{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "category": "observability",
    "endpoint": "https://tlsradar.com/api/v1/mcp",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/tlsradar.json",
    "kind": "mcp",
    "listed": "indexed",
    "liveUrl": "https://www.anchorterminal.com/api/v1/live/tlsradar.json",
    "markdownUrl": "https://www.anchorterminal.com/tools/tlsradar.md",
    "mcpTools": {
      "check": {
        "checker": "anchor-check/1.0",
        "totalTokens": 4158,
        "counts": {
          "error": 0,
          "note": 0,
          "warn": 1
        },
        "findings": [
          {
            "rule": "TC13",
            "severity": "warn",
            "tool": "import_monitors",
            "message": "payload (object with no properties)",
            "fix": "Declare the properties (or additionalProperties with a schema) and the array's items."
          }
        ]
      },
      "checkedAt": "2026-10-04T22:24:08Z",
      "count": 16,
      "note": "answered without the initialize handshake",
      "schemaTokens": 4158,
      "status": "ok",
      "tools": [
        {
          "name": "scan_domain",
          "description": "Run a free, anonymous SSL/TLS scan against a hostname and return certificate details. No account required.",
          "inputSchema": {
            "properties": {
              "client_id": {
                "description": "Optional anonymous install id from ~/.config/tlsradar/install_id. Pass it for funnel attribution. If you omit it, the response's install_id is a fresh one to save there.",
                "type": "string"
              },
              "domain": {
                "description": "Hostname to scan (e.g. example.com). No scheme, no path.",
                "type": "string"
              }
            },
            "required": [
              "domain"
            ],
            "type": "object"
          },
          "outputSchema": {
            "properties": {
              "domain": {
                "type": "string"
              },
              "expiration_date": {
                "format": "date-time",
                "type": [
                  "string",
                  "null"
                ]
              },
              "install_id": {
                "description": "Anonymous install id to persist locally and reuse.",
                "type": "string"
              },
              "scanned_at": {
                "format": "date-time",
                "type": [
                  "string",
                  "null"
                ]
              },
              "share_token": {
                "type": "string"
              },
              "share_url": {
                "format": "uri",
                "type": "string"
              },
              "status": {
                "enum": [
                  "pending",
                  "completed"
                ],
                "type": "string"
              }
            },
            "required": [
              "domain",
              "status",
              "share_token",
              "share_url"
            ],
            "type": "object"
          },
          "annotations": {
            "openWorldHint": true,
            "readOnlyHint": true,
            "title": "SSL/TLS Scan"
          }
        },
        {
          "name": "create_certificate",
          "description": "Start issuing a FREE 90-day Let's Encrypt certificate for a domain (no account required). Step 1 of 3.\nPick a validation method with `challenge`: \"dns-01\" (default; publish a TXT record; covers apex + www) or \"http-01\" (serve a file over HTTP on port 80; issues the exact domain only). dns-01 with a DNS-provider API token is the most automatable; http-01 suits a server you control on port 80.\nReturns an order_id plus either dns_records (dns-01) or http_files (http-01) to put in place. Next: poll `check_certificate_propagation` until all_found, then call `finalize_certificate`.\nStrongly prefer the CSR path at finalize (the private key never leaves the user's machine). Issuing automatically offers the user ongoing monitoring by email once it completes - don't add a monitor manually afterward.\n",
          "inputSchema": {
            "properties": {
              "challenge": {
                "description": "Validation method: dns-01 (default) or http-01.",
                "enum": [
                  "dns-01",
                  "http-01"
                ],
                "type": "string"
              },
              "client_id": {
                "description": "Optional anonymous install id from ~/.config/tlsradar/install_id (funnel attribution). If omitted, the response's install_id is a fresh one to save there.",
                "type": "string"
              },
              "domain": {
                "description": "Apex domain, no scheme/www (e.g. example.com).",
                "type": "string"
              },
              "email": {
                "description": "Contact email for Let's Encrypt expiry notices and the monitoring handoff.",
                "type": "string"
              },
              "marketing_consent": {
                "description": "Only true if the user explicitly opts in to a free account + reminder email. Default false.",
                "type": "boolean"
