SSLMate Cert Spotter API connects to a Nagent workspace with an API key. Once it is connected, agents can call 9 SSLMate Cert Spotter API actions, such as "Add Monitored Domain", "Get CertSpotter Event" and "Get Certificate (API v2)". Nothing is enabled on connect: each action is allowed one at a time, and an action with side effects runs or waits for a person according to the agent's level.
Every operation an agent can call against SSLMate Cert Spotter API, with input parameters and output schema.
SSLMATE_CERT_SPOTTER_API_ADD_MONITORED_DOMAINTool to add or update a monitored domain in Cert Spotter. Use when you need to enable monitoring for a new domain or update an existing one. If the domain already exists, omitted fields retain their existing values.
Input parameters
The domain name to monitor. Use a leading dot (e.g., .example.com) to monitor subdomains.
Whether monitoring is enabled for this domain. Default: true
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
SSLMATE_CERT_SPOTTER_API_AUTHORIZE_CERTIFICATETool to authorize a certificate in Cert Spotter. Use when you need to prevent future notifications for a known certificate. Once authorized, the certificate will not trigger alerts if discovered in Certificate Transparency logs.
Input parameters
Lowercase hex-encoded SHA-256 hash of the TBSCertificate to authorize. Must be exactly 64 hexadecimal characters.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
SSLMATE_CERT_SPOTTER_API_AUTHORIZE_PUBLIC_KEYTool to authorize a public key in Cert Spotter. Use when you need to prevent notifications for certificates using a specific public key. Authorizing a key before certificate issuance avoids race conditions.
Input parameters
List of DNS names for which the public key is authorized. Cert Spotter will not send notifications for certificates using this key on these domains.
Lowercase hex-encoded SHA-256 hash of the public key to authorize. The hash is computed over the DER-encoded subject public key info.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
SSLMATE_CERT_SPOTTER_API_CERTSPOTTER_GET_EVENTTool to retrieve detailed information about a specific CertSpotter certificate issuance. Use when you need to inspect certificate metadata after confirming an issuance ID.
Input parameters
The unique identifier of the CertSpotter issuance/event to retrieve.
Whether to expand and include issuer details in the response.
Whether to include the base64 DER-encoded certificate in the response.
Whether to expand and include DNS names in the response.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
SSLMATE_CERT_SPOTTER_API_DELETE_MONITORED_DOMAINTool to delete a monitored domain from Cert Spotter. Use when you need to remove a domain from monitoring. Returns success confirmation on deletion (HTTP 204). Returns 404 if domain not found.
Input parameters
The monitored domain name to delete (e.g., '.example.com' for wildcard or 'example.com' for exact match)
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
SSLMATE_CERT_SPOTTER_API_GET_CERTIFICATE_V2Tool to retrieve certificate information by common name (domain). Use when you need to inspect certificate metadata, status, or configuration for a specific domain.
Input parameters
The certificate common name (domain) to retrieve, e.g., 'example.com'
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
SSLMATE_CERT_SPOTTER_API_GET_MONITORED_DOMAINTool to retrieve a specific monitored domain by its name. Use when you need to check the monitoring status of a domain.
Input parameters
The monitored domain name. Use a leading dot (e.g., .example.com) to include subdomains.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
SSLMATE_CERT_SPOTTER_API_LIST_CT_ISSUANCESTool to list certificate issuances for a domain from Certificate Transparency logs. Use when you need to discover all unexpired certificates issued for a domain or its subdomains.
Input parameters
Return issuances discovered after this ID (for pagination). Use the ID from the last issuance of the previous page.
Domain name to search for certificate issuances (e.g., example.com)
Comma-separated list of fields to expand in response. Options: dns_names, issuer, cert_der, pubkey_der, pubkey, revocation, problem_reporting
Include wildcard certificates that match the domain. Default: false
Include certificates for subdomains of the specified domain. Default: false
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
SSLMATE_CERT_SPOTTER_API_LIST_MONITORED_DOMAINSTool to list all monitored domains. Use when you need to audit or review the domains currently monitored by Cert Spotter.
Output
Data from the action execution
Error if any occurred during the execution of the action
Whether or not the action execution was successful or not
Agents can call 9 SSLMate Cert Spotter API actions on Nagent, including "Add Monitored Domain", "Get CertSpotter Event" and "Get Certificate (API v2)". Add Monitored Domain: Add or update a monitored domain in Cert Spotter. Each action is listed on this page with its input parameters and its output.
SSLMate Cert Spotter API connects with an API key, under your workspace's own connection. Nothing is enabled on connect: each action is allowed one at a time and can be scoped to the agents that need it.
Add Monitored Domain takes 1 required input: name. It also takes 1 optional input: enabled. It returns data, error and successful.