# SSL Labs API

> SSL Labs returns HTTPS security grades, server and certificate details, protocols, and weaknesses, available as a workflow and API.

SSL Labs (SSLLabs) returns HTTPS grades, server details, certificate information, supported protocols, and known weaknesses. Check ssl certificate needs a website domain or URL and can reuse a report from the last 72 hours.

- Page: https://fous.com/workflows/ssl-labs
- Handle: `@ssl-labs`
- Category: [Security](https://fous.com/workflows/category/security)
- Source website: https://ssllabs.com
- Last verified: Sep 29, 2026
- Fous is not affiliated with SSL Labs.

## Methods

### Check ssl certificate

Operation `check_ssl_certificate`, version 1. 1 credit per call.

Check a website’s SSL Labs HTTPS security grade, servers, certificate, protocols, and known weaknesses. Cached results from the last 72 hours are reused by default; a fresh assessment can take several minutes and may exceed the call time limit. Results are kept off public boards.

**Input**

| Field | Type | Required | Example | Description |
|---|---|---|---|---|
| `website` | string | yes | `"github.com"` | Website domain or URL, for example https://github.com/about. |
| `use_cached` | boolean | no |  | Reuse a report from the last 72 hours when available, for example true; set false to request a fresh test. |

**Input schema**

```json
{
  "type": "object",
  "required": [
    "website"
  ],
  "properties": {
    "website": {
      "type": "string",
      "description": "Website domain or URL, for example https://github.com/about.",
      "examples": [
        "github.com",
        "https://www.ssllabs.com/ssltest/",
        "www.google.com"
      ]
    },
    "use_cached": {
      "type": "boolean",
      "default": true,
      "description": "Reuse a report from the last 72 hours when available, for example true; set false to request a fresh test."
    }
  },
  "additionalProperties": false,
  "examples": [
    {
      "website": "github.com"
    },
    {
      "website": "https://www.ssllabs.com/ssltest/"
    },
    {
      "website": "www.google.com"
    }
  ]
}
```

**Output**

| Field | Type | Example | Description |
|---|---|---|---|
| `domain` | string | `"github.com"` | Website domain that was tested. |
| `servers` | array |  | Server addresses and grades. |
| `servers[].grade` | string or null | `"A+"` |  |
| `servers[].ip_address` | string | `"140.82.112.3"` |  |
| `servers[].results_page_link` | string | `"https://www.ssllabs.com/ssltest/analyze.html?d=github.com&hideResults=on&s=140.82.112.3"` |  |
| `test_date` | string | `"2026-09-28"` |  |
| `overall_grade` | string | `"A+"` | Lowest SSL Labs grade across the tested servers. |
| `known_weaknesses` | array |  |  |
| `days_until_expiry` | integer or null | `33` |  |
| `results_page_link` | string | `"https://www.ssllabs.com/ssltest/analyze.html?d=github.com&hideResults=on"` |  |
| `certificate_issuer` | string or null | `"Sectigo Limited"` |  |
| `supported_protocols` | array |  |  |
| `certificate_expiry_date` | string or null | `"2026-11-01"` |  |

**Example input**

```json
{
  "website": "github.com"
}
```

**Example output**

```json
{
  "domain": "github.com",
  "servers": [
    {
      "grade": "A+",
      "ip_address": "140.82.112.3",
      "results_page_link": "https://www.ssllabs.com/ssltest/analyze.html?d=github.com&hideResults=on&s=140.82.112.3"
    }
  ],
  "test_date": "2026-09-28",
  "overall_grade": "A+",
  "known_weaknesses": [],
  "days_until_expiry": 33,
  "results_page_link": "https://www.ssllabs.com/ssltest/analyze.html?d=github.com&hideResults=on",
  "certificate_issuer": "Sectigo Limited",
  "supported_protocols": [
    "TLS 1.3",
    "TLS 1.2"
  ],
  "certificate_expiry_date": "2026-11-01"
}
```

