Subdomain discovery via certificate database — finds all subdomains with issued SSL certif
Subdomain discovery via certificate database — finds all subdomains with issued SSL certificates. Discovers API endpoints, staging servers, mail servers, and forgotten infrastructure. Deduplication and wildcard handling included. Accepts USDC payments on Base and Solana
10000 (raw units)
price
1
calls / 30d
1
unique payers
2026-09-15
updated
Provider
domain.hugen.tokyo · discovered, not yet claimed by its owner
Payment (x402 accepts[])
[
{
"scheme": "exact",
"network": "eip155:8453",
"payTo": "0x29322Ea7EcB34aA6164cb2ddeB9CE650902E4f60",
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"amount": "10000",
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
"payTo": "4du4AfkjJEwch2zk3shkPJVZfyJHNDnNjEWC6AboaS5Z",
"asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
"amount": "10000",
"maxTimeoutSeconds": 300
}
]Output schema
{
"bazaar": {
"category": "domain-intelligence",
"discoverable": true,
"info": {
"input": {
"method": "GET",
"queryParams": {
"domain": "example.com"
},
"type": "http"
},
"output": {
"example": {
"subdomain_count": 3,
"subdomains": [
"www.example.com",
"mail.example.com",
"api.example.com"
]
},
"type": "json"
}
},
"schema": {
"properties": {
"input": {
"required": [
"method"
]
}
}
},
"tags": [
"whois",
"dns",
"ssl",
"domain"
]
}
}Use it
curl
curl "https://domain.hugen.tokyo/domain/subdomains" # -> 402 Payment Required, accepts[] lists how to pay # retry with a PAYMENT-SIGNATURE (or PAYMENT header) once paid
JavaScript
const res = await fetch("https://domain.hugen.tokyo/domain/subdomains");
if (res.status === 402) {
const { accepts } = await res.json();
// pay one of accepts[] via an x402 client, then retry with the payment header
}Python
import httpx
res = httpx.get("https://domain.hugen.tokyo/domain/subdomains")
if res.status_code == 402:
accepts = res.json()["accepts"]
# pay one of accepts[] via an x402 client, then retry with the payment headerMachine-readable
Everything on this page is also available as clean JSON at /resources/14478.json, and this resource appears in /discovery/resources and /discovery/search.