crt APIcrt.name ↗
Query the crt.name passive subdomain index via API. Get every subdomain for an apex domain with first-seen timestamps, plus live index statistics.
What is the crt API?
The crt.name API provides 2 endpoints that expose the crt.name passive subdomain index, built from the Certificate Transparency firehose. The search_subdomains endpoint returns every known subdomain for a given apex domain in a single call, each record carrying a first-seen ISO-8601 UTC timestamp. The get_index_stats endpoint returns the current total size of the index and a live snapshot of the most recently indexed names.
curl -X GET 'https://api.parse.bot/scraper/a1d5e246-bfcd-44fd-9a3b-bc93659fc2b6/search_subdomains?apex=namecheap.com' \ -H 'X-API-Key: $PARSE_API_KEY'
Typed, relational, agent-ready
A generated client with real types, enums, and the links between objects — the structure a flat JSON response can't carry. Autocompletes in your editor and reads cleanly to coding agents.
- Fully typed · autocompletes
- Objects link to objects
- Typed errors & pagination
Typed Python client. Set up the SDK in your uv project, then pull this API’s typed client:
uv add parse-sdk uv run parse init uv run parse add --marketplace crt-name-api
uv run parse add --marketplace pulls a pinned snapshot of this canonical API — it won’t change underneath you. To customize it, subscribe and swap to your own copy.
"""Walkthrough: crt.name subdomain index — bounded, re-runnable."""
from parse_apis.crt_name_api import CrtName, InputFormatInvalid
client = CrtName()
# Check overall index size and the latest names from the CT firehose.
stats = client.index_stats.get()
print(f"Total indexed: {stats.total_indexed}")
for entry in stats.recent[:3]:
print(f" {entry.subdomain} (apex {entry.apex}, first seen {entry.first_seen})")
# Search all subdomains for an apex domain; limit= caps total items yielded.
try:
first_sub = client.subdomains.search(apex="namecheap.com", limit=1).first()
except InputFormatInvalid:
print("Invalid apex format")
first_sub = None
if first_sub is not None:
print(f"{first_sub.subdomain} — first seen {first_sub.first_seen}")
# Iterate a bounded slice of subdomains for another apex.
for sub in client.subdomains.search(apex="cloudflare.com", limit=5):
print(sub.subdomain, sub.first_seen)
print("exercised: index_stats.get / subdomains.search")
Returns every subdomain the index holds for one apex (registrable, eTLD+1) domain, each with the timestamp it was first seen in Certificate Transparency or other sources. One round trip, no pagination: the whole list comes back in a single call (hundreds of rows for a large apex). first_seen is null for names whose first sighting was not recorded. An apex that is not a registrable domain (for example a hostname with a subdomain prefix) is rejected as stale_input; an apex the index has never seen returns an empty subdomains list with count 0. The site allows roughly 100 requests per day from one network address.
| Param | Type | Description |
|---|---|---|
| apexrequired | string | Registrable apex domain (eTLD+1) such as example.com; must not include a subdomain prefix. |
{
"type": "object",
"fields": {
"apex": "the normalized (lower-cased) apex that was queried",
"count": "integer number of subdomain records returned",
"subdomains": "array of {subdomain, first_seen}; first_seen is an ISO-8601 UTC timestamp or null when unknown"
},
"sample": {
"data": {
"apex": "namecheap.com",
"count": 391,
"subdomains": [
{
"subdomain": "namecheap.com",
"first_seen": "2008-05-09T07:30:28Z"
},
{
"subdomain": "20cl-mirror.namecheap.com",
"first_seen": null
}
]
},
"status": "success"
}
}About the crt API
Subdomain Enumeration
The search_subdomains endpoint accepts a single required parameter, apex, which must be a registrable eTLD+1 domain such as example.com — no subdomain prefix. The response includes the normalized apex, an integer count of records, and a subdomains array. Each element in that array contains a subdomain string and a first_seen timestamp (ISO-8601 UTC, or null when the source had no date). For large apexes this array can reach hundreds of entries. The entire dataset comes back in one call with no pagination.
Index Statistics
The get_index_stats endpoint takes no parameters. It returns total_indexed, an integer representing how many distinct apex domains and subdomains the index currently holds, and recent, an array of the newest indexed names. Each entry in recent includes apex, subdomain, and first_seen. Because this list reflects the live Certificate Transparency firehose, its contents change between calls and serve as a real-time window into newly issued certificates.
Data Scope and Freshness
The index is populated from Certificate Transparency logs, which means a subdomain appears here when a TLS certificate referencing it is issued or renewed. Subdomains that have never had a certificate issued against them will not appear in results. The first_seen field reflects when the name was first observed in the index, not necessarily the current DNS state of that subdomain.
The crt API is a managed, monitored endpoint for crt.name — not a raw scraper you maintain. Every endpoint is automatically health-checked on a schedule, and when crt.name changes and a check fails, the API is automatically queued for repair and re-verified. It is built to keep working as the site underneath it changes.
This isn't an official crt.name API — it's an independent, maintained REST wrapper over public data. Where the source has no official API (or only a limited one), Parse gives you a stable contract over a source that never promised one, and keeps it current. Need a new endpoint or field? You can revise it yourself in plain English and the agent rebuilds it against the live site in minutes — contributing the change back to the shared API is free.
Will this API break when the source site changes?+
Is this an official API from the source site?+
Can I fix or extend this API myself if I need a new endpoint or field?+
What happens if I call an endpoint that has an issue?+
- Enumerate all known subdomains of a target apex during an attack-surface audit using
search_subdomains - Track newly registered or certificated subdomains by polling
get_index_statsfor entries in therecentarray - Feed the
subdomainslist into a port scanner or DNS resolver to identify live hosts - Compare the subdomain count returned by
countacross time to detect infrastructure expansion - Bootstrap threat-intelligence pipelines with subdomain-to-first-seen mappings for age analysis
- Identify shadow IT or forgotten subdomains by diffing
search_subdomainsresults against known internal inventory
| Tier | Price | Credits/month | Rate limit |
|---|---|---|---|
| Free | $0/mo | 200 | 5 req/min |
| Hobby | $30/mo | 1,000 | 20 req/min |
| Developer | $100/mo | 5,000 | 100 req/min |
| Team | $300/mo | 20,000 | 300 req/min |
| Company | $1,000/mo | 100,000 | 500 req/min |
Each endpoint has a fixed posted price per successful call — most fall between 1 and 10 credits — shown on this API's page before you run it. Exceeding the rate limit returns a 429 response. Authenticate with the X-API-Key header.
Does crt.name have an official developer API?+
Does `search_subdomains` return subdomains that no longer resolve in DNS?+
subdomains array may be expired, removed, or pointing nowhere. The first_seen timestamp tells you when it entered the index, not whether it is live today.Are wildcard certificate entries included in the subdomain list?+
*.example.com) may appear in the subdomains array when they are present in the CT log records for that apex. They are returned as-is alongside specific hostnames.Does the API return historical WHOIS or DNS records for each subdomain?+
search_subdomains, and index-level statistics via get_index_stats. There are no WHOIS, DNS resolution, or IP-address fields in the current responses. You can fork this API on Parse and revise it to add an endpoint that enriches each subdomain with DNS or WHOIS data from another source.Can I filter `search_subdomains` results by date range or subdomain pattern?+
first_seen timestamps and subdomain strings are present in the response, so client-side filtering on those fields is straightforward. You can fork this API on Parse and revise it to apply date-range or regex filtering before the response is returned.