APIFreaks - API Hub for Developers SSL APIs API

The SSL APIs API from APIFreaks - API Hub for Developers — 2 operation(s) for ssl apis.

OpenAPI Specification

apifreaks-api-hub-for-developers-ssl-apis-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Apifreaks Api Hub For Developers SSL APIs API
  version: 1.0.0
  contact:
    name: APIFreaks Support
    url: https://apifreaks.com/contact
    email: support@apifreaks.com
  description: 'Operations tagged SSL APIs across 2 of this provider''s published API definitions: apifreaks-api-hub-for-developers-ssl-certificate-chain-lookup-openapi.json, apifreaks-api-hub-for-developers-ssl-certificate-lookup-openapi.json. Each path carries the servers of the definition it was published in.'
servers:
- url: https://api.apifreaks.com/v1.0
  description: SSL Certificate Chain Lookup API Server
security:
- ApiKeyAuthHeader: []
- ApiKeyAuthQuery: []
tags:
- name: SSL APIs
paths:
  /domain/ssl/live/chain:
    servers:
    - url: https://api.apifreaks.com/v1.0
      description: SSL Certificate Chain Lookup API Server
    get:
      tags:
      - SSL APIs
      summary: Retrieve all certificates from the domain to the root Certificate Authority (CA) of a domain.
      description: 'Retrieve the complete SSL certificate chain from root Certificate Authority (CA) to end-user certificate.

        This endpoint provides comprehensive information about each certificate in the chain.

        '
      operationId: sslCertificateChainLookup
      parameters:
      - name: format
        in: query
        required: false
        schema:
          type: string
          enum:
          - json
          - xml
          default: json
        description: Format of the response.
      - name: domainName
        in: query
        required: true
        schema:
          type: string
        description: Domain name or URL whose SSL certificate chain lookup is required
      - name: sslRaw
        in: query
        required: false
        schema:
          type: boolean
        description: Set to true to get the raw openSSL response for each certificate in the chain
      responses:
        '200':
          description: Successful SSL certificate chain lookup response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SSLLookupResponse'
              examples:
                SSL Certificate Chain:
                  value:
                    domainName: google.com
                    queryTime: '2026-06-06 14:58:45'
                    sslCertificates:
                    - chainOrder: end-user
                      authenticationType: domain
                      validityStartDate: 2026-06-2 06:23:03 UTC
                      validityEndDate: 2026-08-31 07:21:11 UTC
                      serialNumber: 7b:75:1c:fe:fb:bb:95:33:0e:e2:a1:6b:9e:89:e1:b7
                      signatureAlgorithm: ECDSA-SHA256
                      subject:
                        commonName: '*.google.com'
                      issuer:
                        commonName: WE1
                        organization: Google Trust Services
                        country: US
                      publicKey:
                        keySize: 256 bit
                        keyAlgorithm: ECDSA
                        pemRaw: '-----BEGIN PUBLIC KEY-----

                          MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAELD2RK4J04b+CkgML4RrJmWd482WIxr61Nq21HpA9c9G5ou6PsaIEhrESlu6xMHM+ucHh/0jQArZwnb8F0YwXZw==

                          -----END PUBLIC KEY-----

                          '
                      extensions:
                        authorityKeyIdentifier: 90:77:92:35:67:C4:FF:A8:CC:A9:E6:7B:D9:80:79:7B:CC:93:F9:38
                        subjectKeyIdentifier: 6D:E0:94:E7:A4:F4:43:F1:20:17:0E:81:FC:C4:91:4D:18:A0:C9:2F
                        keyUsages:
                        - Digital Signature
                        extendedKeyUsages:
                        - TLS Web Server Authentication
                        crlDistributionPoints:
                        - http://c.pki.goog/we1/R7LgAnKD4Lk.crl
                        authorityInfoAccess:
                          issuers:
                          - http://i.pki.goog/we1.crt
                          ocsp:
                          - http://o.pki.goog/s/we1/e3U
                        subjectAlternativeNames:
                          dnsNames:
                          - '*.google.com'
                          - google.com
                        certificatePolicies:
                        - policyId: 2.23.140.1.2.1
                      pemRaw: '-----BEGIN CERTIFICATE-----

