# GET /api/v1/ssl

> SSL certificate status for a domain

- Group: ssl
- Tier: R
- Required scope: read:hosting
- Docs: https://api.inleed.com/reference/ssl/get-ssl-status

## Description

Returns issuer, `validFrom`/`validTo`, `daysRemaining`, `expired`, whether the certificate is self-signed, and the hostnames it covers. Never returns the private key or the raw pem.

## Query parameters

- `input` — string (required). A domain, email address, website URL, or Inleed service id — for example example.se, info@example.se or 42976. Resolved to the owning account automatically, and the resolved target is echoed back in the response. Up to 255 characters.

## Request

```bash
curl -X GET "https://mcp.inleed.com/api/v1/ssl?input=example.se" \
  -H "Authorization: Bearer inl_live_…"
```

## Errors

- **400**  — codes: invalid_request
- **401** No token was presented, or the token is revoked, expired or unknown. — codes: unauthorized, token_expired, token_revoked
- **403** The token lacks a required scope, or this account does not own the resource. — codes: insufficient_scope, domain_not_owned
- **404** No such resource for this account. — codes: not_found
- **422** Validation error — codes: validation_failed
- **429** The rate limit for this token is exhausted. See `Retry-After`. — codes: rate_limited
- **500** Something went wrong on our side. The failure is logged against `requestId`. — codes: internal_error

## Related

- GET /api/v1/ssl/detail — https://api.inleed.com/reference/ssl/get-ssl-detail
- GET /api/v1/ssl/actions/request-letsencrypt — https://api.inleed.com/reference/ssl/precheck-lets-encrypt
- POST /api/v1/ssl/actions/create-csr — https://api.inleed.com/reference/ssl/create-csr
- POST /api/v1/ssl/actions/request-letsencrypt — https://api.inleed.com/reference/ssl/request-ssl-certificate

