Certificate Garden

Watch the internet’s certificates arrive.

Public TLS certificates carry the names of the websites they protect. Explore a small sample of those public records as they appear in a log—one bloom or bouncing sphere at a time.

A twilight pixel-art garden with six planting beds, mossy paths, a blue forest and warm lanterns.
Enter the gardenCertificates bloom in their issuer’s patch.Enter the rainInspect certificates bouncing across an open 3D platform.

Rain requires WebGL. Both views respect pause controls; rain starts paused when reduced motion is enabled.

What you’re seeing

Certificate Transparency logs make TLS certificates publicly inspectable. These views sample up to 32 recent entries from one Google log every 15 seconds. This is a window into that log, not a count of everything issued across the internet.

A certificate can be a renewal or cover an existing website. The same certificate may appear in several logs. Select a bloom or sphere to see its domain names, issuer, validity and log timestamp.

A cyan mark means DNS resolves

The first valid exact hostname on a displayed certificate is checked for an A or AAAA address. A cyan glow shows a successful DNS result. Wildcards are skipped.

DNS resolution does not prove a website loads or is safe. Unknown or failed checks are shown separately. Certificate metadata comes from Google’s public log; Cloudflare receives the hostname queried for DNS.

Follow the records

The visualizations run in your browser. No account is needed, and the app keeps its observations only in memory. Fading, depth and movement describe the display, not certificate expiry or issuance progress.