openapi: 3.2.0 info: title: 2s — the (most) everything Tls API version: '1' summary: The (most) everything API. description: 'The (most) everything API for AI agents: 575+ pay-per-call endpoints on one origin.' contact: name: 2s url: https://2s.io email: alley@2s.io x-logo: url: https://2s.io/icon-512.png altText: 2s x-guidance: 'Pay-per-call REST API for AI agents — hundreds of endpoints returning ground-truth data (US public records, company & legal identifiers, finance/SEC, crypto/web3, security & CVEs, medical codes, weather & geocoding, agriculture, energy, maritime, music, and more). Every endpoint is paid per call in USDC via x402 (Base or Solana) — no API key, no signup. Call any endpoint with no auth to get a 402 PaymentRequirements envelope, sign it (EIP-3009 on Base, partial SPL transfer on Solana), and retry with the PAYMENT-SIGNATURE header. Add ?trial=1 for one free real call per endpoint per hour to test before paying. To discover the right endpoint: GET https://2s.io/api/directory for the full catalog, or GET https://2s.io/api/search/endpoints?q= for a ranked match. Per-call price is on each operation as x-payment-info (from $0.001). Batch up to 50 calls behind one payment via POST https://2s.io/api/batch/run.' servers: - url: https://2s.io tags: - name: tls paths: /api/tls/cert-info: get: tags: - tls summary: Open a live TLS connection to a host and return its description: 'Open a live TLS connection to a host and return its certificate. Give a host (and optional port, default 443). Returns the negotiated TLS protocol + cipher, whether the chain validates against system roots, and the leaf certificate''s subject + issuer (CN/O/C), validity window (valid-from / valid-to), days until expiry + expired flag, serial number, SHA-256 fingerprint, Subject Alternative Names, and the chain length. A genuine network probe agents can''t do from their sandbox — for cert-expiry monitoring, TLS audits, and verifying who issued a site''s certificate. SSRF-guarded: the host must resolve to a public address. Self-signed and expired certs are reported (not rejected).' operationId: tls_cert-info deprecated: false security: - x402Payment: [] responses: '200': description: 'Normalized envelope: items = [certificate probe] (host, port, protocol, cipher, chain validity, leaf cert subject/issuer/validity/SANs); total = 1.' content: application/json: schema: type: object required: - data - meta properties: data: type: object properties: ok: type: boolean enum: - true items: type: array items: type: object properties: host: type: string port: type: number resolvedIp: type: string protocol: type: string nullable: true cipher: type: object properties: name: type: string nullable: true version: type: string nullable: true required: - name - version additionalProperties: false nullable: true authorized: type: boolean authorizationError: type: string nullable: true certificate: type: object properties: subject: type: object additionalProperties: {} issuer: type: object additionalProperties: {} validFrom: type: string nullable: true validTo: type: string nullable: true daysUntilExpiry: type: number nullable: true expired: type: boolean serialNumber: type: string nullable: true fingerprintSha256: type: string nullable: true subjectAltNames: type: array items: type: string isCa: type: boolean nullable: true required: - subject - issuer - validFrom - validTo - daysUntilExpiry - expired - serialNumber - fingerprintSha256 - subjectAltNames - isCa additionalProperties: false chainLength: type: number required: - host - port - resolvedIp - protocol - cipher - authorized - authorizationError - certificate - chainLength additionalProperties: false total: type: integer nullable: true description: Total matching rows upstream; null when unknown. source: $ref: '#/components/schemas/Source' required: - ok - items - total - source additionalProperties: false meta: $ref: '#/components/schemas/CallMeta' '400': $ref: '#/components/responses/BadRequest' '402': $ref: '#/components/responses/PaymentRequired' '405': $ref: '#/components/responses/MethodNotAllowed' '500': $ref: '#/components/responses/ServerError' '502': $ref: '#/components/responses/UpstreamError' x-2s-id: tls.cert-info x-2s-version: null x-2s-price: usd: 0.0025 x-2s-accepts: - x402 x-2s-response-shape: normalized x-payment-info: price: mode: fixed currency: USD amount: '0.002500' protocols: - x402: {} parameters: - name: host in: query required: true description: Hostname to look up. schema: type: string minLength: 1 maxLength: 253 - name: port in: query required: false description: Port. schema: type: integer minimum: 1 maximum: 65535 default: 443 - $ref: '#/components/parameters/TrialMode' components: schemas: Source: type: object description: 'Provenance of the data: upstream provider, source URL, and license.' properties: provider: type: string description: Upstream data provider. url: type: string description: Source URL or documentation link. license: type: string description: License / usage terms for the data. CallMeta: type: object description: Per-call meta envelope — endpoint id, cost, caller kind, settlement details. X402PaymentRequiredV2: type: object description: x402 v2 PaymentRequired envelope. Pick any entry from accepts[], sign for that rail, retry with the PAYMENT-SIGNATURE header. required: - x402Version - accepts properties: x402Version: type: integer const: 2 error: type: string description: Human-readable reason payment is required. resource: type: string description: The resource URL being purchased. accepts: type: array description: Payment requirement options, one per supported network (Base USDC, Solana USDC). items: type: object required: - scheme - network - amount - asset - payTo - maxTimeoutSeconds properties: scheme: type: string enum: - exact network: type: string description: CAIP-2 network id, e.g. "eip155:8453" (Base) or "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp". amount: type: string description: Price in atomic asset units (USDC has 6 decimals). asset: type: string description: Asset contract address / mint. payTo: type: string description: Treasury address to pay. maxTimeoutSeconds: type: integer extra: type: object description: 'Rail-specific extras (EVM: EIP-712 domain name/version; Solana: feePayer).' additionalProperties: true extensions: type: object description: Optional discovery metadata (e.g. bazaar input/output schemas). additionalProperties: true responses: PaymentRequired: description: Payment required. Body contains the x402 PaymentRequirements envelope with a multi-network accepts array; the per-call price is in accepts[].amount (and on the operation as x-2s-price). Sign for whichever rail you hold USDC on (EIP-3009 for Base, partial SPL transfer for Solana) and retry with the PAYMENT-SIGNATURE header (X-PAYMENT also accepted for v1 clients). content: application/json: schema: $ref: '#/components/schemas/X402PaymentRequiredV2' UpstreamError: description: Upstream provider error. MethodNotAllowed: description: Method not allowed — see `Allow` header for the supported method. ServerError: description: Internal server error. BadRequest: description: Bad request — invalid parameters. parameters: TrialMode: name: trial in: query required: false description: 'Try before you buy. Set to 1 for one free real call per endpoint per hour — no wallet or payment needed — to verify the endpoint before paying. Equivalent to sending the "X-2s-Trial: 1" request header. Works on every endpoint.' schema: type: integer enum: - 1 securitySchemes: x402Payment: type: apiKey in: header name: PAYMENT-SIGNATURE description: 'x402 protocol v2: base64-encoded PaymentPayload. Call any paid endpoint without auth to receive a 402 with a multi-network PaymentRequirements envelope. Sign for either rail: EIP-3009 transferWithAuthorization (Base USDC) OR a partial SPL token transfer (Solana USDC). Retry with PAYMENT-SIGNATURE header. X-PAYMENT is also accepted for v1 buyer clients. See https://x402.org.'