Discover/crt API
live

crt APIcrt.name ↗

Query the crt.name passive subdomain index via API. Get every subdomain for an apex domain with first-seen timestamps, plus live index statistics.

Endpoint health
monitored
get_index_stats
search_subdomains
Checks pendingself-healing
Endpoints
2
Updated
2h ago

What is the crt API?

The crt.name API provides 2 endpoints that expose the crt.name passive subdomain index, built from the Certificate Transparency firehose. The search_subdomains endpoint returns every known subdomain for a given apex domain in a single call, each record carrying a first-seen ISO-8601 UTC timestamp. The get_index_stats endpoint returns the current total size of the index and a live snapshot of the most recently indexed names.

This call costs1 credit / call— charged only on success
Try it
Registrable apex domain (eTLD+1) such as example.com; must not include a subdomain prefix.
→ api.parse.bot/scraper/a1d5e246-bfcd-44fd-9a3b-bc93659fc2b6/<endpoint>
Ready to send
Fill in the parameters and hit sign in to send to see live response data here.
Call it over HTTPgrab a free API key at signup
curl -X GET 'https://api.parse.bot/scraper/a1d5e246-bfcd-44fd-9a3b-bc93659fc2b6/search_subdomains?apex=namecheap.com' \
  -H 'X-API-Key: $PARSE_API_KEY'
Python SDK · recommended

Typed, relational, agent-ready

A generated client with real types, enums, and the links between objects — the structure a flat JSON response can't carry. Autocompletes in your editor and reads cleanly to coding agents.

  • Fully typed · autocompletes
  • Objects link to objects
  • Typed errors & pagination

Typed Python client. Set up the SDK in your uv project, then pull this API’s typed client:

uv add parse-sdk
uv run parse init
uv run parse add --marketplace crt-name-api

uv run parse add --marketplace pulls a pinned snapshot of this canonical API — it won’t change underneath you. To customize it, subscribe and swap to your own copy.

"""Walkthrough: crt.name subdomain index — bounded, re-runnable."""
from parse_apis.crt_name_api import CrtName, InputFormatInvalid

client = CrtName()

# Check overall index size and the latest names from the CT firehose.
stats = client.index_stats.get()
print(f"Total indexed: {stats.total_indexed}")
for entry in stats.recent[:3]:
    print(f"  {entry.subdomain} (apex {entry.apex}, first seen {entry.first_seen})")

# Search all subdomains for an apex domain; limit= caps total items yielded.
try:
    first_sub = client.subdomains.search(apex="namecheap.com", limit=1).first()
except InputFormatInvalid:
    print("Invalid apex format")
    first_sub = None

if first_sub is not None:
    print(f"{first_sub.subdomain} — first seen {first_sub.first_seen}")

# Iterate a bounded slice of subdomains for another apex.
for sub in client.subdomains.search(apex="cloudflare.com", limit=5):
    print(sub.subdomain, sub.first_seen)

print("exercised: index_stats.get / subdomains.search")
All endpoints · 2 totalmissing one? ·

Returns every subdomain the index holds for one apex (registrable, eTLD+1) domain, each with the timestamp it was first seen in Certificate Transparency or other sources. One round trip, no pagination: the whole list comes back in a single call (hundreds of rows for a large apex). first_seen is null for names whose first sighting was not recorded. An apex that is not a registrable domain (for example a hostname with a subdomain prefix) is rejected as stale_input; an apex the index has never seen returns an empty subdomains list with count 0. The site allows roughly 100 requests per day from one network address.

Input
ParamTypeDescription
apexrequiredstringRegistrable apex domain (eTLD+1) such as example.com; must not include a subdomain prefix.
Response
{
  "type": "object",
  "fields": {
    "apex": "the normalized (lower-cased) apex that was queried",
    "count": "integer number of subdomain records returned",
    "subdomains": "array of {subdomain, first_seen}; first_seen is an ISO-8601 UTC timestamp or null when unknown"
  },
  "sample": {
    "data": {
      "apex": "namecheap.com",
      "count": 391,
      "subdomains": [
        {
          "subdomain": "namecheap.com",
          "first_seen": "2008-05-09T07:30:28Z"
        },
        {
          "subdomain": "20cl-mirror.namecheap.com",
          "first_seen": null
        }
      ]
    },
    "status": "success"
  }
}

About the crt API

Subdomain Enumeration

The search_subdomains endpoint accepts a single required parameter, apex, which must be a registrable eTLD+1 domain such as example.com — no subdomain prefix. The response includes the normalized apex, an integer count of records, and a subdomains array. Each element in that array contains a subdomain string and a first_seen timestamp (ISO-8601 UTC, or null when the source had no date). For large apexes this array can reach hundreds of entries. The entire dataset comes back in one call with no pagination.

Index Statistics

The get_index_stats endpoint takes no parameters. It returns total_indexed, an integer representing how many distinct apex domains and subdomains the index currently holds, and recent, an array of the newest indexed names. Each entry in recent includes apex, subdomain, and first_seen. Because this list reflects the live Certificate Transparency firehose, its contents change between calls and serve as a real-time window into newly issued certificates.

Data Scope and Freshness

The index is populated from Certificate Transparency logs, which means a subdomain appears here when a TLS certificate referencing it is issued or renewed. Subdomains that have never had a certificate issued against them will not appear in results. The first_seen field reflects when the name was first observed in the index, not necessarily the current DNS state of that subdomain.

Reliability & maintenance

The crt API is a managed, monitored endpoint for crt.name — not a raw scraper you maintain. Every endpoint is automatically health-checked on a schedule, and when crt.name changes and a check fails, the API is automatically queued for repair and re-verified. It is built to keep working as the site underneath it changes.