                        MIIDpDCCA0mgAwIBAgIQe3Uc/vu7lTMO4qFrnonhtzAKBggqhkjOPQQDAjA7MQswCQYDVQQGEwJVUzEeMBwGA1UEChMVR29vZ2xlIFRydXN0IFNlcnZpY2VzMQwwCgYDVQQDEwNXRTEwHhcNMjYwNjAyMDYyMzAzWhcNMjYwODMxMDcyMTExWjAWMRQwEgYDVQQDEwtqZnJlYWtzLmNvbTBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABCw9kSuCdOG/gpIDC+EayZlnePNliMa+tTattR6QPXPRuaLuj7GiBIaxEpbusTBzPrnB4f9I0AK2cJ2/BdGMF2ejggJSMIICTjAOBgNVHQ8BAf8EBAMCB4AwEwYDVR0lBAwwCgYIKwYBBQUHAwEwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUbeCU56T0Q/EgFw6B/MSRTRigyS8wHwYDVR0jBBgwFoAUkHeSNWfE/6jMqeZ72YB5e8yT+TgwXgYIKwYBBQUHAQEEUjBQMCcGCCsGAQUFBzABhhtodHRwOi8vby5wa2kuZ29vZy9zL3dlMS9lM1UwJQYIKwYBBQUHMAKGGWh0dHA6Ly9pLnBraS5nb29nL3dlMS5jcnQwJQYDVR0RBB4wHIILamZyZWFrcy5jb22CDSouamZyZWFrcy5jb20wEwYDVR0gBAwwCjAIBgZngQwBAgEwNgYDVR0fBC8wLTAroCmgJ4YlaHR0cDovL2MucGtpLmdvb2cvd2UxL1I3TGdBbktENExrLmNybDCCAQMGCisGAQQB1nkCBAIEgfQEgfEA7wB2AJROQ4f67MHvgfMZJCaoGGUBx9NfOAIBP3JnfVU3LhnYAAABnoc27FIAAAQDAEcwRQIhAN5bVfN6osVhMW6F32m52+fRsNf6yDQIhXfHZ3S0DXK7AiBdVp3hQqIjM/TpSynLnZJ5W6Ng4Pd5WjRZtZP8wtNBmAB1ANgJVTuUT3r/yBYZb5RPhauw+Pxeh1UmDxXRLnK7RUsUAAABnoc27IUAAAQDAEYwRAIgZ4Hn/21EyS31ZoYWNiIbIbfnSWvnTTzMBGUzkPXa7E4CIChvO8tx+1vcNhmO2/qpE5pwLTIpeqwKH9+OvGdfoa4pMAoGCCqGSM49BAMCA0kAMEYCIQDL0J1LBJszJdu9uQJi5roRavn8KzuiC0caVQ9KxB1LzQIhAL16BeuNfUXnQ0JxUMiVXIWmKz7QoiLImDBS1+b+ZvJP

                        -----END CERTIFICATE-----

                        '
                    - chainOrder: intermediate
                      authenticationType: organization
                      validityStartDate: 2023-12-13 09:00:00 UTC
                      validityEndDate: 2029-02-20 14:00:00 UTC
                      serialNumber: 7f:f3:19:77:97:2c:22:4a:76:15:5d:13:b6:d6:85:e3
                      signatureAlgorithm: ECDSA-SHA2384
                      subject:
                        commonName: WE1
                        organization: Google Trust Services
                        country: US
                      issuer:
                        commonName: GTS Root R4
                        organization: Google Trust Services LLC
                        country: US
                      publicKey:
                        keySize: 256 bit
                        keyAlgorithm: ECDSA
                        pemRaw: '-----BEGIN PUBLIC KEY-----

                          MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEb806/mdXR0whA4VAwkddu1hHD0DBXBeFxhk359V87YZLm4HZ1xoTpQoD+JjExuie/xBZjywmmPXmJiW7DwL6Vg==

                          -----END PUBLIC KEY-----

                          '
                      extensions:
                        authorityKeyIdentifier: 80:4C:D6:EB:74:FF:49:36:A3:D5:D8:FC:B5:3E:C5:6A:F0:94:1D:8C
                        subjectKeyIdentifier: 90:77:92:35:67:C4:FF:A8:CC:A9:E6:7B:D9:80:79:7B:CC:93:F9:38
                        keyUsages:
                        - CRL Sign
                        - Digital Signature
                        - Certificate Sign
                        extendedKeyUsages:
                        - TLS Web Server Authentication
                        - TLS Web Client Authentication
                        crlDistributionPoints:
                        - http://c.pki.goog/r/r4.crl
                        authorityInfoAccess:
                          issuers:
                          - http://i.pki.goog/r4.crt
                        certificatePolicies:
                        - policyId: 2.23.140.1.2.1
                      pemRaw: '-----BEGIN CERTIFICATE-----

                        MIICnzCCAiWgAwIBAgIQf/MZd5csIkp2FV0TttaF4zAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjQwHhcNMjMxMjEzMDkwMDAwWhcNMjkwMjIwMTQwMDAwWjA7MQswCQYDVQQGEwJVUzEeMBwGA1UEChMVR29vZ2xlIFRydXN0IFNlcnZpY2VzMQwwCgYDVQQDEwNXRTEwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAARvzTr+Z1dHTCEDhUDCR127WEcPQMFcF4XGGTfn1XzthkubgdnXGhOlCgP4mMTG6J7/EFmPLCaY9eYmJbsPAvpWo4H+MIH7MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQUkHeSNWfE/6jMqeZ72YB5e8yT+TgwHwYDVR0jBBgwFoAUgEzW63T/STaj1dj8tT7FavCUHYwwNAYIKwYBBQUHAQEEKDAmMCQGCCsGAQUFBzAChhhodHRwOi8vaS5wa2kuZ29vZy9yNC5jcnQwKwYDVR0fBCQwIjAgoB6gHIYaaHR0cDovL2MucGtpLmdvb2cvci9yNC5jcmwwEwYDVR0gBAwwCjAIBgZngQwBAgEwCgYIKoZIzj0EAwMDaAAwZQIxAOcCq1HW90OVznX+0RGU1cxAQXomvtgM8zItPZCuFQ8jSBJSjz5keROv9aYsAm5VsQIwJonMaAFi54mrfhfoFNZEfuNMSQ6/bIBiNLiyoX46FohQvKeIoJ99cx7sUkFN7uJW

