TLS Radar
Free SSL/TLS scanning and Let's Encrypt certificate issuance (private key stays local), plus certificate-expiry monitoring via one MCP server. Public scan and cert tools need no account.
README
TLS Radar plugin for Claude Code & Cowork
Run SSL/TLS scans, issue free Let's Encrypt certificates, and manage cert monitoring from inside Claude Code or Claude Cowork - through a single MCP server, with nothing to configure.
Independent monitoring from a vendor that doesn't sell certificates - built for the 90-day-cert era, where manual renewal tracking is already finished.
<!-- TODO: 30-60s asciinema -> GIF of /tls-cert issuing a real cert end to end. Drop the file at docs/demo.gif -->
# Public - no account, no setup
/tls-scan example.com # free SSL/TLS scan
/tls-cert mydomain.dev # free 90-day Let's Encrypt cert (private key stays local)
/tls-renew mydomain.dev # renew a cert
# Connect once for monitoring (OAuth via /mcp)
/mcp # built-in Claude Code OAuth flow
/tls-monitor add api.foo.io # one or many: /tls-monitor add a.com b.com c.com
/tls-monitor list
/tls-monitor remove api.foo.io
/tls-diagnose # health check (use when something's off)
/tls-upgrade # open pricing page
See real output before installing: sample scan report
Other actions - "what's expiring soon," "scan history for X," "what plan am I on," "export/import my monitors," "invite a teammate" - just ask in plain language; the plugin's skill routes them to the right tool. No slash command needed.
How it works
Claude Code's MCP client talks to one remote server:
tlsradar.com/api/v1/mcp
Certificate issuance is proxied through that server to the Let's Encrypt backend (Beacon), so there's a single connection and a single auth model - no second server, no token to paste into your shell.
- Public tools (
scan,cert_create,cert_check_propagation,cert_finalize,cert_status,cert_renew) work with no account. - Authenticated tools (monitoring, plan info, export/import, team) use Claude Code's built-in OAuth 2.0 + PKCE. Run
/mcponce, pick thetlsradarserver, approve in the browser; the token is managed by Claude Code.
When you run /mcp, Claude Code fetches tlsradar.com/.well-known/oauth-authorization-server (RFC 8414), dynamically registers as a public client (RFC 7591), opens the browser for consent (PKCE / RFC 7636), and includes the token on subsequent requests automatically.
Certificates keep your private key local
/tls-cert generates the key + CSR on your machine with openssl and sends only the CSR. The private key never leaves your computer and no passphrase is ever typed into the chat. If you want a .p12 bundle (e.g. for Windows/Java import), the plugin packages it locally too.
You choose how to prove control of the domain, and the plugin remembers your choice (in ~/.config/tlsradar/config.json):
dns-01- you add a TXT record by hand (works anywhere).dns-01-cloudflare/dns-01-route53- the plugin sets the TXT record for you via the provider API, reading your token from the local environment (CLOUDFLARE_API_TOKEN, or your configuredawsCLI). Those credentials stay on your machine - they're never sent to TLS Radar or Beacon.http-01- serve a file onhttp://yourdomain(port 80); issues the apex only.
When a cert is issued, TLS Radar emails you about ongoing monitoring - the cert → monitoring handoff is fully automatic and server-side.
Works in Claude Code and Cowork
This is a standard plugin, so it runs in both Claude Code and Claude Cowork. Scanning, certificate issuance, and monitoring all work in either client: the tools come from one MCP server, and the certificate flow runs openssl plus a bundled helper script locally (both clients can run local commands and the bundled script via ${CLAUDE_PLUGIN_ROOT}). Connecting for monitoring uses your client's built-in OAuth - /mcp in Claude Code, or the equivalent connect step in Cowork.
Install
In Claude Code, add the marketplace and install - two commands, no clone, no paths:
/plugin marketplace add TLS-Radar/tlsradar-claude-plugin
/plugin install tlsradar@tlsradar
(Or browse it in the /plugin menu after adding the marketplace.) In Claude Cowork, add it from the plugin catalog (search "TLS Radar"). That's it - scanning and cert issuance work immediately. Run /mcp (or Cowork's connect step) when you want monitoring.
<details> <summary>Manual install (no marketplace)</summary>
git clone https://github.com/TLS-Radar/tlsradar-claude-plugin ~/.claude/plugins/tlsradar
</details>
Free plan limits
- 1 monitor included free
- 1 alert per month, delivered at 7 days before expiry
- Unlimited free scans (rate-limited)
- Free Let's Encrypt issuance
- REST API access on every plan, including Free
When you hit the monitor limit, the tool's response includes the recommended upgrade and a pricing URL.
Configuration
Nothing is required. Optional environment variables:
TLSRADAR_BASE_URL- override the TLS Radar URL (defaulthttps://tlsradar.com). Useful for staging/self-host.
Anonymous usage id. On first run the plugin mints a random id at ~/.config/tlsradar/install_id and the scan/cert commands pass it (as a client_id argument) so anonymous usage can be attributed to one install. It identifies an install, not a person. The plugin does not modify your shell config and sends no tracking header — the id travels only as that argument, read from the local file.
To opt out: rm ~/.config/tlsradar/install_id. With the file gone, no id is sent.
Privacy & security
- This plugin ships no tokens or credentials - there's nothing secret in this repo. See
SECURITY.md. - The OAuth token is managed by Claude Code's MCP client, not by this plugin.
- Certificate private keys are generated locally and never sent to any server.
- DNS-provider credentials (
CLOUDFLARE_API_TOKEN, AWS CLI) are read from your local environment and never sent to TLS Radar or Beacon. - An anonymous install id is sent for usage attribution, passed as a tool argument read from
~/.config/tlsradar/install_id(see Configuration to opt out). The plugin modifies no shell files and sends no tracking header. It identifies an install, not a person. - To revoke access:
https://tlsradar.com/oauth/authorized_applicationsor remove the MCP server in/mcp. - Access tokens expire in 2 hours; refresh tokens rotate on use, capped at 90 days.
Layout
.
├── README.md # this file
├── CLAUDE.md # architecture / funnel / contracts (humans + AI agents)
├── CONTRIBUTING.md # dev loop + how to add commands
├── CHANGELOG.md # version history
├── SECURITY.md # reporting + why the plugin holds no secrets
├── LICENSE # MIT
├── .claude-plugin/plugin.json # plugin manifest
├── .claude-plugin/marketplace.json # self-hosting marketplace entry
├── .mcp.json # MCP server config (one remote URL)
├── commands/ # slash commands (how to add one: CONTRIBUTING.md)
├── skills/ # NL skill router (with its own README)
├── hooks/hooks.json # one-time SessionStart welcome (print only)
├── tools/manifest.json # single source of truth for tool names
├── scripts/ # CI guards + tested DNS-provider helper
└── evals/ # tool-routing evals (prompt → expected tool)
Contributing
Start with CONTRIBUTING.md for the dev loop (all checks are offline and run with python3). For architecture, the funnel, contract pitfalls, and the release process, read CLAUDE.md - useful for both humans and AI agents. Changes are tracked in CHANGELOG.md.
Security reports: security@tlsradar.com (never a public issue) - see SECURITY.md.
License
MIT © TLS Radar
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。