported security vulnerabilities, with recent product matches and CVE details, including CISA catalog status and affected versions when reported.
- [All Security workflows](https://fous.com/workflows/category/security)
