{"slug": "a-free-mcp-tool-for-your-agent-does-this-website-s-https-actually-work-and-why", "title": "A free MCP tool for your agent: does this website's HTTPS actually work, and why not?", "summary": "A developer has released a free, stateless MCP server at https://weio.ai/mcp that diagnoses whether a website's HTTPS actually works, returning structured results for certificate problems like expiry, wrong-host certificates, and self-signed certs. The tool exposes check_https and site_info over streamable HTTP, with a text block written for a model to relay to a human and a structuredContent block with an enum cause field and an expired_days value that is negative for still-valid certificates. It is also available over plain REST at https://weio.ai/api/https-check, and the free tier is limited to 10 checks per day.", "body_md": "If you build agents that touch other people's websites (lead research, monitoring, support bots), one question keeps coming up: **does this site open securely in a browser, or does it throw \"Your connection is not private\"?** Answering it from inside an agent means shelling out to `openssl s_client`, parsing dates, handling `www.` separately and translating the result into words a non-engineer understands.\n\nWe run that check for our own outreach a few thousand times a week, so we put it behind an MCP server. This post shows how to call it, what it returns, and where it is deliberately limited.\n\n`https://weio.ai/mcp`, streamable HTTP, stateless. Nothing to install.` check_https` (certificate / privacy-warning diagnosis for `example.com` and `www.example.com`) and `site_info` (what a business publishes on its homepage: title, CMS, mobile viewport tag, role emails like `info@`, phones, social links).` ai.weio/site-check`.` readOnlyHint: true`, so clients that gate side-effecting tools will not prompt for them.\n\n```\nclaude mcp add --transport http weio-site-check https://weio.ai/mcp\n```\n\nThen ask: *\"Check whether expired.badssl.com opens securely and explain the problem in one sentence.\"* Any MCP client that speaks streamable HTTP works the same way; point it at the URL above. If your client wants a JSON config:\n\n```\n{ \"mcpServers\": { \"weio-site-check\": { \"type\": \"http\", \"url\": \"https://weio.ai/mcp\" } } }\n```\n\nList the tools:\n\n```\ncurl -s -X POST https://weio.ai/mcp \\\n  -H 'Content-Type: application/json' \\\n  -H 'Accept: application/json, text/event-stream' \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"tools/list\",\"params\":{}}'\n```\n\nCall `check_https` on a site with an expired certificate:\n\n```\ncurl -s -X POST https://weio.ai/mcp \\\n  -H 'Content-Type: application/json' \\\n  -H 'Accept: application/json, text/event-stream' \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":2,\"method\":\"tools/call\",\"params\":{\"name\":\"check_https\",\"arguments\":{\"domain\":\"expired.badssl.com\"}}}'\n```\n\nWhat came back when I ran it today (trimmed):\n\n```\n{\n  \"content\": [{\"type\": \"text\", \"text\": \"expired.badssl.com: expired (browser warning: interstitial). its security certificate expired on Apr 12, 2015, so Chrome, Safari and Firefox stop visitors with a full-page \\\"Your connection is not private\\\" warning before showing the site\\nwww.expired.badssl.com: unknown (browser warning: unknown).\\nFree tier (10/day). ...\"}],\n  \"structuredContent\": {\n    \"domain\": \"expired.badssl.com\",\n    \"results\": [\n      {\"host\": \"expired.badssl.com\", \"cause\": \"expired\", \"visible\": \"interstitial\",\n       \"not_after\": \"Apr 12 23:59:59 2015 GMT\", \"expired_days\": 4188,\n       \"plain\": \"its security certificate expired on Apr 12, 2015, so Chrome, Safari and Firefox stop visitors with a full-page \\\"Your connection is not private\\\" warning before showing the site\"},\n      {\"host\": \"www.expired.badssl.com\", \"cause\": \"unknown\", \"visible\": \"unknown\"}\n    ]\n  },\n  \"isError\": false\n}\n```\n\nTwo things worth noticing. The `text` block is written for a model to repeat to a human as-is. The `structuredContent` block is for your code: `cause` is a small enum (`ok`, `expired`, `wrong_cert`, `self_signed`, `no_https`, `unreachable`, and a few others), `visible` tells you whether a browser shows a full-page interstitial, a \"Not secure\" label, or nothing, and `expired_days` is negative for certificates that are still valid, so \"warn me 14 days before expiry\" is one comparison.\n\nThe `www` line above says `unknown` because badssl.com does not serve that hostname at all. That is the honest answer; the tool does not guess.\n\nSame engine over plain REST, no MCP client needed:\n\n```\ncurl -s \"https://weio.ai/api/https-check?d=wrong.host.badssl.com\"\n```\n\nreturns `\"cause\": \"wrong_cert\"` with the explanation that the server presents a certificate for `*.badssl.com` instead of the requested name, which is exactly the situation you see on small-business sites where the host never installed a certificate for the domain.\n\n`expired_days > -14` or `visible != \"none\"`.\n1,000 calls for $9, key valid 12 months, emailed automatically to the address you pay with within about five minutes. Details and the checkout are on the [site-check API page](https://weio.ai/services/site-check-api.html?utm_source=devto&utm_medium=article&utm_campaign=mcp-site-check). Send the key as `Authorization: Bearer wk_...` on `/mcp` or the REST endpoint.\n\nWeio is a small company in Santa Barbara, CA where AI operators do most of the work, with a human owner accountable for it. This tool exists because we needed it ourselves. If it misbehaves on a domain, tell us at [sales@weio.ai](mailto:sales@weio.ai) with the domain and we will look at it.", "url": "https://wpnews.pro/news/a-free-mcp-tool-for-your-agent-does-this-website-s-https-actually-work-and-why", "canonical_source": "https://dev.to/weio/a-free-mcp-tool-for-your-agent-does-this-websites-https-actually-work-and-why-not-8fd", "published_at": "2026-09-30 11:31:23+00:00", "updated_at": "2026-09-30 11:47:45.112698+00:00", "lang": "en", "topics": ["ai-agents", "agent-protocols", "ai-tools", "developer-tools"], "entities": ["weio.ai", "MCP", "badssl.com", "Claude"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/a-free-mcp-tool-for-your-agent-does-this-website-s-https-actually-work-and-why", "markdown": "https://wpnews.pro/news/a-free-mcp-tool-for-your-agent-does-this-website-s-https-actually-work-and-why.md", "text": "https://wpnews.pro/news/a-free-mcp-tool-for-your-agent-does-this-website-s-https-actually-work-and-why.txt", "jsonld": "https://wpnews.pro/news/a-free-mcp-tool-for-your-agent-does-this-website-s-https-actually-work-and-why.jsonld"}}