# A free MCP tool for your agent: does this website's HTTPS actually work, and why not?

> Source: <https://dev.to/weio/a-free-mcp-tool-for-your-agent-does-this-websites-https-actually-work-and-why-not-8fd>
> Published: 2026-09-30 11:31:23+00:00

If you build agents that touch other people's websites (lead research, monitoring, support bots), one question keeps coming up: **does this site open securely in a browser, or does it throw "Your connection is not private"?** Answering it from inside an agent means shelling out to `openssl s_client`, parsing dates, handling `www.` separately and translating the result into words a non-engineer understands.

We run that check for our own outreach a few thousand times a week, so we put it behind an MCP server. This post shows how to call it, what it returns, and where it is deliberately limited.

`https://weio.ai/mcp`, streamable HTTP, stateless. Nothing to install.` check_https` (certificate / privacy-warning diagnosis for `example.com` and `www.example.com`) and `site_info` (what a business publishes on its homepage: title, CMS, mobile viewport tag, role emails like `info@`, phones, social links).` ai.weio/site-check`.` readOnlyHint: true`, so clients that gate side-effecting tools will not prompt for them.

```
claude mcp add --transport http weio-site-check https://weio.ai/mcp
```

Then ask: *"Check whether expired.badssl.com opens securely and explain the problem in one sentence."* Any MCP client that speaks streamable HTTP works the same way; point it at the URL above. If your client wants a JSON config:

```
{ "mcpServers": { "weio-site-check": { "type": "http", "url": "https://weio.ai/mcp" } } }
```

List the tools:

```
curl -s -X POST https://weio.ai/mcp \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'
```

Call `check_https` on a site with an expired certificate:

```
curl -s -X POST https://weio.ai/mcp \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"check_https","arguments":{"domain":"expired.badssl.com"}}}'
```

What came back when I ran it today (trimmed):

```
{
  "content": [{"type": "text", "text": "expired.badssl.com: expired (browser warning: interstitial). its security certificate expired on Apr 12, 2015, so Chrome, Safari and Firefox stop visitors with a full-page \"Your connection is not private\" warning before showing the site\nwww.expired.badssl.com: unknown (browser warning: unknown).\nFree tier (10/day). ..."}],
  "structuredContent": {
    "domain": "expired.badssl.com",
    "results": [
      {"host": "expired.badssl.com", "cause": "expired", "visible": "interstitial",
       "not_after": "Apr 12 23:59:59 2015 GMT", "expired_days": 4188,
       "plain": "its security certificate expired on Apr 12, 2015, so Chrome, Safari and Firefox stop visitors with a full-page \"Your connection is not private\" warning before showing the site"},
      {"host": "www.expired.badssl.com", "cause": "unknown", "visible": "unknown"}
    ]
  },
  "isError": false
}
```

Two things worth noticing. The `text` block is written for a model to repeat to a human as-is. The `structuredContent` block is for your code: `cause` is a small enum (`ok`, `expired`, `wrong_cert`, `self_signed`, `no_https`, `unreachable`, and a few others), `visible` tells you whether a browser shows a full-page interstitial, a "Not secure" label, or nothing, and `expired_days` is negative for certificates that are still valid, so "warn me 14 days before expiry" is one comparison.

The `www` line above says `unknown` because badssl.com does not serve that hostname at all. That is the honest answer; the tool does not guess.

Same engine over plain REST, no MCP client needed:

```
curl -s "https://weio.ai/api/https-check?d=wrong.host.badssl.com"
```

returns `"cause": "wrong_cert"` with the explanation that the server presents a certificate for `*.badssl.com` instead of the requested name, which is exactly the situation you see on small-business sites where the host never installed a certificate for the domain.

`expired_days > -14` or `visible != "none"`.
1,000 calls for $9, key valid 12 months, emailed automatically to the address you pay with within about five minutes. Details and the checkout are on the [site-check API page](https://weio.ai/services/site-check-api.html?utm_source=devto&utm_medium=article&utm_campaign=mcp-site-check). Send the key as `Authorization: Bearer wk_...` on `/mcp` or the REST endpoint.

Weio is a small company in Santa Barbara, CA where AI operators do most of the work, with a human owner accountable for it. This tool exists because we needed it ourselves. If it misbehaves on a domain, tell us at [sales@weio.ai](mailto:sales@weio.ai) with the domain and we will look at it.
