CertIndex MCP

공식

유일한 인증서 투명성 MCP 서버입니다. 21억 5천만 개 이상의 TLS 인증서를 검색하고, 새로운 발급을 위해 도메인을 모니터링하며, 글로벌 CT 파이어호스를 에이전트로 스트리밍합니다.

CertIndex MCP(으)로 무엇을 할 수 있나요?

  • 도메인 또는 발급자로 인증서 검색search_certificates를 사용하여 도메인, CN, 발급자 또는 SAN 패턴과 일치하는 TLS 인증서를 찾습니다.
  • 지문으로 인증서 조회get_certificate로 특정 SHA-256 지문에 대한 전체 PEM 데이터와 CT 로그 메타데이터를 가져옵니다.
  • 도메인의 모든 인증서 나열get_domain_certificates를 통해 특정 도메인에 대해 발급된 모든 인증서를 가져오며, 선택적으로 현재 유효한 인증서만 필터링할 수 있습니다.
  • CT 로그에서 확인된 서브도메인 열거get_subdomains에서 커서 기반 페이지네이션을 사용하여 도메인에 대해 관찰된 고유 서브도메인을 찾습니다.
  • 곧 만료되는 인증서 찾기get_expiring_certs를 사용하여 지정된 일수 내에 만료되는 도메인의 인증서를 식별합니다.
  • 글로벌 인덱스 스윕 실행submit_global_sweep으로 CN 또는 SAN 기준 전체 CT 코퍼스에 대한 비동기 부분 문자열 검색을 제출한 후, get_sweep_results로 결과를 폴링합니다.

문서

certindex-mcp

CI PyPI License: MIT

An MCP (Model Context Protocol) server that exposes CertIndex's Certificate Transparency search tools to any MCP-compatible client (Claude Desktop, the MCP Inspector, Continue, etc.).

CertIndex indexes the full public CT corpus (~5 M certificates, growing ~100 k/day). This server wraps the public CertIndex REST API so an LLM can ask questions like:

  • "List every TLS certificate ever issued for example.com."
  • "What subdomains has Let's Encrypt seen for mycompany.io?"
  • "Show me certs expiring in the next 30 days for api.mycompany.io."
  • "Pull the full PEM and CT log metadata for SHA-256 <fingerprint>."

Why this repo exists

The CertIndex monorepo bundles an MCP server (mounted at https://api.ctindex.io/mcp) that talks directly to the production Postgres index. This standalone package is a thin client-side shim: it speaks MCP to your editor / agent and forwards every tool call to the hosted CertIndex REST API over HTTPS. Two consequences:

  1. You don't need a copy of the index — sign up for a free API key at https://ctindex.io and you're done.
  2. The package has a tiny dependency footprint (mcp, httpx, pydantic) — easy to audit, easy to vendor, no DB drivers.

Install

pip install certindex-mcp

Or with uvx for one-shot use:

uvx certindex-mcp

To install the latest development version from source instead:

pip install git+https://github.com/certindex/certindex-mcp

Quickstart — Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):

{
  "mcpServers": {
    "certindex": {
      "command": "uvx",
      "args": ["certindex-mcp"],
      "env": {
        "CERTINDEX_API_KEY": "ctx_live_..."
      }
    }
  }
}

Restart Claude Desktop. The ten CertIndex tools appear in the tool tray.

Tools

Ten tools, matching the hosted CertIndex MCP server 1:1:

ToolWhat it doesNotable parameters
search_certificatesSearch the CT index by domain, CN, issuer, SAN, validity, or wildcard status.domain, cn, issuer, san, expired, is_wildcard, page/limit
get_certificateFetch a single cert by SHA-256 fingerprint.sha256, include_enrichment
get_domain_certificatesEvery cert ever issued for an exact domain.valid_only, include_enrichment, include_signals (paid plans), page/limit
get_subdomainsEnumerate unique subdomains seen in CT.Offset (page/limit) or keyset cursor mode — pass cursor="" to start, then feed back each response's next_cursor
get_latest_certMost recent currently-valid cert for a domain.include_enrichment, include_signals, include_precerts (let precertificates compete for "latest")
get_expiring_certsCerts for a domain expiring within days days.days
submit_global_sweepSubmit an async, domain-less CN/SAN substring sweep of the entire index (POST /v1/sweeps).cn/san_contains (3+ chars, at least one required), issuer, is_wildcard, is_precert, expired, first_seen_*/not_after_* date bounds, strict_attribution, resume_token (continuation past the result cap)
get_sweep_resultsPoll a sweep job and paginate its results when done (GET /v1/sweeps/{id}).sweep_id, page/limit (up to 1,000)
get_usageCaller's tier, current usage, remaining quota, and entitlements.
get_historical_backfill_statusCheck / start the paid deep-history backfill for a domain.domain

Quickstart — MCP Inspector

export CERTINDEX_API_KEY=ctx_live_...
npx @modelcontextprotocol/inspector uvx certindex-mcp

Configuration

Env varDefaultDescription
CERTINDEX_API_KEY(required)Your CertIndex API key. Mint one at https://ctindex.io/app/keys
CERTINDEX_BASE_URLhttps://api.ctindex.ioOverride for self-hosted deployments / staging
CERTINDEX_TIMEOUT30Per-request HTTP timeout (seconds)

Security

Input validation, rate-limit handling, and our supply-chain posture are documented in SECURITY.md. Please report vulnerabilities to security@ctindex.io rather than filing public issues.

Development

git clone https://github.com/certindex/certindex-mcp
cd certindex-mcp
pip install -e ".[dev]"
pytest

CI runs on Python 3.11 / 3.12 / 3.13.

License

MIT © CertIndex contributors.