Recommended Free Tools
A TLS scan API lets you request a remote assessment of a server and consume its results in code; a local scanner runs from infrastructure you control. For public-facing servers, Qualys SSL Labs offers an HTTP/JSON API for programmatic assessments, including scheduled and bulk use. For services that cannot be reached from the public internet—or when you need the scan to run locally—testssl.sh is a command-line alternative. These tools have different reach, privacy, and operating constraints, so choose based on where the target is reachable and where you are willing to run the assessment.
What a TLS scan API checks—and what it does not guarantee
A TLS scanner connects to a server and assesses its TLS configuration. That is distinct from checking certificate details through a local file or relying only on what a browser happened to negotiate for one connection. Qualys SSL Labs describes its API as exposing its SSL/TLS server testing functionality programmatically and supporting scheduled and bulk assessments. Its scope, as documented, is servers available on the public internet.
The phrase “SSL certificate checker API” can imply a narrow certificate lookup, but an SSL Labs assessment is a broader server test. The available source material does not establish a complete inventory of certificate-specific fields, nor does it establish that any particular scanner guarantees expiry, hostname-mismatch, revocation, or trust-chain checks in a particular response. If one of those checks is a requirement, confirm it in the current API schema or tool documentation before building a control around it.
TLS is the modern protocol family; “SSL” remains common in product names and search terms. testssl.sh’s documented protocol coverage includes checks from SSLv2 and SSLv3 through TLS 1.3. Which protocols and findings a service reports can depend on its current implementation and version, so validate the current documentation when protocol coverage is a compliance requirement.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
Choose remote API or local scanner
| Consideration | Qualys SSL Labs API | testssl.sh |
|---|---|---|
| Where the scan runs | On Qualys servers; targets are public-internet servers, per the API documentation. | Run by the operator from their own environment. |
| Target scope | Publicly reachable servers. | TLS-enabled services; its project describes support beyond web servers on port 443, including other ports and STARTTLS services. |
| Automation and output | HTTP/JSON API; documentation describes scheduled and bulk assessment use cases. | Command-line tool with CSV, JSON, and HTML output described by the project. |
| Privacy and access | The assessment is performed remotely by Qualys, so the target must be externally reachable and assessment request information is shared with the service. | The scan is initiated by you. Network access from the machine running the scan is still required. |
| Commercial use | Documentation says commercial use is generally not allowed without explicit permission from Qualys. | Check the project’s current license and release information for your intended use. |
Use SSL Labs when you specifically need a remote assessment of a public host and its API workflow fits your operations. Prefer a local scanner when the endpoint is private, exposed only to an internal network, or when you need the scan to originate from your own environment. A local scan is not automatically equivalent to a remote scan: network path and vantage point affect what a scanner can reach.
How the SSL Labs API workflow works
The API documentation describes an asynchronous assessment workflow, rather than a guarantee that every request immediately returns a finished report. A request can return an acceptable existing report when one is available; otherwise, a newly started assessment must complete and be polled. Design the integration as a job, not as a synchronous check with a short fixed timeout.
- Submit the target for assessment. Send an HTTP request using the current API v4 request format. The documentation describes HTTP/JSON interaction; consult the current API reference for exact parameters and response fields.
- Inspect the response state. Determine whether it contains an existing report or indicates that assessment is underway. Handle response states according to the current schema rather than assuming one response shape.
- Poll only when needed. If a new assessment is running, poll according to the API’s current guidance and stop when the report reaches a completed state. Use bounded retries and an overall deadline so a stalled job does not block an application indefinitely.
- Store results and their context. Associate the resulting assessment with the requested hostname and time, and retain the status needed for your own monitoring. Confirm which result fields are stable and appropriate for your downstream decision before treating them as a policy signal.
The documentation also describes scheduled and bulk assessment as use cases. Build scheduling around the API’s current limits and lifecycle guidance; the source material does not establish a current request quota, rate limit, or guaranteed completion time. Do not treat “free subject to restrictions” as permission for unlimited use.
Integration safeguards
- Validate and normalize input hostnames before creating jobs; do not let arbitrary user input become an uncontrolled scan target.
- Keep an explicit allowlist if scans are initiated by an application, and check that your use complies with the service’s current rules.
- Represent pending, completed, and failed assessments separately. A timeout or incomplete result is not a successful clean assessment.
- Make retries deliberate. Since a request can return an existing report or initiate a new assessment, understand the API’s semantics before retrying after a network failure.
- Keep the current API version and response schema under review. The API v4 documentation by Nauman Shah is dated 17 October 2023; that is a document update date, not evidence of present performance or current limits.
