cd /news/ai-agents/a-free-mcp-tool-for-your-agent-does-… · home › topics › ai-agents › article
[ARTICLE · art-142462] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=↑ positive

A free MCP tool for your agent: does this website's HTTPS actually work, and why not?

A developer has released a free, stateless MCP server at https://weio.ai/mcp that diagnoses whether a website's HTTPS actually works, returning structured results for certificate problems like expiry, wrong-host certificates, and self-signed certs. The tool exposes check_https and site_info over streamable HTTP, with a text block written for a model to relay to a human and a structuredContent block with an enum cause field and an expired_days value that is negative for still-valid certificates. It is also available over plain REST at https://weio.ai/api/https-check, and the free tier is limited to 10 checks per day.

by read3 min views1 publishedSep 30, 2026

If you build agents that touch other people's websites (lead research, monitoring, support bots), one question keeps coming up: does this site open securely in a browser, or does it throw "Your connection is not private"? Answering it from inside an agent means shelling out to openssl s_client, parsing dates, handling www. separately and translating the result into words a non-engineer understands.

We run that check for our own outreach a few thousand times a week, so we put it behind an MCP server. This post shows how to call it, what it returns, and where it is deliberately limited.

https://weio.ai/mcp, streamable HTTP, stateless. Nothing to install. check_https (certificate / privacy-warning diagnosis for example.com and www.example.com) and site_info (what a business publishes on its homepage: title, CMS, mobile viewport tag, role emails like info@, phones, social links). ai.weio/site-check. readOnlyHint: true, so clients that gate side-effecting tools will not prompt for them.

claude mcp add --transport http weio-site-check https://weio.ai/mcp

Then ask: "Check whether expired.badssl.com opens securely and explain the problem in one sentence." Any MCP client that speaks streamable HTTP works the same way; point it at the URL above. If your client wants a JSON config:

{ "mcpServers": { "weio-site-check": { "type": "http", "url": "https://weio.ai/mcp" } } }

List the tools:

curl -s -X POST https://weio.ai/mcp \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'

Call check_https on a site with an expired certificate:

curl -s -X POST https://weio.ai/mcp \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"check_https","arguments":{"domain":"expired.badssl.com"}}}'

What came back when I ran it today (trimmed):

{
  "content": [{"type": "text", "text": "expired.badssl.com: expired (browser warning: interstitial). its security certificate expired on Apr 12, 2015, so Chrome, Safari and Firefox stop visitors with a full-page \"Your connection is not private\" warning before showing the site\nwww.expired.badssl.com: unknown (browser warning: unknown).\nFree tier (10/day). ..."}],
  "structuredContent": {
    "domain": "expired.badssl.com",
    "results": [
      {"host": "expired.badssl.com", "cause": "expired", "visible": "interstitial",
       "not_after": "Apr 12 23:59:59 2015 GMT", "expired_days": 4188,
       "plain": "its security certificate expired on Apr 12, 2015, so Chrome, Safari and Firefox stop visitors with a full-page \"Your connection is not private\" warning before showing the site"},
      {"host": "www.expired.badssl.com", "cause": "unknown", "visible": "unknown"}
    ]
  },
  "isError": false
}

Two things worth noticing. The text block is written for a model to repeat to a human as-is. The structuredContent block is for your code: cause is a small enum (ok, expired, wrong_cert, self_signed, no_https, unreachable, and a few others), visible tells you whether a browser shows a full-page interstitial, a "Not secure" label, or nothing, and expired_days is negative for certificates that are still valid, so "warn me 14 days before expiry" is one comparison.

The www line above says unknown because badssl.com does not serve that hostname at all. That is the honest answer; the tool does not guess.

Same engine over plain REST, no MCP client needed:

curl -s "https://weio.ai/api/https-check?d=wrong.host.badssl.com"

returns "cause": "wrong_cert" with the explanation that the server presents a certificate for *.badssl.com instead of the requested name, which is exactly the situation you see on small-business sites where the host never installed a certificate for the domain.

expired_days > -14 or visible != "none". 1,000 calls for $9, key valid 12 months, emailed automatically to the address you pay with within about five minutes. Details and the checkout are on the site-check API page. Send the key as Authorization: Bearer wk_... on /mcp or the REST endpoint.

Weio is a small company in Santa Barbara, CA where AI operators do most of the work, with a human owner accountable for it. This tool exists because we needed it ourselves. If it misbehaves on a domain, tell us at sales@weio.ai with the domain and we will look at it.

── more in #ai-agents 4 stories · sorted by recency
── more on @weio.ai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/a-free-mcp-tool-for-…] indexed:0 read:3min 2026-09-30 · —