How to hit the crt.sh API

crt.sh by Sectigo searches Certificate Transparency logs: every publicly trusted TLS certificate issued for a domain. Useful for finding subdomains and spotting unexpected certificates.

Authentication

None — no key, no signup. Every example runs as-is.

Full reference: https://crt.sh/

Certificates for a domain

%25. is a URL-encoded %. wildcard for subdomains.

curl "https://crt.sh/?q=%25.posttaco.dev&output=json"
Run in PostTaco
Example response (trimmed)
[
  {
    "issuer_ca_id": 413869,
    "issuer_name": "C=US, O=SSL Corporation, CN=Cloudflare TLS Issuing ECC CA 4",
    "common_name": "posttaco.dev",
    "name_value": "*.posttaco.dev\nposttaco.dev",
    "id": 28867657156,
    "not_before": "2026-08-15T04:03:45",
    "not_after": "2026-11-12T17:28:04",
    "serial_number": "509ff0c015192c0d26fb9fd58e4dd4d0",
    "result_count": 3
  },
  {
    "issuer_ca_id": 286236,
    "issuer_name": "C=US, O=Google Trust Services, CN=WE1",
    "common_name": "www.posttaco.dev",
    "name_value": "www.posttaco.dev",
    "id": 28913856085,
    "not_before": "2026-08-14T18:33:56",
    "not_after": "2026-11-12T19:33:51",
    "serial_number": "00bb0b9e9c24f4a1c913d36b46fa244b75",
    "result_count": 2
  }
]