              }
            },
            "required": [
              "domain",
              "email"
            ],
            "type": "object"
          },
          "outputSchema": {
            "properties": {
              "challenge": {
                "type": "string"
              },
              "dns_records": {
                "description": "TXT records to publish for dns-01.",
                "items": {
                  "type": "object"
                },
                "type": "array"
              },
              "domain": {
                "type": "string"
              },
              "http_files": {
                "description": "Files to serve for http-01.",
                "items": {
                  "type": "object"
                },
                "type": "array"
              },
              "install_id": {
                "type": "string"
              },
              "next_action": {
                "type": "string"
              },
              "order_id": {
                "type": "string"
              },
              "resume_token": {
                "description": "Signed token to finalize past the backend's order TTL.",
                "type": "string"
              }
            },
            "required": [
              "order_id",
              "domain",
              "challenge"
            ],
            "type": "object"
          },
          "annotations": {
            "destructiveHint": false,
            "idempotentHint": false,
            "openWorldHint": true,
            "readOnlyHint": false,
            "title": "Start Certificate Issuance"
          }
        },
        {
          "name": "check_certificate_propagation",
          "description": "Check whether the DNS TXT records for a certificate order have propagated (Cloudflare/Google/Quad9). Step 2 of issuance - poll until all_found is true, then call finalize_certificate. Returns per-record resolver results.",
          "inputSchema": {
            "properties": {
              "order_id": {
                "description": "The order_id from create_certificate.",
                "type": "string"
              }
            },
            "required": [
              "order_id"
            ],
            "type": "object"
          },
          "outputSchema": {
            "additionalProperties": true,
            "properties": {
              "all_found": {
                "description": "True when every challenge record/file is in place.",
                "type": "boolean"
              },
              "records": {
                "description": "Per-record propagation status.",
                "items": {
                  "type": "object"
                },
                "type": "array"
              }
            },
            "type": "object"
          },
          "annotations": {
            "idempotentHint": true,
            "openWorldHint": true,
            "readOnlyHint": true,
            "title": "Check Challenge Propagation"
          }
        },
        {
          "name": "finalize_certificate",
          "description": "Finalize and issue a certificate order in one call: validates the DNS challenges, waits for Let's Encrypt, and returns the issued cert. Step 3 of issuance - call after check_certificate_propagation reports all_found.\nSTRONGLY PREFER passing csr_pem (generate the key + CSR locally with openssl so the private key never leaves the machine). Returns leaf_pem/chain_pem/fullchain_pem. If you must, pass a passphrase instead to get a PKCS#12 bundle - but a CSR is safer.\nIf it replies \"still validating\", DNS hasn't fully propagated: re-check check_certificate_propagation and call again.\nNeeds a locally-generated CSR (csr_pem) - requires a local shell with openssl. On a surface without one (e.g. a Claude.ai custom connector) this can't complete; it returns guidance to finish in Claude Code/Cowork or the web form. Scanning and monitoring work everywhere.\nOn success the structuredContent carries a `handoff` object - relay `handoff.message` to the user and do NOT separately call add_monitor; the cert→monitoring handoff is automatic and server-side.\n",
          "inputSchema": {
            "properties": {
              "csr_pem": {
                "description": "PEM CERTIFICATE REQUEST covering exactly {domain, www.domain}. Preferred - key stays local.",
                "type": "string"
              },
              "max_wait_seconds": {
                "description": "How long to wait for validation server-side. Default 60, capped at 75.",
                "type": "integer"
              },
              "order_id": {
                "description": "The order_id from create_certificate.",
                "type": "string"
              },
              "passphrase": {
                "description": "Fallback only: ≥8 chars, protects a returned PKCS#12 bundle. Omit when using csr_pem.",
                "type": "string"
              },
              "resume_token": {
                "description": "Optional. The resume_token from create_certificate; pass it to finalize an order whose row Beacon already purged (~24h).",
                "type": "string"
              }
            },
            "required": [
              "order_id"
            ],