This isn't an official crt.name API — it's an independent, maintained REST wrapper over public data. Where the source has no official API (or only a limited one), Parse gives you a stable contract over a source that never promised one, and keeps it current. Need a new endpoint or field? You can revise it yourself in plain English and the agent rebuilds it against the live site in minutes — contributing the change back to the shared API is free.

Will this API break when the source site changes?+
It's built not to. Every endpoint is health-checked on a schedule with automated test probes. When the source site changes and a check fails, the API is automatically queued for repair and re-verified — that's the self-healing layer. Each API page shows when its endpoints were last verified. And because marketplace APIs are shared, any fix reaches everyone using it.
Is this an official API from the source site?+
No — Parse APIs are independent, managed REST wrappers over publicly available data. That is the point: where a site has no official API (or only a limited one), Parse gives you a maintained, monitored endpoint for that data and keeps it working as the site changes — so you get a stable contract over a source that never promised one.
Can I fix or extend this API myself if I need a new endpoint or field?+
Yes — and you don't have to wait on us. This API was generated by the Parse agent, which stays attached. Describe the change in plain English ("add an endpoint that returns reviews", "fix the price field") in the revise box on the API page or via the revise_api MCP tool, and the agent rebuilds it against the live site in minutes. Contributing the change back to the public API is free.
What happens if I call an endpoint that has an issue?+
Errors are machine-readable: a bad call returns a clean status with the list of available endpoints and a repair hint, so an agent (or you) can recover or trigger a fix instead of failing silently. Confirmed failures feed the automatic repair queue.
Common use cases
  • Enumerate all known subdomains of a target apex during an attack-surface audit using search_subdomains
  • Track newly registered or certificated subdomains by polling get_index_stats for entries in the recent array
  • Feed the subdomains list into a port scanner or DNS resolver to identify live hosts
  • Compare the subdomain count returned by count across time to detect infrastructure expansion
  • Bootstrap threat-intelligence pipelines with subdomain-to-first-seen mappings for age analysis
  • Identify shadow IT or forgotten subdomains by diffing search_subdomains results against known internal inventory
Pricing & limitsSee full pricing →
TierPriceCredits/monthRate limit
Free$0/mo2005 req/min
Hobby$30/mo1,00020 req/min
Developer$100/mo5,000100 req/min
Team$300/mo20,000300 req/min
Company$1,000/mo100,000500 req/min

Each endpoint has a fixed posted price per successful call — most fall between 1 and 10 credits — shown on this API's page before you run it. Exceeding the rate limit returns a 429 response. Authenticate with the X-API-Key header.

Frequently asked questions
Does crt.name have an official developer API?+
crt.name does not publish a documented public REST API. The site is primarily intended for browser-based queries.
Does `search_subdomains` return subdomains that no longer resolve in DNS?+
Yes. The index records every subdomain ever observed in Certificate Transparency logs, regardless of current DNS state. A subdomain present in the subdomains array may be expired, removed, or pointing nowhere. The first_seen timestamp tells you when it entered the index, not whether it is live today.
Are wildcard certificate entries included in the subdomain list?+
Wildcard entries (e.g., *.example.com) may appear in the subdomains array when they are present in the CT log records for that apex. They are returned as-is alongside specific hostnames.
Does the API return historical WHOIS or DNS records for each subdomain?+
Not currently. The API covers subdomain names and their CT first-seen timestamps via search_subdomains, and index-level statistics via get_index_stats. There are no WHOIS, DNS resolution, or IP-address fields in the current responses. You can fork this API on Parse and revise it to add an endpoint that enriches each subdomain with DNS or WHOIS data from another source.
Can I filter `search_subdomains` results by date range or subdomain pattern?+
The endpoint returns the full subdomain list for an apex in one response; server-side filtering by date or pattern is not available. The first_seen timestamps and subdomain strings are present in the response, so client-side filtering on those fields is straightforward. You can fork this API on Parse and revise it to apply date-range or regex filtering before the response is returned.
Page content last updated . Spec covers 2 endpoints from crt.name.
Related APIs in Developer ToolsSee all →
crt.sh API
Search for SSL/TLS certificates across public transparency logs by domain, fingerprint, serial number, or public key, and retrieve detailed certificate information including issuer, validity dates, and certificate chain details. Monitor certificate issuance for domains you care about to track security changes and detect unauthorized certificates.
namecheap.com API
Search for available domain names, check their registration status, and browse TLD pricing across different extensions. Discover discounted domains on the marketplace and explore hosting bundles to find the perfect combination for your website needs.
domains.cloudflare.com API
Search for available domain names and check their pricing to find the perfect domain for your project. Discover all supported top-level domains (TLDs) available through Cloudflare Registrar to expand your domain registration options.
domains-monitor.com API
Search and monitor domain information across multiple zones, access free domain lists, and retrieve detailed zone metadata and account information. Aggregate domain data and track availability across supported TLDs.
domains.squarespace.com API
Access data from domains.squarespace.com.
instantdomainsearch.com API
Check domain name availability instantly across over 800 TLD extensions and verify whether specific domains are registered. Search and monitor domain registration status to find your perfect web address or track competitor domains in real-time.
dotdb.com API
Search domains and uncover keyword insights to research competitor strategies and domain market intelligence. Get detailed domain metadata, keyword reports, and pricing information to inform your SEO and business decisions.
SOVEREIGNCROWNHAALAAHTRUST.ORG API
Discover grant opportunities and browse registered nonprofit entities within the Sovereign Crown Haalaah Trust platform, while monitoring real-time system status. Access comprehensive information about available grants and participating organizations to support your funding research and partnership decisions.