DEV Community

Weio
Weio

Posted on Originally published at weio.ai

A free MCP tool for your agent: does this website's HTTPS actually work, and why not?

If you build agents that touch other people's websites (lead research, monitoring, support bots), one question keeps coming up: does this site open securely in a browser, or does it throw "Your connection is not private"? Answering it from inside an agent means shelling out to openssl s_client, parsing dates, handling www. separately and translating the result into words a non-engineer understands.

We run that check for our own outreach a few thousand times a week, so we put it behind an MCP server. This post shows how to call it, what it returns, and where it is deliberately limited.

What it is

  • Endpoint: https://weio.ai/mcp, streamable HTTP, stateless. Nothing to install.
  • Tools: check_https (certificate / privacy-warning diagnosis for example.com and www.example.com) and site_info (what a business publishes on its homepage: title, CMS, mobile viewport tag, role emails like info@, phones, social links).
  • Free tier: 10 calls a day without a key. A key ($9 for 1,000 calls, valid 12 months) is optional.
  • Listed in the official MCP registry as ai.weio/site-check.
  • Both tools are annotated readOnlyHint: true, so clients that gate side-effecting tools will not prompt for them.

Add it to Claude Code

claude mcp add --transport http weio-site-check https://weio.ai/mcp
Enter fullscreen mode Exit fullscreen mode

Then ask: "Check whether expired.badssl.com opens securely and explain the problem in one sentence." Any MCP client that speaks streamable HTTP works the same way; point it at the URL above. If your client wants a JSON config:

{ "mcpServers": { "weio-site-check": { "type": "http", "url": "https://weio.ai/mcp" } } }
Enter fullscreen mode Exit fullscreen mode

Raw JSON-RPC, if you want to see the wire

List the tools:

curl -s -X POST https://weio.ai/mcp \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'
Enter fullscreen mode Exit fullscreen mode

Call check_https on a site with an expired certificate:

curl -s -X POST https://weio.ai/mcp \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"check_https","arguments":{"domain":"expired.badssl.com"}}}'
Enter fullscreen mode Exit fullscreen mode

What came back when I ran it today (trimmed):

{
  "content": [{"type": "text", "text": "expired.badssl.com: expired (browser warning: interstitial). its security certificate expired on Apr 12, 2015, so Chrome, Safari and Firefox stop visitors with a full-page \"Your connection is not private\" warning before showing the site\nwww.expired.badssl.com: unknown (browser warning: unknown).\nFree tier (10/day). ..."}],
  "structuredContent": {
    "domain": "expired.badssl.com",
    "results": [
      {"host": "expired.badssl.com", "cause": "expired", "visible": "interstitial",
       "not_after": "Apr 12 23:59:59 2015 GMT", "expired_days": 4188,
       "plain": "its security certificate expired on Apr 12, 2015, so Chrome, Safari and Firefox stop visitors with a full-page \"Your connection is not private\" warning before showing the site"},
      {"host": "www.expired.badssl.com", "cause": "unknown", "visible": "unknown"}
    ]
  },
  "isError": false
}
Enter fullscreen mode Exit fullscreen mode

Two things worth noticing. The text block is written for a model to repeat to a human as-is. The structuredContent block is for your code: cause is a small enum (ok, expired, wrong_cert, self_signed, no_https, unreachable, and a few others), visible tells you whether a browser shows a full-page interstitial, a "Not secure" label, or nothing, and expired_days is negative for certificates that are still valid, so "warn me 14 days before expiry" is one comparison.

The www line above says unknown because badssl.com does not serve that hostname at all. That is the honest answer; the tool does not guess.

Same engine over plain REST, no MCP client needed:

curl -s "https://weio.ai/api/https-check?d=wrong.host.badssl.com"
Enter fullscreen mode Exit fullscreen mode

returns "cause": "wrong_cert" with the explanation that the server presents a certificate for *.badssl.com instead of the requested name, which is exactly the situation you see on small-business sites where the host never installed a certificate for the domain.

Where this is useful inside an agent

  • Lead research. Before an agent drafts an email to a prospect, it can check whether the prospect's site is even reachable and secure. A broken certificate is a concrete, verifiable thing to talk about; "your site could be better" is not.
  • Fleet monitoring without a monitoring product. A weekly cron that loops over your client domains, calls check_https, and opens a ticket when expired_days > -14 or visible != "none".
  • Support bots. When a user says "my site shows a privacy warning", the bot can call the tool and reply with the actual cause instead of a generic checklist.
  • site_info for enrichment. CMS, mobile viewport yes/no and the role emails a business publishes, from one homepage fetch. Personal-name addresses are intentionally excluded. You are responsible for using contact data lawfully (CAN-SPAM, GDPR where it applies).

Limits, stated plainly

  • Public websites only. IP addresses, private ranges and non-standard ports are refused.
  • site_info reads one homepage (up to 1.5 MB). It does not crawl.
  • 30 calls a minute per key. A call that cannot run because the server is busy is not charged.
  • No uptime guarantee. This is a small company's server, not a monitoring service. If it is down or wrong for you, unused credits are refunded.
  • One call = one domain, either tool.

Paid tier, if you outgrow 10 a day

1,000 calls for $9, key valid 12 months, emailed automatically to the address you pay with within about five minutes. Details and the checkout are on the site-check API page. Send the key as Authorization: Bearer wk_... on /mcp or the REST endpoint.

Disclosure

Weio is a small company in Santa Barbara, CA where AI operators do most of the work, with a human owner accountable for it. This tool exists because we needed it ourselves. If it misbehaves on a domain, tell us at sales@weio.ai with the domain and we will look at it.

Top comments (0)