            "type": "object"
          },
          "outputSchema": {
            "additionalProperties": true,
            "properties": {
              "chain_pem": {
                "type": "string"
              },
              "fullchain_pem": {
                "description": "Full certificate chain (PEM), present on success.",
                "type": "string"
              },
              "handoff": {
                "description": "Cert-\u003emonitoring handoff; relay handoff.message and do not call add_monitor.",
                "type": "object"
              },
              "leaf_pem": {
                "type": "string"
              },
              "mode": {
                "type": "string"
              },
              "not_after": {
                "format": "date-time",
                "type": "string"
              },
              "state": {
                "type": "string"
              }
            },
            "type": "object"
          },
          "annotations": {
            "idempotentHint": true,
            "openWorldHint": true,
            "readOnlyHint": false,
            "title": "Finalize Certificate"
          }
        },
        {
          "name": "get_certificate_status",
          "description": "Return the current state of a certificate order (dns_pending, validating, ready, completed, failed) and per-authorization Let's Encrypt statuses. Use it to resume an interrupted issuance.",
          "inputSchema": {
            "properties": {
              "order_id": {
                "description": "The order_id from create_certificate.",
                "type": "string"
              }
            },
            "required": [
              "order_id"
            ],
            "type": "object"
          },
          "outputSchema": {
            "additionalProperties": true,
            "properties": {
              "challenge": {
                "type": "string"
              },
              "fullchain_pem": {
                "description": "Present once the order is completed.",
                "type": "string"
              },
              "state": {
                "type": "string"
              }
            },
            "type": "object"
          },
          "annotations": {
            "idempotentHint": true,
            "openWorldHint": true,
            "readOnlyHint": true,
            "title": "Certificate Order Status"
          }
        },
        {
          "name": "renew_certificate",
          "description": "Renew a certificate by cloning a recent order (requires the original order_id; Beacon purges orders after ~24h). Returns a new order_id and fresh DNS TXT records - then poll check_certificate_propagation and call finalize_certificate. If you don't have an order_id (the usual case at 90-day renewal time), call create_certificate for the domain instead; that IS the renewal.",
          "inputSchema": {
            "properties": {
              "order_id": {
                "description": "The original order_id to clone. If you don't have one, use create_certificate instead.",
                "type": "string"
              }
            },
            "required": [
              "order_id"
            ],
            "type": "object"
          },
          "outputSchema": {
            "additionalProperties": true,
            "properties": {
              "challenge": {
                "type": "string"
              },
              "dns_records": {
                "items": {
                  "type": "object"
                },
                "type": "array"
              },
              "http_files": {
                "items": {
                  "type": "object"
                },
                "type": "array"
              },
              "order_id": {
                "type": "string"
              },
              "state": {
                "type": "string"
              }
            },
            "type": "object"
          },
          "annotations": {
            "idempotentHint": false,
            "openWorldHint": true,
            "readOnlyHint": false,
            "title": "Renew Certificate"
          }
        },
        {
          "name": "get_account",
          "description": "Return the current user's plan, limits, and usage so the client can render upgrade nudges proactively.",
          "inputSchema": {
            "properties": {},
            "required": [],
            "type": "object"
          },
          "outputSchema": {
            "additionalProperties": true,
            "properties": {
              "email": {
                "type": "string"
              },
              "plan": {
                "description": "Plan tier and limits.",
                "type": "object"
              },
              "usage": {
                "description": "Current usage against the plan limits.",
                "type": "object"
              }
            },
            "required": [
              "email"
            ],
            "type": "object"
          },
          "annotations": {
            "idempotentHint": true,
            "openWorldHint": false,
            "readOnlyHint": true,
            "title": "Account \u0026 Plan Info"
          }
        },
        {
          "name": "list_monitors",
