thoughtasylumTOOLBOX Preview

Tools › Encoding

Certificate Decoder

Paste a PEM certificate, or a chain of them, or choose a .pem, .crt, .cer or .der file, to see its subject, issuer, validity dates (flagging expired ones), alternative names, key type and size, key usage, serial number and SHA-256 and SHA-1 fingerprints, with a check that a chain links up. Also reads certificate signing requests (CSRs) and SSH public keys.

About this tool What it's for, how to use it and an example

What it's for

Read the details of an X.509 certificate, the kind used for HTTPS websites, email signing and code signing, without using the command line.

For example, when a site shows a certificate warning or a service is about to stop working, paste its certificate to check when it expires, which names it covers and who issued it.

How to use it

Paste a PEM certificate (the text between -----BEGIN CERTIFICATE----- and -----END CERTIFICATE-----), or several for a chain, or choose a .pem, .crt, .cer or .der file. For each certificate you see the subject, issuer, validity dates (expired ones are flagged), alternative names, whether it’s a certificate authority, key type and size, the public key in PEM form, signature algorithm, serial number, and SHA-256 and SHA-1 fingerprints, each with a Copy button.

Paste a chain (the server’s certificate first, then each issuer) and the tool checks that each one is issued by the next and that its signature was made by that issuer’s key.

It also reads a certificate signing request (-----BEGIN CERTIFICATE REQUEST-----), showing the subject, the names it asks for and its public key, and an OpenSSH public key (ssh-ed25519 AAAA…), showing its type, size, comment and fingerprints as ssh-keygen -l gives them.

Example

Paste this test certificate:

-----BEGIN CERTIFICATE-----
MIIB3TCCAYSgAwIBAgIUKvEtYPv9fU3CFTILMWQcvm6BY6AwCgYIKoZIzj0EAwIw
MDEYMBYGA1UEAwwPd3d3LmV4YW1wbGUuY29tMRQwEgYDVQQKDAtFeGFtcGxlIEx0
ZDAeFw0yNjAxMDEwMDAwMDBaFw0yNzAxMDEwMDAwMDBaMDAxGDAWBgNVBAMMD3d3
dy5leGFtcGxlLmNvbTEUMBIGA1UECgwLRXhhbXBsZSBMdGQwWTATBgcqhkjOPQIB
BggqhkjOPQMBBwNCAATQ2X0o0q3T0OAuxRi0KnhbRslf5aOYCjLFV0Svo7dx87cu
iO2VYt/cBXxiqOgliwNov+Z5bpkDLMcG8BIwE18fo3wwejAdBgNVHQ4EFgQUNFbW
PSyrGPVkqxHW9VgIVsbc2J0wHwYDVR0jBBgwFoAUNFbWPSyrGPVkqxHW9VgIVsbc
2J0wDwYDVR0TAQH/BAUwAwEB/zAnBgNVHREEIDAegg93d3cuZXhhbXBsZS5jb22C
C2V4YW1wbGUuY29tMAoGCCqGSM49BAMCA0cAMEQCIHmxIrRwfZ3uHkd0wXG9LlKS
GqJfwqn/Cg7RF/ZHYy5YAiBmfWs7+hLmmoXb2Rv35Tz5jngVzfK1Z6Uq7lkXvNqR
DA==
-----END CERTIFICATE-----

It’s a self-signed certificate for www.example.com from “Example Ltd”, valid for 2026, with example.com as an alternative name and an EC P-256 key.

Good to know

Signatures are checked only between the certificates you paste together, for RSA, ECDSA and Ed25519 (not RSA-PSS), and whether a trusted authority issued the last one isn’t checked, so this tells you what a chain says and whether it hangs together, not whether to trust it. If you paste a private key by mistake, the tool warns you and doesn’t decode it.

Guide: What's inside this JWT?

Also reads a certificate signing request or an SSH public key. Signatures are checked between the certificates you paste together, but not whether a trusted authority issued the last one.

Private: this tool runs in your browser. Nothing you type, paste or choose leaves this page.

Saved you a few minutes? Say thanks with a coffee.

Something wrong with this tool, or missing from it? Report a bug or suggest a feature.

↑ ↓ move↵ openesc close