                        -----END CERTIFICATE-----

                        '
                    - chainOrder: intermediate
                      authenticationType: organization
                      validityStartDate: 2023-11-15 03:43:21 UTC
                      validityEndDate: 2028-01-28 00:00:42 UTC
                      serialNumber: 7f:e5:30:bf:33:13:43:be:dd:82:16:10:49:3d:8a:1b
                      signatureAlgorithm: SHA256-RSA
                      subject:
                        commonName: GTS Root R4
                        organization: Google Trust Services LLC
                        country: US
                      issuer:
                        commonName: GlobalSign Root CA
                        organization: GlobalSign nv-sa
                        organizationalUnit: Root CA
                        country: BE
                      publicKey:
                        keySize: 384 bit
                        keyAlgorithm: ECDSA
                        pemRaw: '-----BEGIN PUBLIC KEY-----

                          MHYwEAYHKoZIzj0CAQYFK4EEACIDYgAE83Rzp2iLYK5DuDXFgTB7S0md+8FhzubeRr1r1WEYNa5A3XP3iZEwWus87oV8okB2O6nGuEfYKueSkWpz6bFyOZ8pn6KY019eWIZlD6GEZQbR3IvJx3PIjGov5cSr0R2K

                          -----END PUBLIC KEY-----

                          '
                      extensions:
                        authorityKeyIdentifier: 60:7B:66:1A:45:0D:97:CA:89:50:2F:7D:04:CD:34:A8:FF:FC:FD:4B
                        subjectKeyIdentifier: 80:4C:D6:EB:74:FF:49:36:A3:D5:D8:FC:B5:3E:C5:6A:F0:94:1D:8C
                        keyUsages:
                        - CRL Sign
                        - Digital Signature
                        - Certificate Sign
                        extendedKeyUsages:
                        - TLS Web Server Authentication
                        - TLS Web Client Authentication
                        crlDistributionPoints:
                        - http://c.pki.goog/r/gsr1.crl
                        authorityInfoAccess:
                          issuers:
                          - http://i.pki.goog/gsr1.crt
                        certificatePolicies:
                        - policyId: 2.23.140.1.2.1
                      pemRaw: '-----BEGIN CERTIFICATE-----

                        MIIDejCCAmKgAwIBAgIQf+UwvzMTQ77dghYQST2KGzANBgkqhkiG9w0BAQsFADBXMQswCQYDVQQGEwJCRTEZMBcGA1UEChMQR2xvYmFsU2lnbiBudi1zYTEQMA4GA1UECxMHUm9vdCBDQTEbMBkGA1UEAxMSR2xvYmFsU2lnbiBSb290IENBMB4XDTIzMTExNTAzNDMyMVoXDTI4MDEyODAwMDA0MlowRzELMAkGA1UEBhMCVVMxIjAgBgNVBAoTGUdvb2dsZSBUcnVzdCBTZXJ2aWNlcyBMTEMxFDASBgNVBAMTC0dUUyBSb290IFI0MHYwEAYHKoZIzj0CAQYFK4EEACIDYgAE83Rzp2iLYK5DuDXFgTB7S0md+8FhzubeRr1r1WEYNa5A3XP3iZEwWus87oV8okB2O6nGuEfYKueSkWpz6bFyOZ8pn6KY019eWIZlD6GEZQbR3IvJx3PIjGov5cSr0R2Ko4H/MIH8MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUgEzW63T/STaj1dj8tT7FavCUHYwwHwYDVR0jBBgwFoAUYHtmGkUNl8qJUC99BM00qP/8/UswNgYIKwYBBQUHAQEEKjAoMCYGCCsGAQUFBzAChhpodHRwOi8vaS5wa2kuZ29vZy9nc3IxLmNydDAtBgNVHR8EJjAkMCKgIKAehhxodHRwOi8vYy5wa2kuZ29vZy9yL2dzcjEuY3JsMBMGA1UdIAQMMAowCAYGZ4EMAQIBMA0GCSqGSIb3DQEBCwUAA4IBAQAYQrsPBtYDh5bjP2OBDwmkoWhIDDkic574y04tfzHpn+cJodI2D4SseesQ6bDrarZ7C30ddLibZatoKiws3UL9xnELz4ct92vID24FfVbiI1hY+SW6FoVHkNeWIP0GCbaM4C6uVdF5dTUsMVs/ZbzNnIdCp5Gxmx5ejvEau8otR/CskGN+hr/W5GvT1tMBjgWKZ1i4//emhA1JG1BbPzoLJQvyEotc03lXjTaCzv8mEbep8RqZ7a2CPsgRbuvTPBwcOMBBmuFeU88+FSBX6+7iP0il8b4Z0QFqIwwMHfs/L6K1vepuoxtGzi4CZ68zJpiq1UvSqTbFJjtbD4seiMHl