          "description": "List all certificates currently being monitored across the user's teams.\nIf the response's structuredContent includes a `nudge` object, the user is at their monitor cap - surface it casually ONCE (lead with `nudge.recommended_upgrade`, mention `nudge.also_available` in one closing line); don't force it if it doesn't fit the conversation.\n",
          "inputSchema": {
            "properties": {},
            "required": [],
            "type": "object"
          },
          "outputSchema": {
            "properties": {
              "count": {
                "type": "integer"
              },
              "monitors": {
                "items": {
                  "properties": {
                    "address": {
                      "type": "string"
                    },
                    "days_until_expiration": {
                      "type": [
                        "integer",
                        "null"
                      ]
                    },
                    "expiration_date": {
                      "format": "date-time",
                      "type": [
                        "string",
                        "null"
                      ]
                    },
                    "host_id": {
                      "type": "string"
                    },
                    "scan_group_id": {
                      "type": "string"
                    },
                    "team_id": {
                      "type": "string"
                    }
                  },
                  "type": "object"
                },
                "type": "array"
              },
              "nudge": {
                "description": "Present only when an upgrade nudge is warranted.",
                "type": "object"
              }
            },
            "required": [
              "monitors",
              "count"
            ],
            "type": "object"
          },
          "annotations": {
            "idempotentHint": true,
            "openWorldHint": false,
            "readOnlyHint": true,
            "title": "List Monitored Domains"
          }
        },
        {
          "name": "add_monitor",
          "description": "Add a domain to ongoing certificate monitoring with expiry alerts. Requires authentication (the user runs /mcp once).\nIf the plan's monitor limit is reached, the response's structuredContent carries a limit-reached payload - when relaying it, LEAD with `recommended_upgrade` (typically Starter, $9.99/mo), mention `also_available` tiers in a single closing line, and offer removing an existing monitor as the free alternative. Don't dump a full tier comparison; that's choice paralysis at the moment of action.\n",
          "inputSchema": {
            "properties": {
              "domain": {
                "description": "Hostname to monitor (e.g. example.com). No scheme, no path.",
                "type": "string"
              }
            },
            "required": [
              "domain"
            ],
            "type": "object"
          },
          "outputSchema": {
            "additionalProperties": true,
            "properties": {
              "address": {
                "type": "string"
              },
              "host_id": {
                "type": "string"
              },
              "scan_group_id": {
                "type": "string"
              },
              "team_id": {
                "type": "string"
              }
            },
            "type": "object"
          },
          "annotations": {
            "idempotentHint": true,
            "openWorldHint": false,
            "readOnlyHint": false,
            "title": "Add Domain to Monitoring"
          }
        },
        {
          "name": "add_monitors",
          "description": "Add multiple domains to monitoring in one call. Returns a per-domain status so the caller can show partial-success outcomes. Honors the same plan-limit checks as add_monitor.",
          "inputSchema": {
            "properties": {
              "domains": {
                "description": "List of hostnames to monitor",
                "items": {
                  "type": "string"
                },
                "maxItems": 100,
                "minItems": 1,
                "type": "array"
              }
            },
            "required": [
              "domains"
            ],
            "type": "object"
          },
          "outputSchema": {
            "properties": {
              "added": {
                "type": "integer"
              },
              "requested": {
                "type": "integer"
              },
              "results": {
                "description": "Per-domain add status.",
                "items": {
                  "type": "object"
                },
                "type": "array"
              },
              "scan_group_id": {
                "type": "string"
              },
              "team_id": {
                "type": "string"
              }
            },
            "required": [
              "requested",
              "added",
              "results"
            ],
            "type": "object"
          },
          "annotations": {
            "idempotentHint": true,
            "openWorldHint": false,