Run testssl.sh locally
testssl.sh is a command-line alternative for checking TLS/SSL protocols, ciphers, and cryptographic weaknesses on TLS-enabled services. It can output machine-readable results, with CSV, JSON, and HTML cited by the project. Its scope includes services beyond HTTPS on port 443, including other ports and STARTTLS. This makes it useful when the target is reachable only from a controlled network or when you need a scan to originate from your own host.
Install and invoke the current stable release using the instructions in the project repository and manual. The project repository and manual describe the tool’s capabilities and output formats, but do not specify a stable invocation syntax, release number, or installation command; those can change, so use the command documented for the version you install rather than copying a potentially stale command. Select the target service and port appropriate to the endpoint, then choose a machine-readable output format if another program will consume the result.
Operational notes for a local scan
- Run the scanner from a network that can reach the service and port being assessed. A local tool cannot test an inaccessible endpoint merely because the host is known.
- For STARTTLS or nonstandard ports, use the project manual’s target syntax for that service type and port.
- Keep the tool updated according to its repository’s current release status, particularly when results inform security decisions.
- Parse structured output defensively: preserve unknown fields and distinguish scan errors or incomplete results from a passing assessment.
- Do not assume a local result and a remote SSL Labs result are directly comparable. The tools run from different networks and the available documentation does not establish field-by-field parity.
Decide what to automate
Before wiring results into alerts or a release gate, decide what constitutes a finding for your system. A scanner report is evidence about the endpoint as seen from a particular vantage point at a particular time; it is not, by itself, proof that every client, route, or internal service sees the same behavior. Keep the distinction between “scan completed” and “policy passed.”
- For public endpoints: SSL Labs can provide a remote, HTTP/JSON assessment flow. Check its current terms, limits, and API lifecycle before embedding it in a product.
- For private or specialized services: run testssl.sh from a network with access to the target, using the documented service and port options.
- For periodic monitoring: record the assessment time and result status, and account for asynchronous completion rather than assuming a fixed response duration.
- For a specific certificate requirement: verify that the current report schema exposes the needed check and define how missing or indeterminate data should be handled.
Troubleshooting common failures
The remote assessment cannot reach the host
SSL Labs is a remote assessment performed by Qualys servers, and its API documentation concerns servers available on the public internet. A hostname available only inside a private network, blocked by a firewall, or otherwise inaccessible from the public internet is not a suitable target for that remote path. Use a local scanner from an authorized network with access to the service instead.
The API response is not a finished report
The API workflow may return an existing report or start an assessment that must complete. Treat a pending state as a job to poll under the current API guidance; do not interpret it as a failed scan or a clean result. If polling does not resolve the state, inspect the current response schema and service guidance before retrying or escalating.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsA scan times out or cannot connect locally
For testssl.sh, first verify that the machine running it can reach the target’s port and that the target is the intended TLS service. For other ports or STARTTLS services, consult the manual for the correct mode. The project documentation does not specify a universal timeout or a single remedy for every network failure.
Rank #4
The result format is difficult to consume
testssl.sh documents CSV, JSON, and HTML outputs. Choose a structured format for automated processing and validate it against the installed release. For SSL Labs, consume the current JSON schema rather than hard-coding assumptions based on an old response example.
You plan to use SSL Labs commercially
Do not infer commercial rights from the service being free. The API v4 documentation says commercial use is generally not allowed without explicit permission from Qualys. Confirm current terms and obtain permission before incorporating the API into a commercial integration.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server, not a TLS scanner; it does not replace SSL Labs or testssl.sh for checking certificates or TLS versions. It can be useful alongside security work when you also need website screenshots. One GET request returns an image or PDF; see the ScreenshotNeo API documentation for the current request options.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Best Value
- Used Book in Good Condition
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
ScreenshotNeo removes cookie banners, newsletter popups, and chat widgets before the shot; bot checks, blank pages, and failed loads are never billed. Its MCP server lets AI agents take screenshots, and the free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Learn about ScreenshotNeo or sign up free.
Sources and currency
Qualys SSL Labs’ project page describes its API’s programmatic testing, scheduled and bulk assessment uses, and free access subject to restrictions. Its API v4 documentation describes the remote assessment and polling workflow and commercial-use restriction; the cited documentation was last updated 17 October 2023. The testssl.sh project repository and manual describe its TLS checks, service scope, protocols, and output formats. API terms, limits, schemas, and software releases can change, so verify the current official documentation before production use.
Frequently Asked Questions
Can an SSL Labs API scan a private intranet host?
No, not through the documented remote assessment model: SSL Labs assessments run on Qualys servers and target servers available on the public internet. Use a locally run scanner from a network that can reach the private host.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchDoes a successful TLS scan prove every client connection is secure?
No. A scan describes what the tool observed from its own network path at that time; it does not establish identical behavior for every client or route.
Does ScreenshotNeo check SSL certificates or supported TLS versions?
No. ScreenshotNeo captures website images or PDFs; it is not a TLS scanner.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




