> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sreagent.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a certificate monitor

> Watch a hostname's TLS certificate. The platform opens a TLS connection to hostname:port every check_interval_hours, records what it found, and raises an alert once the certificate is within warn_days_before of expiry and a sharper one within critical_days_before. It alerts on a certificate that fails verification too, whatever its expiry date says: an untrusted chain or a wrong-host certificate is already failing for everything that checks one. warn_days_before must be greater than critical_days_before, or a certificate between the two would be announced as the milder of the two problems. The first check runs shortly after; check_certificate_now runs one at once. Needs the infrastructure suite.



## OpenAPI

````yaml /api-reference/openapi.json post /certificate_monitors
openapi: 3.1.0
info:
  description: >-
    A resource-shaped endpoint onto the same tool surface the MCP server
    (/api/mcp) reaches. Every gate, refusal and audit row a caller sees here is
    the exact one the MCP endpoint answers for the same tool. Authenticated with
    an API key holding the api:admin scope, or the read-only api:config_read
    scope for GET alone.
  title: SRE Agent configuration API
  version: 1.0.0
servers:
  - url: https://sreagent.app/api/v1/config
security:
  - apiKey: []
tags:
  - name: ai_providers
  - name: ai_settings
  - name: alert_mutes
  - name: alert_routes
  - name: aws_external_id
  - name: certificate_monitors
  - name: change_notifications
  - name: compliance_periods
  - name: connectors
  - name: data_sources
  - name: deploy_policies
  - name: export
  - name: github_settings
  - name: image_targets
  - name: notification_settings
  - name: organization_settings
  - name: outbound_configs
  - name: outbound_rules
  - name: overseer_settings
  - name: prompt_templates
  - name: repo_settings
  - name: service_bindings
  - name: slack
  - name: slis
  - name: slos
  - name: status_page_components
  - name: status_page_incidents
  - name: status_page_settings
  - name: synthetic_checks
  - name: team_members
  - name: teams
  - name: ticket_import_rules
  - name: ticket_integrations
paths:
  /certificate_monitors:
    post:
      tags:
        - certificate_monitors
      summary: Create a certificate monitor
      description: >-
        Watch a hostname's TLS certificate. The platform opens a TLS connection
        to hostname:port every check_interval_hours, records what it found, and
        raises an alert once the certificate is within warn_days_before of
        expiry and a sharper one within critical_days_before. It alerts on a
        certificate that fails verification too, whatever its expiry date says:
        an untrusted chain or a wrong-host certificate is already failing for
        everything that checks one. warn_days_before must be greater than
        critical_days_before, or a certificate between the two would be
        announced as the milder of the two problems. The first check runs
        shortly after; check_certificate_now runs one at once. Needs the
        infrastructure suite.
      operationId: create_certificate_monitor
      parameters: []
      requestBody:
        content:
          application/json:
            schema:
              properties:
                check_interval_hours:
                  description: How often to check, at least 1. Default 24.
                  type: integer
                critical_days_before:
                  description: >-
                    Days of validity left that raise the sharper one. Default 7,
                    and it must be below warn_days_before.
                  type: integer
                hostname:
                  description: >-
                    The host to connect to, 1 to 253 characters. A wildcard
                    certificate has no host to dial, so name a concrete one.
                  type: string
                port:
                  description: 1 to 65535. Default 443.
                  type: integer
                warn_days_before:
                  description: >-
                    Days of validity left that raise the first alert. Default
                    30.
                  type: integer
              required:
                - hostname
              type: object
        required: true
      responses:
        '201':
          description: Created.
        '409':
          description: A row already matches this resource's natural key.
        '422':
          description: The tool refused the request's shape or content.
        default:
          description: The request failed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    Error:
      type: object
      description: The body of every failed request.
      properties:
        error:
          type: string
          description: >-
            A short machine-readable code such as forbidden, conflict or
            read_only_key.
        message:
          type: string
          description: A sentence that says what to change.
      required:
        - error
        - message
      additionalProperties: true
  securitySchemes:
    apiKey:
      description: >-
        An sre_ak_* API key holding the api:admin scope (or api:config_read,
        which every write refuses with read_only_key).
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.