Skip to main content

certindex-mcp

CI PyPI License: MIT

An MCP (Model Context Protocol) server that exposes CertIndex's Certificate Transparency search tools to any MCP-compatible client (Claude Desktop, the MCP Inspector, Continue, etc.).

CertIndex indexes the full public CT corpus (~5 M certificates, growing ~100 k/day). This server wraps the public CertIndex REST API so an LLM can ask questions like:

  • "List every TLS certificate ever issued for example.com."
  • "What subdomains has Let's Encrypt seen for mycompany.io?"
  • "Show me certs expiring in the next 30 days for api.mycompany.io."
  • "Pull the full PEM and CT log metadata for SHA-256 <fingerprint>."

Why this repo exists

The CertIndex monorepo bundles an MCP server (mounted at https://api.ctindex.io/mcp) that talks directly to the production Postgres index. This standalone package is a thin client-side shim: it speaks MCP to your editor / agent and forwards every tool call to the hosted CertIndex REST API over HTTPS. Two consequences:

  1. You don't need a copy of the index — sign up for a free API key at https://ctindex.io and you're done.
  2. The package has a tiny dependency footprint (mcp, httpx, pydantic) — easy to audit, easy to vendor, no DB drivers.

Install

pip install certindex-mcp

Or with uvx for one-shot use:

uvx certindex-mcp

To install the latest development version from source instead:

pip install git+https://github.com/certindex/certindex-mcp

Quickstart — Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):

{
  "mcpServers": {
    "certindex": {
      "command": "uvx",
      "args": ["certindex-mcp"],
      "env": {
        "CERTINDEX_API_KEY": "ctx_live_..."
      }
    }
  }
}

Restart Claude Desktop. The ten CertIndex tools appear in the tool tray.

Tools

Ten tools, matching the hosted CertIndex MCP server 1:1:

Tool What it does Notable parameters
search_certificates Search the CT index by domain, CN, issuer, SAN, validity, or wildcard status. domain, cn, issuer, san, expired, is_wildcard, page/limit
get_certificate Fetch a single cert by SHA-256 fingerprint. sha256, include_enrichment
get_domain_certificates Every cert ever issued for an exact domain. valid_only, include_enrichment, include_signals (paid plans), page/limit
get_subdomains Enumerate unique subdomains seen in CT. Offset (page/limit) or keyset cursor mode — pass cursor="" to start, then feed back each response's next_cursor
get_latest_cert Most recent currently-valid cert for a domain. include_enrichment, include_signals, include_precerts (let precertificates compete for "latest")
get_expiring_certs Certs for a domain expiring within days days. days
submit_global_sweep Submit an async, domain-less CN/SAN substring sweep of the entire index (POST /v1/sweeps). cn/san_contains (3+ chars, at least one required), issuer, is_wildcard, is_precert, expired, first_seen_*/not_after_* date bounds, strict_attribution, resume_token (continuation past the result cap)
get_sweep_results Poll a sweep job and paginate its results when done (GET /v1/sweeps/{id}). sweep_id, page/limit (up to 1,000)
get_usage Caller's tier, current usage, remaining quota, and entitlements. —
get_historical_backfill_status Check / start the paid deep-history backfill for a domain. domain

Quickstart — MCP Inspector

export CERTINDEX_API_KEY=ctx_live_...
npx @modelcontextprotocol/inspector uvx certindex-mcp

Configuration

Env var Default Description
CERTINDEX_API_KEY (required) Your CertIndex API key. Mint one at https://ctindex.io/app/keys
CERTINDEX_BASE_URL https://api.ctindex.io Override for self-hosted deployments / staging
CERTINDEX_TIMEOUT 30 Per-request HTTP timeout (seconds)

Security

Input validation, rate-limit handling, and our supply-chain posture are documented in SECURITY.md. Please report vulnerabilities to security@ctindex.io rather than filing public issues.

Development

git clone https://github.com/certindex/certindex-mcp
cd certindex-mcp
pip install -e ".[dev]"
pytest

CI runs on Python 3.11 / 3.12 / 3.13.

License

MIT © CertIndex contributors.

Metadata

Release files for certindex-mcp 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for certindex-mcp 0.2.1
File Size Uploaded
certindex_mcp-0.2.1.tar.gz 19.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for certindex-mcp 0.2.1
File Interpreter ABI Platform
certindex_mcp-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 33.5 kB

Release files / certindex_mcp-0.2.1.tar.gz

Download URL certindex_mcp-0.2.1.tar.gz
Size 19.0 kB
Tags Source
SHA-256 checksum
How to use checksums
2bae04510888bab1fa9b0ecd9653c368a7b203556c10386b7c6bc56562e2840e
BLAKE2b-256 checksum
How to use checksums
5eccb180c7a275dfb8c06d7a0f18b466d74a1d83621e856a58c0178e91b42dcb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.13

Release files / certindex_mcp-0.2.1-py3-none-any.whl

Download URL certindex_mcp-0.2.1-py3-none-any.whl
Size 14.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
16290bd4e639de2fbd7a5317ccf96a241e5966e7d8b4d36c470b7e80f8e78259
BLAKE2b-256 checksum
How to use checksums
203a85e399945c72642c2be76112ab53d5dc11c7efa7f5643e7a56179688a711
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.13

Release history Release notifications | RSS feed

0.3.0

2 release files

This release

0.2.1 This release

2 release files

0.2.0

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page