Certificate Decoder - Read an X.509 SSL/TLS Certificate or CSR Online

AdSense Placeholder
Slot: header_tool

Certificate Decoder

Paste a PEM certificate or CSR and see everything inside it

AdSense Placeholder
Slot: tool_mid_article

Everything in the Certificate

Subject, issuer, validity dates, serial number, signature algorithm, public key, alternative names, key usages and more, laid out clearly.

Chains and CSRs

Paste a whole chain and each certificate is decoded, with a check that each one names the next as its issuer. CSRs are decoded too.

Fingerprints

SHA-1 and SHA-256 fingerprints, calculated from the certificate itself, in the colon-separated form browsers show.

Full Privacy

Decoding happens in your browser. The certificate is never uploaded. (Certificates are public, but CSRs and your drafts may not be.)

Reading a Certificate

An X.509 certificate binds a public key to an identity. The subject says who it is for and the issuer says which certificate authority vouched for it. For a website, the names that matter are the subject alternative names: a browser accepts the certificate only if the site's hostname matches one of them. The validity dates say when it can be used, and the key usage and extended key usage say what for, such as serverAuth for HTTPS servers.

This tool shows what the certificate says; it does not check that it can be trusted. It does not verify signatures, look up revocation, or build a trust path to a root store, so a decoded certificate can still be forged, revoked or untrusted. To check a live site, use the SSL Certificate Checker. Private keys must never be pasted anywhere, and this tool ignores them.

Key Takeaways

  • Formats: PEM certificates and CSRs, plus bare base64 or hex DER, one or many at once.
  • Checked against OpenSSL: Results were verified against Python's cryptography library and Node's X509 parser on many certificates.
  • Related tools: See also the SSL Certificate Checker and the JWT Decoder.
AdSense Placeholder
Slot: footer_leaderboard