                        -----END CERTIFICATE-----

                        '
                    - chainOrder: root
                      authenticationType: self-signed-ca
                      validityStartDate: 2011-09-22 11:22:02 UTC
                      validityEndDate: 2030-09-22 11:22:02 UTC
                      serialNumber: 'Signature Algorithm: sha256WithRSAEncryption'
                      signatureAlgorithm: SHA256-RSA
                      subject:
                        commonName: Actalis Authentication Root CA
                        organization: Actalis S.p.A./03358520967
                        locality: Milan
                        country: IT
                      issuer:
                        commonName: Actalis Authentication Root CA
                        organization: Actalis S.p.A./03358520967
                        locality: Milan
                        country: IT
                      publicKey:
                        keySize: 4096 bit
                        keyAlgorithm: RSA
                        pemRaw: '-----BEGIN PUBLIC KEY-----

                          MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAp8bEpSmkLO/lGMWwUKNvUTufClrJwkg4CsIcoBh/kbWHuUA/3R1oHwiD1S0eiKD4j1aPbZkCkpAW1V8IbInX4ay8IMKx4INRimlNAJZaby/ARH6jDuSRzVju3PvHHkVH3Se5CAGfpiEd9UEtL0z9KK3giq0itFZljoZUj5NDKd45RnijMCO6zfB9E1fAXdKDa0hMxKufgFpbOr3JpyI/gCczWw63igxdBzcIy2zSekciRDXFzMwujt0q7bd9Zg1fYVEiVRvjRuPjPdA1YprbrxTIW6HMiRvhMCb8oJsfgadHHwTrozmSBp+Z07/T6k9QnBn+locePGX2oxgkg4YQ51Q+qDp2JE+BIcXjDwL4k5RHILv+1A7TaLndxHqEguNTVHnd25zS8gebLra8Pu2Fbe8lEfKXGkJh90qX6IuxEAf6ZYGyojnP9zz/GPvG8VqLWeICrHuS0E4UT1lF9gxeKF+w6D9Fz8+vm2/7hNN3WpVvrJSEnu68wEqPSpP4RCHiMUVhUE4Q2OM1fEwZtN4Fv6MGn8i1zeQf1xcGDXqVdFUNaBr8EBtiZJ1t4JWgw5QHVw0U5r0F+7if5t+L4sbnfpb2U8WANFAoWPASUHEXMLrmeGO89LKtmyuy/uE5jF66CyCU3nuDuP/jVo23Eek7jPKxwV2dpAtMK9myGPW1n0sCAwEAAQ==

                          -----END PUBLIC KEY-----

                          '
                      extensions:
                        authorityKeyIdentifier: 52:D8:88:3A:C8:9F:78:66:ED:89:F3:7B:38:70:94:C9:02:02:36:D0
                        subjectKeyIdentifier: 52:D8:88:3A:C8:9F:78:66:ED:89:F3:7B:38:70:94:C9:02:02:36:D0
                        keyUsages:
                        - CRL Sign
                        - Certificate Sign
                      pemRaw: '-----BEGIN CERTIFICATE-----

