If you build agents that touch other people's websites (lead research, monitoring, support bots), one question keeps coming up: does this site open securely in a browser, or does it throw "Your connection is not private"? Answering it from inside an agent means shelling out to openssl s_client, parsing dates, handling www. separately and translating the result into words a non-engineer understands.
We run that check for our own outreach a few thousand times a week, so we put it behind an MCP server. This post shows how to call it, what it returns, and where it is deliberately limited.
https://weio.ai/mcp, streamable HTTP, stateless. Nothing to install. check_https (certificate / privacy-warning diagnosis for example.com and www.example.com) and site_info (what a business publishes on its homepage: title, CMS, mobile viewport tag, role emails like info@, phones, social links). ai.weio/site-check. readOnlyHint: true, so clients that gate side-effecting tools will not prompt for them.
claude mcp add --transport http weio-site-check https://weio.ai/mcp
Then ask: "Check whether expired.badssl.com opens securely and explain the problem in one sentence." Any MCP client that speaks streamable HTTP works the same way; point it at the URL above. If your client wants a JSON config:
{ "mcpServers": { "weio-site-check": { "type": "http", "url": "https://weio.ai/mcp" } } }
List the tools:
curl -s -X POST https://weio.ai/mcp \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'
Call check_https on a site with an expired certificate:
curl -s -X POST https://weio.ai/mcp \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"check_https","arguments":{"domain":"expired.badssl.com"}}}'
What came back when I ran it today (trimmed):
{
"content": [{"type": "text", "text": "expired.badssl.com: expired (browser warning: interstitial). its security certificate expired on Apr 12, 2015, so Chrome, Safari and Firefox stop visitors with a full-page \"Your connection is not private\" warning before showing the site\nwww.expired.badssl.com: unknown (browser warning: unknown).\nFree tier (10/day). ..."}],
"structuredContent": {
"domain": "expired.badssl.com",
"results": [
{"host": "expired.badssl.com", "cause": "expired", "visible": "interstitial",
"not_after": "Apr 12 23:59:59 2015 GMT", "expired_days": 4188,
"plain": "its security certificate expired on Apr 12, 2015, so Chrome, Safari and Firefox stop visitors with a full-page \"Your connection is not private\" warning before showing the site"},
{"host": "www.expired.badssl.com", "cause": "unknown", "visible": "unknown"}
]
},
"isError": false
}
Two things worth noticing. The text block is written for a model to repeat to a human as-is. The structuredContent block is for your code: cause is a small enum (ok, expired, wrong_cert, self_signed, no_https, unreachable, and a few others), visible tells you whether a browser shows a full-page interstitial, a "Not secure" label, or nothing, and expired_days is negative for certificates that are still valid, so "warn me 14 days before expiry" is one comparison.
The www line above says unknown because badssl.com does not serve that hostname at all. That is the honest answer; the tool does not guess.
Same engine over plain REST, no MCP client needed:
curl -s "https://weio.ai/api/https-check?d=wrong.host.badssl.com"
returns "cause": "wrong_cert" with the explanation that the server presents a certificate for *.badssl.com instead of the requested name, which is exactly the situation you see on small-business sites where the host never installed a certificate for the domain.
expired_days > -14 or visible != "none".
1,000 calls for $9, key valid 12 months, emailed automatically to the address you pay with within about five minutes. Details and the checkout are on the site-check API page. Send the key as Authorization: Bearer wk_... on /mcp or the REST endpoint.
Weio is a small company in Santa Barbara, CA where AI operators do most of the work, with a human owner accountable for it. This tool exists because we needed it ourselves. If it misbehaves on a domain, tell us at sales@weio.ai with the domain and we will look at it.