Certificate & CSR Decoder
Decode PEM certificates and CSRs: subject, issuer, validity, SANs, key usage, extensions and fingerprints.
Frequently Asked Questions
What can this tool decode?
PEM blocks labelled CERTIFICATE (X.509 certificates) and CERTIFICATE REQUEST (PKCS#10 CSRs), plus binary .der and .cer files. Paste a full chain and each certificate gets its own tab.
How do I check what a CSR contains before sending it to a CA?
Paste the CSR and check the subject, the requested subject alternative names and the key type and size. A missing www hostname or a typo in the organization is much cheaper to fix now than after the certificate has been issued.
Why does my certificate need subject alternative names?
Browsers match the hostname against the SAN list and ignore the common name (CN). A TLS certificate with no SANs will not be trusted for any hostname, even if the CN is correct.
Does this verify the certificate signature or trust chain?
No. It decodes the structure only. To see the chain a live server presents and whether it is trusted, use the TLS/SSL Certificate Checker.
What is the SPKI pin?
The Base64 SHA-256 hash of the certificate's SubjectPublicKeyInfo. It identifies the public key rather than the certificate, so it stays the same when a certificate is renewed with the same key — which is why certificate pinning in mobile apps uses it.
Is it safe to paste my certificate here?
Yes. Certificates and CSRs only contain public information, and decoding happens entirely in your browser. If you paste a private key by mistake, the tool refuses to decode it and warns you.