> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sreagent.app/llms.txt
> Use this file to discover all available pages before exploring further.

# List certificate monitors

> List the TLS certificates this organization watches, with the newest check beside each one: last_status, days_until_expiry and expires_at. A monitor no check has run against yet answers last_status "unchecked". `discovered` is true for a monitor Kubernetes or ACM discovery filed rather than a person, which is the monitor discovery proposes again after a delete. Optionally filter by enabled, or by that flag. Needs the infrastructure suite.



## OpenAPI

````yaml /api-reference/openapi.json get /certificate_monitors
openapi: 3.1.0
info:
  description: >-
    A resource-shaped endpoint onto the same tool surface the MCP server
    (/api/mcp) reaches. Every gate, refusal and audit row a caller sees here is
    the exact one the MCP endpoint answers for the same tool. Authenticated with
    an API key holding the api:admin scope, or the read-only api:config_read
    scope for GET alone.
  title: SRE Agent configuration API
  version: 1.0.0
servers:
  - url: https://sreagent.app/api/v1/config
security:
  - apiKey: []
tags:
  - name: ai_providers
  - name: ai_settings
  - name: alert_mutes
  - name: alert_routes
  - name: aws_external_id
  - name: certificate_monitors
  - name: change_notifications
  - name: compliance_periods
  - name: connectors
  - name: data_sources
  - name: deploy_policies
  - name: export
  - name: github_settings
  - name: image_targets
  - name: notification_settings
  - name: organization_settings
  - name: outbound_configs
  - name: outbound_rules
  - name: overseer_settings
  - name: prompt_templates
  - name: repo_settings
  - name: service_bindings
  - name: slack
  - name: slis
  - name: slos
  - name: status_page_components
  - name: status_page_incidents
  - name: status_page_settings
  - name: synthetic_checks
  - name: team_members
  - name: teams
  - name: ticket_import_rules
  - name: ticket_integrations
paths:
  /certificate_monitors:
    get:
      tags:
        - certificate_monitors
      summary: List certificate monitors
      description: >-
        List the TLS certificates this organization watches, with the newest
        check beside each one: last_status, days_until_expiry and expires_at. A
        monitor no check has run against yet answers last_status "unchecked".
        `discovered` is true for a monitor Kubernetes or ACM discovery filed
        rather than a person, which is the monitor discovery proposes again
        after a delete. Optionally filter by enabled, or by that flag. Needs the
        infrastructure suite.
      operationId: list_certificate_monitors
      parameters: []
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  data:
                    items:
                      $ref: '#/components/schemas/certificate_monitors_row'
                    type: array
                  organization:
                    type: object
                  truncated:
                    type: boolean
                type: object
          description: The organization's rows.
        default:
          description: The request failed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    certificate_monitors_row:
      properties:
        check_interval_hours:
          type:
            - integer
            - 'null'
        critical_days_before:
          type:
            - integer
            - 'null'
        days_until_expiry:
          type:
            - integer
            - 'null'
        discovered:
          type: boolean
        enabled:
          type: boolean
        expires_at:
          type:
            - string
            - 'null'
        hostname:
          type: string
        id:
          type: string
        last_checked_at:
          type:
            - string
            - 'null'
        last_error:
          type:
            - string
            - 'null'
        last_status:
          type: string
        port:
          type:
            - integer
            - 'null'
        updated_at:
          type: string
        warn_days_before:
          type:
            - integer
            - 'null'
      required:
        - hostname
        - port
        - check_interval_hours
        - warn_days_before
        - critical_days_before
        - days_until_expiry
        - discovered
        - enabled
        - expires_at
        - id
        - last_checked_at
        - last_error
        - last_status
        - updated_at
      type: object
    Error:
      type: object
      description: The body of every failed request.
      properties:
        error:
          type: string
          description: >-
            A short machine-readable code such as forbidden, conflict or
            read_only_key.
        message:
          type: string
          description: A sentence that says what to change.
      required:
        - error
        - message
      additionalProperties: true
  securitySchemes:
    apiKey:
      description: >-
        An sre_ak_* API key holding the api:admin scope (or api:config_read,
        which every write refuses with read_only_key).
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.