                        MIIFuzCCA6OgAwIBAgIIVwoRl0LE48wwDQYJKoZIhvcNAQELBQAwazELMAkGA1UEBhMCSVQxDjAMBgNVBAcMBU1pbGFuMSMwIQYDVQQKDBpBY3RhbGlzIFMucC5BLi8wMzM1ODUyMDk2NzEnMCUGA1UEAwweQWN0YWxpcyBBdXRoZW50aWNhdGlvbiBSb290IENBMB4XDTExMDkyMjExMjIwMloXDTMwMDkyMjExMjIwMlowazELMAkGA1UEBhMCSVQxDjAMBgNVBAcMBU1pbGFuMSMwIQYDVQQKDBpBY3RhbGlzIFMucC5BLi8wMzM1ODUyMDk2NzEnMCUGA1UEAwweQWN0YWxpcyBBdXRoZW50aWNhdGlvbiBSb290IENBMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAp8bEpSmkLO/lGMWwUKNvUTufClrJwkg4CsIcoBh/kbWHuUA/3R1oHwiD1S0eiKD4j1aPbZkCkpAW1V8IbInX4ay8IMKx4INRimlNAJZaby/ARH6jDuSRzVju3PvHHkVH3Se5CAGfpiEd9UEtL0z9KK3giq0itFZljoZUj5NDKd45RnijMCO6zfB9E1fAXdKDa0hMxKufgFpbOr3JpyI/gCczWw63igxdBzcIy2zSekciRDXFzMwujt0q7bd9Zg1fYVEiVRvjRuPjPdA1YprbrxTIW6HMiRvhMCb8oJsfgadHHwTrozmSBp+Z07/T6k9QnBn+locePGX2oxgkg4YQ51Q+qDp2JE+BIcXjDwL4k5RHILv+1A7TaLndxHqEguNTVHnd25zS8gebLra8Pu2Fbe8lEfKXGkJh90qX6IuxEAf6ZYGyojnP9zz/GPvG8VqLWeICrHuS0E4UT1lF9gxeKF+w6D9Fz8+vm2/7hNN3WpVvrJSEnu68wEqPSpP4RCHiMUVhUE4Q2OM1fEwZtN4Fv6MGn8i1zeQf1xcGDXqVdFUNaBr8EBtiZJ1t4JWgw5QHVw0U5r0F+7if5t+L4sbnfpb2U8WANFAoWPASUHEXMLrmeGO89LKtmyuy/uE5jF66CyCU3nuDuP/jVo23Eek7jPKxwV2dpAtMK9myGPW1n0sCAwEAAQaNjMGEwHQYDVR0OBBYEFFLYiDrIn3hm7YnzezhwlMkCAjbQMA8GA1UdEwEB/wQFMAMBAf8wHwYDVR0jBBgwFoAUUtiIOsifeGbtifN7OHCUyQICNtAwDgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4ICAQALe3KHwGCmSUyIWOYdiPcUZEim2FgKDk8TNd81HdTtBjHIgT5q1d07GjLukD0R0i70jsNjLiNmsGe+b7bAEzlgqqI0JZN1Ut6nna0Oh4lScWoWPBkdg/iaKWW+9D+a2fDzWochcYBNy+A4mz+7+uAwTc+G02UQGRjRlwKxK3JCaKygvU5a2hi/a5iB0P2avl4VSM0RFbnAKVy06Ij3Pjaut2L9HmLecHgQHEhb2rykOLpn7VU+Xlff1ANATIGk0k9jpwlCCRT8AKnCgHNPLsBA2RF7SOp6AsDT6ygBJlh0wcBzIm2Tlf05fbsq4/aC4yyXX04fkZT6/iyj2HYauE2yOE+b+h1IYHkm4vP9qdCa6HCPSXrW5b0KDtst842/6+OkfcvHlXHo2qN8xcL4dJIEG4aspCJTQLas/kx2z/uUMsA1n3Y/buWQbqCmJqK4LL7RK4X9p2jIugErsWx0Hbhzlefut8cl8ABMALJ+tguLHPPAUJ4lueAI3jZm/zel0btUZCzJJ7VLkn5l/9Mt4blOvH+kQSGQQXemOR/qnuOf0GZvBeyqdn6/axag67XH/JJULysRJyU3eExRarDzzFhdFPFqSBX/wge2sY0PjlxQRrM9vwGYT7JZVEc+NHt4bVaTLnPqZih4zR0Uv6CPLy64Lo7yFIrM6bV8+2ydDKXhl

                        -----END CERTIFICATE-----

                        '
        '400':
          description: Bad Request – Invalid domain parameter
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                Invalid Domain Param:
                  value:
                    timestamp: '2025-08-14T10:27:07.511Z'
                    status: 400
                    error: Invalid Param Exception
                    message: ' Please pass domain param correct value e.g. whoisfreaks.com, https://whoisfreaks.com, http://whoisfreaks.com [For Technical Support: support@apifreaks.com]'
                    path: /v1.0/domain/ssl/live/chain
        '403':
          description: Forbidden – Domain extension unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                Unavailable Domain Extension:
                  value:
                    timestamp: '2025-08-14T10:27:54.671Z'
                    status: 403
                    error: Forbidden
                    message: Unavailable domain extension.
                    path: /v1.0/domain/ssl/live/chain
        '404':
          description: Not Found – No SSL certificate exists
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                No SSL Certificate:
                  value:
                    timestamp: '2025-08-14T10:28:32.443Z'
                    status: 404
                    error: SSL Data Not Found
                    message: No Ssl Certificate exists for entered Domain
                    path: /v1.0/domain/ssl/live/chain
  /domain/ssl/live:
    servers:
    - url: https://api.apifreaks.com/v1.0
      description: SSL Certificate Lookup API Server
    get:
      tags:
      - SSL APIs
      summary: Retrieve the SSL certificate and any hidden information embedded within it for a domain.
      description: 'Retrieve comprehensive SSL certificate information without the certificate chain.

        This endpoint provides detailed information about the SSL certificate including expiry dates, issuer details, and encryption methods.

