TLS Checker API

GET

Check supported TLS versions and highest negotiable protocol for any domain.

TLS Check inspects which TLS/SSL protocol versions a server supports. It probes TLS 1.0 through 1.3, reports which are negotiable, and derives a security verdict — the highest supported version, whether deprecated protocols are still exposed, and a composite risk score.

Try it — live request, no key required

Request
GETapi.apiverve.com/v1/tlscheck?domain=amazon.com
Query parameters
Verification
Format

No key required to try it. Get a key to use it in your app.

Example
{
  "status": "ok",
  "error": null,
  "data": {
    "domain": "amazon.com",
    "tlsVersions": {
      "TLSv1": true,
      "TLSv1.1": true,
      "TLSv1.2": true,
      "TLSv1.3": true
    },
    "highestVersion": "TLSv1.3",
    "hasDeprecatedTLS": true,
    "isSecure": false,
    "riskScore": 55,
    "riskLevel": "medium"
  }
}

About the TLS Checker API

TLS Check connects to the provided domain and port and runs a TLS handshake for each protocol version to determine which are supported. It identifies the highest negotiable version (like TLS 1.2/1.3), flags whether deprecated TLS 1.0/1.1 remain exposed, and returns a composite risk score summarizing the server's protocol security.

What people use it for

Payment Gateway Auditing
Before onboarding merchant checkout domains, fintech compliance auditors check whether incoming endpoints accept legacy protocols like TLS 1.0 or 1.1.
Deployment Pipeline Verification
Flag outdated web server configurations during production releases by testing handshake support across all modern protocol versions before traffic switches over.
Attack Surface Scanning
Security analysts query customer-facing domains periodically to find legacy protocol support and review the highest negotiable version across exposed web ports.
Vendor Security Assessments
When evaluating SaaS suppliers, procurement teams inspect external hostnames to confirm that partner servers negotiate TLS 1.2 or 1.3.

Ways to call it

One endpoint, many ways in — REST with JSON, XML, YAML and CSV, plus GraphQL and an MCP interface for AI agents.

JSON
Default REST response
XML
Markup format
YAML
Human-readable
CSV
Tabular export
Beta
GraphQL
Query language
New
MCP
For AI agents

Other ways to use TLS Checker

Same data, same APIVerve account, same credit balance — one key works on all of them.

Questions.

Common questions about the TLS Checker API.

Read the docs →
Which TLS versions does the check test against?
The check runs live handshakes for TLS 1.0, 1.1, 1.2, and 1.3. You can target any standard domain and specify a custom port if the service does not run on standard HTTPS port 443.
Which plan fits 25,000 domain TLS checks a month?
The Starter plan easily covers this volume. Each check costs 2 credits, so 25,000 scans use 50,000 of the 200,000 credits on Starter, working out to about $0.30 per 1,000 calls. The Free plan includes 100 checks each month for testing.
Are the risk score and deprecated protocol flags available on the Free plan?
No, those are premium fields. The Free plan reports raw version support and the highest negotiable TLS version. The composite risk score, risk level band, deprecated TLS flag, and overall security verdict unlock on any paid plan.
Does this check use cached data or scan live?
Every check performs real-time TLS handshakes directly against the destination host and port at the moment of your request. It does not rely on cached or historical scan databases.
What does the response return if a server refuses all TLS connections?
If none of the tested TLS protocols successfully negotiate a handshake, each protocol flag returns false and the highest version field returns null. You can use that null check to detect non-TLS services or connection failures.

Ready to build with TLS Checker? Start with 200 free credits — one key unlocks all 300+ APIs.

Explore the catalog

300+ APIs on the same key and the same response shape.

Browse all APIs