Cometh · Domain Security

Cometh Domain Security

Domain security

Domain security posture for Cometh, probed live across 10 host(s) and 1 registrable domain(s). 8 host(s) serve HTTPS (up to TLSv1.3); 4 advertise HSTS. Email/DNS controls: DNSSEC present, SPF present, DMARC present (p=none).

CompanyBlockchainAccount AbstractionERC-4337Smart WalletPaymasterBundlerPasskeysWebAuthnGasless TransactionsDeFiCustodyStakingPaymentsJSON-RPCMiCASAFeWeb3

Transport & Host Security

www.cometh.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 11 02:01:48 2026 GMT
docs.cometh.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Nov 15 06:59:42 2026 GMT
api.4337.cometh.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Sep 22 22:50:11 2026 GMT
bundler.cometh.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Sep 21 03:40:52 2026 GMT
paymaster.cometh.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Sep 20 03:40:14 2026 GMT
status.cometh.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 14 18:53:03 2026 GMT
security.cometh.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 9 14:58:35 2026 GMT
app.cometh.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Oct 11 07:51:44 2026 GMT
api.marketplace.cometh.io
HTTPS: no · HSTS: no
api.checkout.cometh.io
HTTPS: no · HSTS: no

Domain (DNS/Email) Security

cometh.io
DNSSEC: yes · SPF: yes · DMARC: yes (p=none) · CAA: none

Source

Domain Security

cometh-domain-security.yml Raw ↑
generated: '2026-08-17'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
hosts:
- host: www.cometh.io
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 11 02:01:48 2026 GMT
  hsts: true
  hsts_max_age: 31536000
- host: docs.cometh.io
  https: true
  tls_version: TLSv1.3
  cert_expires: Nov 15 06:59:42 2026 GMT
  hsts: true
  hsts_max_age: 31536000
- host: api.4337.cometh.io
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 22 22:50:11 2026 GMT
  hsts: null
- host: bundler.cometh.io
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 21 03:40:52 2026 GMT
  cert_cn: bundler.cometh.io
  hsts: null
  http_status: 404
  note: 'Kong gateway; unmatched paths return {"message":"no Route matched with those values"}.'
- host: paymaster.cometh.io
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 20 03:40:14 2026 GMT
  cert_cn: paymaster.cometh.io
  hsts: null
  http_status: 401
  note: 'Kong key-auth; every path returns {"message":"No API key found in request"} until an apikey is supplied.'
- host: status.cometh.io
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 14 18:53:03 2026 GMT
  hsts: true
  hsts_max_age: 63113904
  hsts_preload: true
  http_status: 200
- host: security.cometh.io
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct  9 14:58:35 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  http_status: 200
  note: Vanta-hosted trust centre.
- host: app.cometh.io
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 11 07:51:44 2026 GMT
  hsts: null
  http_status: 200
  note: Project dashboard where apikey/apisecret are issued; serves no HSTS header.
- host: api.marketplace.cometh.io
  https: false
  tls_version: null
  tls_error: 'CERTIFICATE_VERIFY_FAILED: self-signed certificate'
  cert_subject: 'C=US, ST=California, L=San Francisco, O=Kong, OU=IT Department, CN=localhost'
  cert_issuer: 'C=US, ST=California, L=San Francisco, O=Kong, OU=IT Department, CN=localhost'
  cert_valid: 2026-08-16 to 2046-08-11
  hsts: null
  note: >-
    HOST IS BROKEN FOR TLS. The name resolves (CNAME entrypoint.core.cometh.tech) but the gateway answers with Kong's
    DEFAULT self-signed localhost certificate, so no client can verify it; with verification disabled the gateway
    returns 404 "no Route matched with those values". The still-published @cometh/marketplace-sdk targets this host —
    see lifecycle/cometh-lifecycle.yml.
- host: api.checkout.cometh.io
  https: false
  tls_version: null
  tls_error: 'CERTIFICATE_VERIFY_FAILED: self-signed certificate'
  cert_subject: 'O=Kong, CN=localhost (default certificate)'
  hsts: null
  note: Same failure mode as api.marketplace.cometh.io; targeted by the still-published @cometh/checkout-sdk.
domains:
- domain: cometh.io
  dnssec: true
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: none
  note: >-
    DNSSEC is signed and SPF/DMARC exist, but the DMARC policy is p=none (monitor only, no enforcement) and NO CAA
    record is published, so any public CA may issue for the domain.
x-findings:
- 'Two API hostnames (api.marketplace, api.checkout) present Kong''s default self-signed localhost certificate — unusable over TLS.'
- 'No CAA record on cometh.io; DMARC is p=none.'
- 'No HSTS on the three live API hosts (api.4337, bundler, paymaster) nor on the app.cometh.io dashboard.'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/cometh-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.