        '
      operationId: sslCertificateLookup
      parameters:
      - name: format
        in: query
        required: false
        schema:
          type: string
          enum:
          - json
          - xml
          default: json
        description: Format of the response.
      - name: domainName
        in: query
        required: true
        schema:
          type: string
        description: Domain name or URL whose SSL certificate lookup is required
      - name: sslRaw
        in: query
        required: false
        schema:
          type: boolean
        description: Set to true to get the raw openSSL response of the domain
      responses:
        '200':
          description: Successful SSL certificate lookup response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SSLLookupResponse_2'
              examples:
                Single SSL Certificate:
                  value:
                    domainName: google.com
                    queryTime: '2026-06-06 14:58:44'
                    sslCertificates:
                    - chainOrder: end-user
                      authenticationType: domain
                      validityStartDate: 2026-05-18 18:35:21 UTC
                      validityEndDate: 2026-08-10 18:35:20 UTC
                      serialNumber: d5:2a:59:68:49:a3:ce:9b:10:64:16:9b:c7:eb:df:4b
                      signatureAlgorithm: SHA256-RSA
                      subject:
                        commonName: '*.google.com'
                      issuer:
                        commonName: WR2
                        organization: Google Trust Services
                        country: US
                      publicKey:
                        keySize: 256 bit
                        keyAlgorithm: ECDSA
                        pemRaw: '-----BEGIN PUBLIC KEY-----

                          MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAErGwQHDlGZHg4bCpvaBQKF07hm4v6puRsRi7O6JQH78GTcBkGAHRZSLqvlH8K+wDBOiTKlDh3sWlmEJDUJDdoKA==

                          -----END PUBLIC KEY-----

                          '
                      extensions:
                        authorityKeyIdentifier: DE:1B:1E:ED:79:15:D4:3E:37:24:C3:21:BB:EC:34:39:6D:42:B2:30
                        subjectKeyIdentifier: 2E:EC:34:B9:3E:97:83:C3:7E:E5:D0:F4:AB:56:D4:25:99:67:7D:6B
                        keyUsages:
                        - Digital Signature
                        extendedKeyUsages:
                        - TLS Web Server Authentication
                        crlDistributionPoints:
                        - http://c.pki.goog/wr2/GSyT1N4PBrg.crl
                        authorityInfoAccess:
                          issuers:
                          - http://i.pki.goog/wr2.crt
                          ocsp:
                          - http://o.pki.goog/wr2
                        subjectAlternativeNames:
                          dnsNames:
                          - '*.google.com'
                          - google.com
                          - youtube.com
                          - '*.youtube.com'
                          - '*.ytimg.com'
                        certificatePolicies:
                        - policyId: 2.23.140.1.2.1
                      pemRaw: '-----BEGIN CERTIFICATE-----

