A free MCP tool for your agent: does this website's HTTPS actually work, and why not?
If you build agents that touch other people's websites (lead research, monitoring, support bots), one question keeps coming up: does this site open securely in a browser, or does it throw "Your connection is not private"? Answering it from inside an agent means shelling out to openssl s_client, pars

If you build agents that touch other people's websites (lead research, monitoring, support bots), one question keeps coming up: does this site open securely in a browser, or does it throw "Your connection is not private"? Answering it from inside an agent means shelling out to openssl s_client, parsing dates, handling www. separately and translating the result into words a non-engineer understands. We run that check for our own outreach a few thousand times a week, so we put it behind an MCP server. This post shows how to call it, what it returns, and where it is deliberately limited. Endpoint: https://weio.ai/mcp, streamable HTTP, stateless. Nothing to install. Tools: check_https (certificate / privacy-warning diagnosis for example.com and www.example.com) and site_info (what a business publishes on its homepage: title, CMS, mobile viewport tag, role emails like info@, phones, social links). Free tier: 10 calls a day without a key. A key ($9 for 1,000 calls, valid 12 months) is optional. Listed in the official MCP registry as ai.weio/site-check. Both tools are annotated readOnlyHint: true, so clients that gate side-effecting tools will not prompt for them. claude mcp add --transport http weio-site-check https://weio.ai/mcp Then ask: "Check whether expired.badssl.com opens securely and explain the problem in one sentence." Any MCP client that speaks streamable HTTP works the same way; point it at the URL above. If your client wants a JSON config: { "mcpServers": { "weio-site-check": { "type": "http", "url": "https://weio.ai/mcp" } } } List the tools: curl -s -X POST https://weio.ai/mcp \ -H 'Content-Type: application/json' \ -H 'Accept: application/json, text/event-stream' \ -d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' Call check_https on a site with an expired certificate: curl -s -X POST https://weio.ai/mcp \ -H 'Content-Type: application/json' \ -H 'Accept: application/json, text/event-stream' \ -d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"check_https","arguments":{"domain":"expired.badssl.com"}}}' What came back when I ran it today (trimmed): { "content": [{"type": "text", "text": "expired.badssl.com: expired (browser warning: interstitial). its security certificate expired on Apr 12, 2015, so Chrome, Safari and Firefox stop visitors with a full-page \"Your connection is not private\" warning before showing the site\nwww.expired.badssl.com: unknown (browser warning: unknown).\nFree tier (10/day). ..."}], "structuredContent": { "domain": "expired.badssl.com", "results": [ {"host": "expired.badssl.com", "cause": "expired", "visible": "interstitial", "not_after": "Apr 12 23:59:59 2015 GMT", "expired_days": 4188, "plain": "its security certificate expired on Apr 12, 2015, so Chrome, Safari and Firefox stop visitors with a full-page \"Your connection is not private\" warning before showing the site"}, {"host": "www.expired.badssl.com", "cause": "unknown", "visible": "unknown"} ] }, "isError": false } Two things worth noticing. The text block is written for a model to repeat to a human as-is. The structuredContent block is for your code: cause is a small enum (ok, expired, wrong_cert, self_signed, no_https, unreachable, and a few others), visible tells you whether a browser shows a full-page interstitial, a "Not secure" label, or nothing, and expired_days is negative for certificates that are still valid, so "warn me 14 days before expiry" is one comparison. The www line above says unknown because badssl.com does not serve that hostname at all. That is the honest answer; the tool does not guess. Same engine over plain REST, no MCP client needed: curl -s "https://weio.ai/api/https-check?d=wrong.host.badssl.com" returns "cause": "wrong_cert" with the explanation that the server presents a certificate for *.badssl.com instead of the requested name, which is exactly the situation you see on small-business sites where the host never installed a certificate for the domain. Lead research. Before an agent drafts an email to a prospect, it can check whether the prospect's site is even reachable and secure. A broken certificate is a concrete, verifiable thing to talk about; "your site could be better" is not. Fleet monitoring without a monitoring product. A weekly cron that loops over your client domains, calls check_https, and opens a ticket when expired_days > -14 or visible != "none". Support bots. When a user says "my site shows a privacy warning", the bot can call the tool and reply with the actual cause instead of a generic checklist. site_info for enrichment. CMS, mobile viewport yes/no and the role emails a business publishes, from one homepage fetch. Personal-name addresses are intentionally excluded. You are responsible for using contact data lawfully (CAN-SPAM, GDPR where it applies). Public websites only. IP addresses, private ranges and non-standard ports are refused. site_info reads one homepage (up to 1.5 MB). It does not crawl. 30 calls a minute per key. A call that cannot run because the server is busy is not charged. No uptime guarantee. This is a small company's server, not a monitoring service. If it is down or wrong for you, unused credits are refunded. One call = one domain, either tool. 1,000 calls for $9, key valid 12 months, emailed automatically to the address you pay with within about five minutes. Details and the checkout are on the site-check API page. Send the key as Authorization: Bearer wk_... on /mcp or the REST endpoint. Weio is a small company in Santa Barbara, CA where AI operators do most of the work, with a human owner accountable for it. This tool exists because we needed it ourselves. If it misbehaves on a domain, tell us at sales@weio.ai with the domain and we will look at it.
Key Takeaways
- •If you build agents that touch other people's websites (lead research, monitoring, support bots), one question keeps coming up: does this site open securely in a browser, or does it throw "Your connection is not private"? Answering it from inside an agent means shelling out to openssl s_client, pars
- •This story was reported by Dev.to, covering developments in the dev space.
- •AI advancements continue to reshape industries — read the full article on Dev.to for complete coverage.
📖 Continue reading the full article:
Read Full Article on Dev.to →