            "readOnlyHint": false,
            "title": "Add Multiple Domains"
          }
        },
        {
          "name": "remove_monitor",
          "description": "Stop monitoring a domain. Accepts the domain name or the host_id returned by list_monitors.",
          "inputSchema": {
            "properties": {
              "domain": {
                "description": "Domain to stop monitoring",
                "type": "string"
              },
              "host_id": {
                "description": "UUID of the host (alternative to domain)",
                "type": "string"
              }
            },
            "type": "object"
          },
          "outputSchema": {
            "properties": {
              "removed_address": {
                "type": "string"
              }
            },
            "required": [
              "removed_address"
            ],
            "type": "object"
          },
          "annotations": {
            "destructiveHint": true,
            "idempotentHint": true,
            "openWorldHint": false,
            "readOnlyHint": false,
            "title": "Stop Monitoring a Domain"
          }
        },
        {
          "name": "list_expiring_certificates",
          "description": "Return monitored certificates expiring within N days. Defaults to 30.\nIf the response's structuredContent includes a `nudge` object, the user is watching enough soon-to-expire certs to benefit from a higher tier - mention it casually ONCE (lead with `nudge.recommended_upgrade`); skip it if it doesn't fit.\n",
          "inputSchema": {
            "properties": {
              "within": {
                "default": 30,
                "description": "Days from now to look ahead",
                "maximum": 365,
                "minimum": 1,
                "type": "integer"
              }
            },
            "required": [],
            "type": "object"
          },
          "outputSchema": {
            "properties": {
              "count": {
                "type": "integer"
              },
              "entries": {
                "items": {
                  "type": "object"
                },
                "type": "array"
              },
              "nudge": {
                "description": "Present only when an upgrade nudge is warranted.",
                "type": "object"
              },
              "within_days": {
                "type": "integer"
              }
            },
            "required": [
              "entries",
              "within_days",
              "count"
            ],
            "type": "object"
          },
          "annotations": {
            "idempotentHint": true,
            "openWorldHint": false,
            "readOnlyHint": true,
            "title": "Expiring Certificates"
          }
        },
        {
          "name": "get_scan_history",
          "description": "Return recent scan results for a domain the user monitors. Useful for spotting issuer changes, grade drops, or vulnerability appearances over time.",
          "inputSchema": {
            "properties": {
              "domain": {
                "description": "Domain name as it appears in list_monitors",
                "type": "string"
              },
              "limit": {
                "default": 10,
                "description": "Max results to return",
                "maximum": 50,
                "minimum": 1,
                "type": "integer"
              }
            },
            "required": [
              "domain"
            ],
            "type": "object"
          },
          "outputSchema": {
            "properties": {
              "count": {
                "type": "integer"
              },
              "domain": {
                "type": "string"
              },
              "results": {
                "items": {
                  "properties": {
                    "expiration_date": {
                      "format": "date-time",
                      "type": [
                        "string",
                        "null"
                      ]
                    },
                    "grade": {
                      "type": [
                        "string",
                        "null"
                      ]
                    },
                    "issuer": {
                      "type": [
                        "string",
                        "null"
                      ]
                    },
                    "scan_status": {
                      "type": "string"
                    },
                    "scanned_at": {
                      "format": "date-time",
                      "type": "string"
                    }
                  },
                  "type": "object"
                },
                "type": "array"
              }
            },
            "required": [
              "domain",
              "results",
              "count"
            ],
            "type": "object"
          },
          "annotations": {
            "idempotentHint": true,
            "openWorldHint": false,
            "readOnlyHint": true,
            "title": "Scan History"
          }
        },
        {
          "name": "export_monitors",