                        MIIIdTCCB12gAwIBAgIRANUqWWhJo86bEGQWm8fr30swDQYJKoZIhvcNAQELBQAwOzELMAkGA1UEBhMCVVMxHjAcBgNVBAoTFUdvb2dsZSBUcnVzdCBTZXJ2aWNlczEMMAoGA1UEAxMDV1IyMB4XDTI2MDUxODE4MzUyMVoXDTI2MDgxMDE4MzUyMFowFzEVMBMGA1UEAwwMKi5nb29nbGUuY29tMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAErGwQHDlGZHg4bCpvaBQKF07hm4v6puRsRi7O6JQH78GTcBkGAHRZSLqvlH8K+wDBOiTKlDh3sWlmEJDUJDdoKKOCBmEwggZdMA4GA1UdDwEB/wQEAwIHgDATBgNVHSUEDDAKBggrBgEFBQcDATAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQu7DS5PpeDw37l0PSrVtQlmWd9azAfBgNVHSMEGDAWgBTeGx7teRXUPjckwyG77DQ5bUKyMDBYBggrBgEFBQcBAQRMMEowIQYIKwYBBQUHMAGGFWh0dHA6Ly9vLnBraS5nb29nL3dyMjAlBggrBgEFBQcwAoYZaHR0cDovL2kucGtpLmdvb2cvd3IyLmNydDCCBDgGA1UdEQSCBC8wggQrggwqLmdvb2dsZS5jb22CFiouYXBwZW5naW5lLmdvb2dsZS5jb22CCSouYmRuLmRldoIVKi5vcmlnaW4tdGVzdC5iZG4uZGV2ghIqLmNsb3VkLmdvb2dsZS5jb22CGCouY3Jvd2Rzb3VyY2UuZ29vZ2xlLmNvbYIYKi5kYXRhY29tcHV0ZS5nb29nbGUuY29tggsqLmdvb2dsZS5jYYILKi5nb29nbGUuY2yCDiouZ29vZ2xlLmNvLmlugg4qLmdvb2dsZS5jby5qcIIOKi5nb29nbGUuY28udWuCDyouZ29vZ2xlLmNvbS5hcoIPKi5nb29nbGUuY29tLmF1gg8qLmdvb2dsZS5jb20uYnKCDyouZ29vZ2xlLmNvbS5jb4IPKi5nb29nbGUuY29tLm14gg8qLmdvb2dsZS5jb20udHKCDyouZ29vZ2xlLmNvbS52boILKi5nb29nbGUuZGWCCyouZ29vZ2xlLmVzggsqLmdvb2dsZS5mcoILKi5nb29nbGUuaHWCCyouZ29vZ2xlLml0ggsqLmdvb2dsZS5ubIILKi5nb29nbGUucGyCCyouZ29vZ2xlLnB0ghkqLmdlbWluaS5jbG91ZC5nb29nbGUuY29tgg0qLmdzdGF0aWMuY29tghQqLm1ldHJpYy5nc3RhdGljLmNvbYIKKi5ndnQxLmNvbYIRKi5nY3BjZG4uZ3Z0MS5jb22CCiouZ3Z0Mi5jb22CDiouZ2NwLmd2dDIuY29tghAqLnVybC5nb29nbGUuY29tghYqLnlvdXR1YmUtbm9jb29raWUuY29tggsqLnl0aW1nLmNvbYIKYWkuYW5kcm9pZIILYW5kcm9pZC5jb22CDSouYW5kcm9pZC5jb22CEyouZmxhc2guYW5kcm9pZC5jb22CBGcuY28CBDEwLmdvb2dsZS5jb22CEiouZ29vZ2xlLWNhcnRzLmNvbYIKZ29vZ2xlLmNvbYISZ29vZ2xlY29tbWVyY2UuY29tghQqLmdvb2dsZWNvbW1lcmNlLmNvbYIKdXJjaGluLmNvbYIMKi51cmNoaW4uY29tggh5b3V0dS5iZYILeW91dHViZS5jb22CDSoueW91dHViZS5jb22CEW11c2ljLnlvdXR1YmUuY29tghMqLm11c2ljLnlvdXR1YmUuY29tghR5b3V0dWJlZWR1Y2F0aW9uLmNvbYIWKi55b3V0dWJlZWR1Y2F0aW9uLmNvbYIPeW91dHViZWtpZHMuY29tghEqLnlvdXR1YmVraWRzLmNvbYIFeXQuYmWCByoueXQuYmWCGmFuZHJvaWQuY2xpZW50cy5nb29nbGUuY29tghUqLmFpc3R1ZGlvLmdvb2dsZS5jb20wEwYDVR0gBAwwCjAIBgZngQwBAgEwNgYDVR0fBC8wLTAroCmgJ4YlaHR0cDovL2MucGtpLmdvb2cvd3IyL0dTeVQxTjRQQnJnLmNybDCCAQMGCisGAQQB1nkCBAIEgfQEgfEA7wB2AMs49xWJfIShRF9bwd37yW7ymlnNRwppBYWwyxTDFFjnAAABnjyV+/0AAAQDAEcwRQIgCgvqLruYdmtREQIJopZQVZEAux/EdciE9ThPK5WLOIwCIQDJjNYSb4sTv+LnXVHnirnD6kTT5FY8gLI6mKR0WI/m1AB1ANgJVTuUT3r/yBYZb5RPhauw+Pxeh1UmDxXRLnK7RUsUAAABnjyV+8EAAAQDAEYwRAIgQvDSSJRos+D8Lk6bpjH2ZlYxD/N6Gv2TqkFZhUlFKeQCIBq55PPw4e5N89gLgzFC2kp1X+YvFsURPsLrz1LqOAymMA0GCSqGSIb3DQEBCwUAA4IBAQBtZusj1ojCxhZxk5KpZ92eZuTkDVJgJGtDq8gPRehf50mZiu2gDK1JgXIzKRey3tHmgNrCmTon5QJAL9yDyrOGs2GoQsfMkenH0+/hTsLB+n03ni9+9jghfPvE9CZbFimniiqGznhnW5mNOZGy2AnXz79ZfHr4J8AuPh4HVvPc6q/2coyl7Vlxp2XDo6j1eoZARVSske22WvE34U4Yunq+SE0E0a8aKTV7Q7YHeu8/NAsFmG7V6QSSqAyFyxqeEzuz8ylBPxS/cejBk+29tGlfqqrR1JEKdcFLF7EuRyvRWAuQMQBHRA9boa3/lz1f+jEkkUbfqEMrDAnxLthdKKJk

