01Run it
Straight from the command's own help.
p202 system healthp202 system health --cert-warn-days 30 --json02What you get
Captured from the real binary, run against a demo store with 30 days of traffic. Switch tabs to see the same run as JSON, the shape scripts and agents parse.
$ p202 system health api_version: v3 status: healthy timestamp: 1791540192 tls_days_left: tls_detail: the configured URL is http://, so TLS is not in use and there is no certificate to check tls_issuer: tls_not_after: tls_status: not_used
$ p202 system health --json { "data": { "api_version": "v3", "status": "healthy", "timestamp": 1791540192, "tls_days_left": null, "tls_detail": "the configured URL is http://, so TLS is not in use and there is no certificate to check", "tls_issuer": null, "tls_not_after": null, "tls_status": "not_used" } }
03Build your command
Pick values and the command line writes itself, quoted and ready to paste.
p202 system healthSet flags below; the command updates as you type.
04Flags
1 flag, plus the global flags every command takes.
| Flag | What it does |
|---|---|
| --cert-warn-daysint · default 21 | Report the certificate as expiring when it expires within this many days (0 turns the warning off) |
05How it works
Calls the unauthenticated system/health endpoint and, for an https base URL, checks the TLS certificate of its host first: a verified handshake on its own connection, with no HTTP request, so an expired certificate is reported as one instead of as a network error from the API call.
tls_status: ok, expiring (expires within --cert-warn-days), expired, hostname_mismatch, unknown_authority, invalid, unreachable; not_used for an http:// URL. tls_not_after, tls_days_left and tls_issuer describe the certificate the server sent (null when none arrived); tls_detail says why.
Like p202 rotator check, it exits 5 (partial_failure) when tls_status is
anything but ok or not_used, with the health object still printed on stdout.
When only the API call fails, it exits as that error does (3 network, 4 server).
06For agents
Running this from an agent
- Read the same facts as JSON:
p202 commands system health --json. - With
AI_AGENT,CLAUDECODEor another agent variable set, output is compact JSON and errors arrive on stderr as a JSON envelope with ahint. - Exit codes: 0 ok, 1 bad input, 2 auth, 3 network, 4 server error, 5 partial failure.
{
"path": "p202 system health",
"use": "health",
"short": "Check system health and the TLS certificate (no auth required)",
"long": "Calls the unauthenticated system/health endpoint and, for an https base URL,\nchecks the TLS certificate of its host first: a verified handshake on its own\nconnection, with no HTTP request, so an expired certificate is reported as\none instead of as a network error from the API call.\n\ntls_status: ok, expiring (expires within --cert-warn-days), expired,\nhostname_mismatch, unknown_authority, invalid, unreachable; not_used for an\nhttp:// URL. tls_not_after, tls_days_left and tls_issuer describe the\ncertificate the server sent (null when none arrived); tls_detail says why.\n\nLike `p202 rotator check`, it exits 5 (partial_failure) when tls_status is\nanything but ok or not_used, with the health object still printed on stdout.\nWhen only the API call fails, it exits as that error does (3 network, 4 server).",
"runnable": true,
"example": "p202 system health\n p202 system health --cert-warn-days 30 --json",
"flags": [
{
"name": "cert-warn-days",
"type": "int",
"default": "21",
"usage": "Report the certificate as expiring when it expires within this many days (0 turns the warning off)",
"required": false
}
]
}