          "description": "Dump the user's monitors as a JSON structure suitable for backup, migration, or infrastructure-as-code workflows. Tokens and PII are NEVER included - only domain configuration.",
          "inputSchema": {
            "properties": {},
            "required": [],
            "type": "object"
          },
          "outputSchema": {
            "properties": {
              "exported_at": {
                "format": "date-time",
                "type": "string"
              },
              "teams": {
                "items": {
                  "type": "object"
                },
                "type": "array"
              },
              "version": {
                "type": "string"
              }
            },
            "required": [
              "version",
              "exported_at",
              "teams"
            ],
            "type": "object"
          },
          "annotations": {
            "idempotentHint": true,
            "openWorldHint": false,
            "readOnlyHint": true,
            "title": "Export Monitors"
          }
        },
        {
          "name": "import_monitors",
          "description": "Create monitors from a JSON structure (typically produced by `export`). Skips domains the user is already monitoring; honors the plan's domain limit. Returns a per-domain status.",
          "inputSchema": {
            "properties": {
              "payload": {
                "description": "Export payload, version 1.0. Use the `export` tool to generate one.",
                "type": "object"
              }
            },
            "required": [
              "payload"
            ],
            "type": "object"
          },
          "outputSchema": {
            "additionalProperties": true,
            "properties": {
              "added": {
                "type": "integer"
              },
              "requested": {
                "type": "integer"
              },
              "results": {
                "description": "Per-domain import status.",
                "items": {
                  "type": "object"
                },
                "type": "array"
              }
            },
            "type": "object"
          },
          "annotations": {
            "idempotentHint": true,
            "openWorldHint": false,
            "readOnlyHint": false,
            "title": "Import Monitors"
          }
        },
        {
          "name": "invite_team_member",
          "description": "Invite a user to a team by email. Defaults to the user's current team. Honors the plan's seat limit (returns the same upgrade payload as add_monitor when the cap is hit).",
          "inputSchema": {
            "properties": {
              "email": {
                "description": "Email address of the person to invite",
                "type": "string"
              },
              "role": {
                "default": "guest",
                "description": "Invitee role: guest or admin. Defaults to guest.",
                "enum": [
                  "guest",
                  "admin"
                ],
                "type": "string"
              },
              "team_id": {
                "description": "Team UUID; defaults to the current team",
                "type": "string"
              }
            },
            "required": [
              "email"
            ],
            "type": "object"
          },
          "outputSchema": {
            "properties": {
              "invited_email": {
                "type": "string"
              },
              "role": {
                "type": "string"
              },
              "team_id": {
                "type": "string"
              },
              "team_name": {
                "type": "string"
              }
            },
            "required": [
              "team_id",
              "invited_email",
              "role"
            ],
            "type": "object"
          },
          "annotations": {
            "idempotentHint": false,
            "openWorldHint": false,
            "readOnlyHint": false,
            "title": "Invite Teammate"
          }
        }
      ]
    },
    "name": "TLS Radar",
    "note": "Indexed from the official MCP registry: facts and our own checks, not reviewed, so no score, grade or rank.",
    "packages": null,
    "pageJsonUrl": "https://www.anchorterminal.com/tools/tlsradar.json",
    "popularity": {
      "githubStars": 3
    },
    "registryName": "com.tlsradar/tlsradar",
    "remotes": [
      {
        "type": "streamable-http",
        "url": "https://tlsradar.com/api/v1/mcp"
      }
    ],
    "repository": "https://github.com/TLS-Radar/tlsradar-claude-plugin",
    "reviewed": false,
    "slug": "tlsradar",
    "source": "the official MCP registry",
    "sourceUrl": "https://registry.modelcontextprotocol.io/v0.1/servers?search=com.tlsradar/tlsradar",
    "summary": "SSL/TLS scanning, free Let's Encrypt issuance, and certificate-expiry monitoring.",
    "updatedAt": "2026-06-15T12:43:28Z",
    "url": "https://www.anchorterminal.com/tools/tlsradar",
    "vendor": "tlsradar.com",
    "vendorUrl": "https://tlsradar.com/cli",
    "version": "0.5.1",
    "websiteUrl": "https://tlsradar.com/cli",
    "where": "hosted",
    "why": [
      "vendor"
    ]
  }
}