                        -----END CERTIFICATE-----

                        '
        '400':
          description: Bad Request – Invalid domain parameter
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                Invalid Domain Param:
                  value:
                    timestamp: '2025-08-14T10:21:23.349Z'
                    status: 400
                    error: Invalid Param Exception
                    message: 'Please pass domain param correct value[For Technical Support: support@apifreaks.com]'
                    path: /v1.0/ssl/live
        '403':
          description: Forbidden – Domain extension unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                Unavailable Domain Extension:
                  value:
                    timestamp: '2025-08-14T10:18:47.504Z'
                    status: 403
                    error: Forbidden
                    message: Unavailable domain extension.
                    path: /v1.0/ssl/live
        '404':
          description: Not Found – No SSL certificate exists for entered domain
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                No SSL Certificate:
                  value:
                    timestamp: '2025-08-14T10:18:28.465Z'
                    status: 404
                    error: SSL Data Not Found
                    message: No Ssl Certificate exists for entered Domain
                    path: /v1.0/ssl/live
components:
  schemas:
    SSLExtensions:
      type: object
      description: X.509 certificate extensions.
      required:
      - keyUsages
      properties:
        authorityKeyIdentifier:
          type: string
          description: Authority key identifier.
        subjectKeyIdentifier:
          type: string
          description: Subject key identifier.
        keyUsages:
          type: array
          items:
            type: string
          description: Key usage extensions.
        extendedKeyUsages:
          type: array
          items:
            type: string
          description: Extended key usage extensions.
        crlDistributionPoints:
          type: array
          items:
            type: string
          description: CRL distribution point URLs.
        authorityInfoAccess:
          $ref: '#/components/schemas/SSLAuthorityInfoAccess'
        subjectAlternativeNames:
          $ref: '#/components/schemas/SSLSubjectAlternativeNames'
        certificatePolicies:
          type: array
          items:
            $ref: '#/components/schemas/SSLCertificatePolicy'
          description: Certificate policy objects.
    SSLPublicKey:
      type: object
      description: Public key details of the SSL certificate.
      required:
      - keySize
      - keyAlgorithm
      - pemRaw
      properties:
        keySize:
          type: string
          description: Public key size (e.g., 256 bit).
        keyAlgorithm:
          type: string
          description: Public key algorithm (e.g., ECDSA, RSA).
        pemRaw:
          type: string
          description: Raw PEM-encoded public key.
    SSLCertificateItem:
      type: object
      description: A single SSL certificate in the certificate chain.
      required:
      - chainOrder
      - authenticationType
      - validityStartDate
      - validityEndDate
      - serialNumber
      - signatureAlgorithm
      - pemRaw
      - subject
      - issuer
      - publicKey
      - extensions
      properties:
        chainOrder:
          type: string
          description: Position in the certificate chain (end-user, intermediate, root).
        authenticationType:
          type: string
          description: Authentication type (domain, organization, extended).
        validityStartDate:
          type: string
          format: date-time
          description: Certificate validity start date.
        validityEndDate:
          type: string
          format: date-time
          description: Certificate validity end date.
        serialNumber:
          type: string
          description: Certificate serial number.
        signatureAlgorithm:
          type: string
          description: Signature algorithm used (e.g., SHA256-RSA).
        subject:
          $ref: '#/components/schemas/SSLSubject'
        issuer:
          $ref: '#/components/schemas/SSLIssuer'
        publicKey:
          $ref: '#/components/schemas/SSLPublicKey'
        extensions:
          $ref: '#/components/schemas/SSLExtensions'
        pemRaw:
          type: string
          description: Raw PEM-encoded certificate.
    SSLSubject:
      type: object
      description: Subject information of the SSL certificate.
      required:
      - commonName
      properties:
        commonName:
          type: string
          description: Common name of the subject.
        organization:
          type: string
          description: Organization of the subject.
        organizationalUnit:
          type: string
          description: Organizational unit of the subject.
        locality:
          type: string
          description: Locality of the subject.
        state:
          type: string
          description: State of the subject.
        country:
          type: string
          description: Country of the subject.
        incCountry:
          type: string
          description: Incorporation country of the subject.
        incState:
          type: string
          description: Incorporation state of the subject.
        businessCategory:
          type: string
          description: Business category of the subject.
        street:
          type: string
          description: Street address of the subject.
        postalCode:
          type: string
          description: Postal code of the subject.
        serialNumber:
          type: string
          description: Serial number of the subject.
    SSLIssuer:
      type: object
      description: Issuer information of the SSL certificate.
      required:
      - commonName
      - organization
      - country
      properties:
        commonName:
          type: string
          description: Common name of the issuer.
        organization:
          type: string
          description: Organization of the issuer.
        organizationalUnit:
          type: string
          description: Organizational unit of the issuer.
        locality:
          type: string
          description: Locality of the issuer.
        state:
          type: string
          description: State of the issuer.
        country:
          type: string
          description: Country of the issuer.
        incCountry:
          type: string
          description: Incorporation country of the issuer.
        incState:
          type: string
          description: Incorporation state of the issuer.
        businessCategory:
          type: string
          description: Business category of the issuer.
        street:
          type: string
          description: Street address of the issuer.
        postalCode:
          type: string
          description: Postal code of the issuer.
        serialNumber:
          type: string
          description: Serial number of the issuer.
    SSLAuthorityInfoAccess:
      type: object
      

# --- truncated at 32 KB (37 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/apifreaks-api-hub-for-developers/refs/heads/main/openapi/apifreaks-api-hub-for-developers-ssl-apis-api-openapi.yml