A clear view of gateway certificates. Spot renewal risks before they become downtime.
Loading certificate observations…
Gateway domains, advertised ports and network status come from the public ar.io gateway registry via the ar.io SDK. No private keys are used.
The scanner makes a TLS connection to the registered HTTPS endpoint with the correct server name. It reads the certificate that endpoint actually serves and checks its dates, hostname and trust validation. Invalid certificates can be inspected, but are never marked as trusted.
DNS answers must be public. Connections are pinned to a validated address, with up to three attempts. The result describes the first reachable endpoint from one scanner, not every CDN edge or IP. Gateway subdomains, revocation status, domain-registration expiry and private origin certificates are not checked.
Normal checks run every six hours. Certificates with 14 days or less remaining, expired certificates and connection or validation errors are checked hourly. Leaving gateways are checked daily. The registry refreshes every six hours. The page refreshes saved results every minute; it cannot trigger scans or renew certificates.
Results older than 12 hours for active gateways, or 30 hours for leaving gateways, are marked stale. An unreachable host is not labelled expired. Previous certificates, when available, are clearly labelled as historical.
Green means a trusted, hostname-matching certificate with more than 14 days remaining. Amber means 14 days or less; red means expired or a validation problem. A valid certificate alone does not prove gateway uptime, observer success or preservation of a reward streak.
Independent community project. Not an official ar.io service. No wallet, login, notifications, analytics or tracking cookies.