## Quick start

Call the API with a Fous API key (`FOUS_API_KEY`). To create one, turn on Developer mode in Fous Studio, then open Keys & connections → API keys (https://app.fous.com/keys).

```bash
# First set your key: export FOUS_API_KEY='YOUR_FOUS_API_KEY'
: "${FOUS_API_KEY:?Set FOUS_API_KEY before running this example}"

curl 'https://api.fous.com/v1/query' \
  --fail-with-body --silent --show-error --max-time 120 \
  -H "Authorization: Bearer $FOUS_API_KEY" \
  -H 'Content-Type: application/json' \
  --data-raw '{
  "api": "@ssl-labs",
  "visibility": "public",
  "operation": "check_ssl_certificate",
  "version": 1,
  "input": {
    "website": "github.com"
  },
  "response": {
    "format": "json"
  }
}'
```

```python
# Save as fous.py and run with python3 fous.py. No packages needed.
# First set your key: export FOUS_API_KEY='YOUR_FOUS_API_KEY'
import json
import os
import urllib.error
import urllib.request

api_key = os.environ.get("FOUS_API_KEY")
if not api_key:
    raise RuntimeError("Set FOUS_API_KEY before running this example")

body = json.loads("{\n  \"api\": \"@ssl-labs\",\n  \"visibility\": \"public\",\n  \"operation\": \"check_ssl_certificate\",\n  \"version\": 1,\n  \"input\": {\n    \"website\": \"github.com\"\n  },\n  \"response\": {\n    \"format\": \"json\"\n  }\n}")
request = urllib.request.Request(
    "https://api.fous.com/v1/query",
    data=json.dumps(body).encode("utf-8"),
    headers={
        "Authorization": f"Bearer {api_key}",
        "Content-Type": "application/json",
    },
    method="POST",
)
try:
    with urllib.request.urlopen(request, timeout=120) as response:
        result = json.load(response)
except urllib.error.HTTPError as error:
    raise RuntimeError(f"HTTP {error.code}: {error.read().decode('utf-8', errors='replace')}") from error
if result.get("success") is False:
    raise RuntimeError(result.get("error", {}).get("message", "Request failed"))
print(json.dumps(result["data"]["output"], indent=2))
```

```typescript
// Save as fous.mts and run with npx tsx fous.mts.
// First set your key: export FOUS_API_KEY='YOUR_FOUS_API_KEY'
const apiKey = process.env.FOUS_API_KEY;
if (!apiKey) throw new Error("Set FOUS_API_KEY before running this example");

const response = await fetch("https://api.fous.com/v1/query", {
  method: "POST",
  headers: {
    "Authorization": `Bearer ${apiKey}`,
    "Content-Type": "application/json",
  },
  signal: AbortSignal.timeout(120_000),
  body: JSON.stringify({
  "api": "@ssl-labs",
  "visibility": "public",
  "operation": "check_ssl_certificate",
  "version": 1,
  "input": {
    "website": "github.com"
  },
  "response": {
    "format": "json"
  }
}),
});
type ApiResult = { success: boolean; data?: { output: unknown }; error?: { message: string } };
const result: ApiResult = await response.json();
if (!response.ok || result.success === false) {
  throw new Error(result.error?.message ?? `HTTP ${response.status}`);
}
if (!result.data) throw new Error("Missing API response data");
console.log(result.data.output);
```

Or describe the data in plain language: send `{"api":"@ssl-labs","prompt":"Describe the data you need, with every detail"}` to the same URL. Fous fills in the input, runs the method that fits and returns only the fields you asked for; `data.route.calls[].request` is the exact call it made. Routing is free; the run costs the same.

## Use cases

- Compare HTTPS grades across a website’s servers
- Review certificate expiry dates and issuers
- Identify supported protocols and known weaknesses
- Track certificate expiry dates for monitored websites

## FAQ

### Is Fous affiliated with SSL Labs?

No. Fous is not affiliated with SSL Labs. This workflow reads the public ssllabs.com website and returns its data.

### How much does it cost?

Each run costs 1 credit. With pay-as-you-go, a credit costs 1¢; monthly plans cost less per credit.

### Do I need a SSL Labs account?

No. You only need a Fous account.

### How current is the data?

Fous gets the data from ssllabs.com when you run it; repeating the same request within a day may return the saved result. Fous checks this workflow automatically; it last passed a check on Sep 29, 2026.

### What HTTPS grade did the website receive?

Check ssl certificate returns the overall grade and grades for tested servers.

### When does the website’s certificate expire?

Check ssl certificate returns the certificate expiry date and days until expiry.

### Which protocols does the website support?

Check ssl certificate returns the supported protocols.

## Related

- [Google PageSpeed Insights API](https://fous.com/workflows/google-pagespeed-insights.md): Check web page speed and quality on mobile and desktop.
- [crt.sh API](https://fous.com/workflows/crt-sh.md): Public certificate transparency search for issued certificates and names they cover.
- [Have I Been Pwned API](https://fous.com/workflows/have-i-been-pwned.md): Find public records of known data breaches.
- [ICANN Lookup API](https://fous.com/workflows/icann-lookup.md): Public domain registration lookup using ICANN registration data.
- [National Vulnerability Database API](https://fous.com/workflows/national-vulnerability-database.md): The U.S. National Vulnerability Database provides publicly reported security vulnerabilities, with recent product matches and CVE details, including CISA catalog status and affected versions when reported.
- [QS Top Universities API](https://fous.com/workflows/qs-top-universities.md): QS Top Universities provides rankings and profiles with latest world ranks, student figures, up to five subject ranks and listed tuition; subject editions may differ.
- [Cloudflare Radar API](https://fous.com/workflows/cloudflare-radar.md): Cloudflare Radar provides internet trends, domain popularity and weekly rank history only for top-100 sites, plus recent and ongoing outages with locations when identified.
- [Google Public DNS API](https://fous.com/workflows/google-public-dns.md): Public DNS lookups and DNS-over-HTTPS from Google.
- [All Security workflows](https://fous.com/workflows/category/security)
