Discontinued

This API no longer responds. Our last check on 2026-07-31 found no working endpoint — the service appears to have shut down or moved. The documentation, code samples and score below are kept for reference only; do not build against this API. See working Security APIs →

Mozilla tls scanner API

Free to Use

Overview

The Mozilla TLS Scanner API lets you check the TLS/SSL configuration of any public domain. It tests for common security issues like weak cipher suites, certificate problems, and protocol misconfigurations. This is a great tool for learning what makes HTTPS connections secure or vulnerable.

Beginner Tip

Submit a scan with a POST request, then poll the GET endpoint with the returned scan ID until the scan status is "finished" — results usually arrive within 10-30 seconds.

Available Data

The kind of data this API exposes, based on its documentation. We could not call the endpoint to confirm the exact field names.

Use case: Integrate mozilla observatory tls scanner data into web and mobile applications
Mozilla tls scanner data via REST API

Example Response

Illustrative shape only — we were not able to call this endpoint (it requires credentials or exposes no public sample URL), so the fields below show the kind of data this API returns rather than a recorded response.

JSON Response · Illustrative
{
  "status": "success",
  "data": {
    "result": "Data from Mozilla tls scanner",
    "description": "Mozilla observatory tls scanner",
    "timestamp": "2025-01-15T10:00:00Z"
  }
}

Field Reference

id Unique scan ID used to retrieve results.
target The domain name that was scanned.
status Current scan status: "pending", "running", or "finished".
has_tls Whether the target supports TLS/HTTPS.
cert_id Internal ID for the TLS certificate found on the target.
analysis List of analyzer results detailing specific TLS checks and their pass/fail status.

Implementation Example

Calls a real endpoint of this API. Replace any placeholder credentials with your own key.

Request
const url = "https://tls-observatory.services.mozilla.com/api/v1/run?target=example.com";
const response = await fetch(url);
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();
console.log(data);

What Can You Build?

Note: These code examples are AI-generated and unverified. Always refer to the official API documentation for accurate usage.

Common Errors & Troubleshooting

Generated guidance based on this API's documentation, not observed by us. Treat it as a starting point and check against the provider's own error reference.

Scan result shows status "pending" TLS scans take time; the result is not ready immediately after submitting.
Use the scan ID to poll GET /api/v1/results?id=<scanID> in a loop until status is "finished".
400 Bad Request The target domain parameter is missing or malformed.
Ensure the query string uses ?target=yourdomain.com with a valid hostname (no http:// prefix).
Empty or unexpected response The domain may be unreachable or the observatory backend is overloaded.
Verify the domain resolves publicly and retry after a short wait.

Metadata Score Breakdown

Estimated from metadata — endpoint not independently tested

This score is estimated from observable metadata — HTTPS support, authentication model, declared CORS, and documentation reachability — because the API requires authentication or exposes no publicly testable endpoint. The five-signal breakdown is only shown for live-tested APIs.

Metadata estimate · endpoint not independently tested

Technical Specifications

Auth No Auth
HTTPS REQUIRED
CORS UNKNOWN
Category Security
Difficulty Beginner
Listing details not endpoint-verified

Related Tags

Similar APIs

View All →