All integrations
SSL Labs logo

SSL Labs

Compliance & SecurityMonitoring

Test any public HTTPS server with Qualys SSL Labs, the free TLS assessment behind ssllabs.com, and act on what it finds. Scan a host for its A+ to F grade, read the certificate chain, protocols, cipher suites and HSTS policy of every IP behind the name, and get every vulnerability test decoded into plain words rather than the result codes the API returns. Purpose-built checks answer the two questions a monitor asks: how many days the certificate has left, and whether the grade still clears the bar you set. Assessments run on Qualys's servers and are free for testing infrastructure you operate; commercial use needs their permission.

12 actions

Actions

Steps your workflow can run in SSL Labs.

Scan a hostAssess a host's TLS configuration and wait for the result: the grade for every IP behind the hostname, the certificate chain, the protocols and cipher suites on offer and the vulnerability tests. Uses a stored report when there is a recent one and runs a fresh assessment otherwise, so a scheduled check is cheap to repeat.
Start a scanStart a fresh assessment and return straight away, without waiting for it. For a host that takes longer to assess than a step should sit and wait: start it here, then read the result later with 'Check scan progress' or 'Get the last report'.
Check scan progressAsk how a running assessment is getting on: the status, how far through each endpoint is and how long SSL Labs thinks is left. Never starts a new assessment, so it is safe to call on a loop while one runs.
Get the last reportRead the report SSL Labs already holds for a host, without waiting. The cheapest way to read a grade. If nothing recent enough is stored, SSL Labs starts an assessment and this returns its status rather than waiting for it.
Get endpoint detailsThe full assessment of one IP address behind a hostname: its grade, protocols, cipher suites, HSTS policy, certificate chain and every vulnerability test. A hostname on a CDN can answer from a dozen addresses with different configurations, and this reads one of them. Never starts an assessment.
Check certificate expiryHow many days a host's certificate has left, and whether that is inside the window you set. The renewal alarm: point a scheduled workflow at it and branch on 'is_expiring_soon'. Reads a stored report where there is one, so it is cheap to run daily.
Check the gradeCheck a host's SSL Labs grade against the lowest grade you will accept, and answer with whether it clears the bar. The gate for a deployment check or a compliance report: it looks at every endpoint, so one badly configured server in a pool cannot hide behind the others.
List vulnerabilitiesEvery vulnerability test SSL Labs ran on a host, endpoint by endpoint, in plain words: Heartbleed, ROBOT, POODLE, GOLDENDOODLE, Ticketbleed, DROWN, FREAK, Logjam, BEAST and the rest, each with its result and whether the server is actually vulnerable. Also reports obsolete protocols and how many weak or insecure cipher suites are on offer.
Get service statusWhether SSL Labs is up, which grading criteria it is applying and how many assessments this registration may run at once against how many are already running. Run it before a batch of scans to see how many will fit.
List assessment status codesThe codes an assessment reports while it runs, with what each one means. 'Check scan progress' returns a code such as TESTING_HEARTBLEED, and this is the table that turns it into 'Testing Heartbleed'.
List root certificatesThe root certificates in one of the five trust stores SSL Labs validates chains against: Mozilla, Apple macOS, Android, Java and Windows. Each root comes back with its name, subject, key and validity dates, and the days it has left, so you can see which roots are about to age out. The PEM itself is left out unless you ask for it.
Register for API accessRegister an email address for SSL Labs API access. Connecting this integration already registers the address you connected with, so this is for registering a second one. SSL Labs does not accept free mail domains such as Gmail, Yahoo or Hotmail: the address has to be an organization one.

Connect in a few clicks

Authenticate once and every action and trigger for the app is ready to drop into a workflow. No glue code, no maintenance.

Automate across your stack

Chain apps together with triggers, actions, and logic that move data between your tools automatically, so work happens without you.

Secure by default

Credentials are encrypted and scoped per workspace. Connect the tools your team already trusts with confidence.

Automate SSL Labs with Lodol.

Connect SSL Labs and build your first workflow in minutes. No credit card required.

Free plan available · No credit card required