Related tools
- Self-Signed Certificate GeneratorGenerate a self-signed X.509 certificate and private key for local development, in your browser.
- OAuth Scope DecoderTurn an OAuth scope list into plain English access and an honest risk read.
- JWT Vulnerability CheckDecode a JWT and test it for alg=none and weak HMAC signing secrets, entirely in your browser.
- Passkey TesterRegister and authenticate passkeys, then decode the attestation object, flags, and public key.
- Hash & ChecksumHash text or files with MD5, SHA-1, SHA-256, SHA-384, and SHA-512 at once, and verify the result against a known hash.
- HMAC GeneratorCompute and verify HMAC digests for a message and a secret key, in your browser.
What it does
Decodes X.509 certificates and shows what is actually inside them: subject and issuer distinguished names, serial number, the not before and not after dates with a plain-English expiry countdown, public key algorithm and size, signature algorithm, SHA-256 and SHA-1 fingerprints, subject alternative names, key usage and extended key usage in words rather than OIDs, basic constraints, and the subject and authority key identifiers. Paste one certificate or a whole bundle. When you paste several, it also checks whether each certificate's issuer name matches the next certificate's subject name and tells you if the chain order is right, reversed, or broken. Full detail mode adds every extension OID with its raw hex value and the complete RDN component list.
How to use it
Paste a PEM block, a whole nginx or Apache config that contains one, the output of openssl s_client, or a bare base64 DER blob. You can also drop a .crt, .cer, .pem, or .der file straight onto the input. Certificates are decoded in the order they appear, so paste your leaf first and its issuers after it if you want the chain verdict to be meaningful. Switch the detail dropdown to Full detail when you need the raw extension bytes.
Why this one
The usual certificate decoder sites make you paste a certificate into a form and press a button on someone else's server, which is a strange thing to do with a document you are trying to inspect. This one decodes in your browser, so your inputs never leave your device, and it works offline after the first load. It reads bundles, not just single certificates, and it says what key usage and extended key usage mean instead of printing bare OIDs.
FAQ
- Is my certificate uploaded anywhere?
- Not from this page. Decoding happens in your browser and your inputs never leave your device. There is also an optional POST endpoint for scripts, and if you choose to call that one the certificate obviously does travel to the server, so use the page when that matters.
- Does it verify the chain signatures?
- No. It decodes each certificate and sanity-checks the chain by name, comparing every certificate's issuer to the next certificate's subject, then reports whether the order looks correct, reversed, or broken. It never checks a signature, so a matching name is not proof of a valid chain. Use openssl verify for that.
- How do I get the PEM for a website?
- Run openssl s_client -showcerts -servername example.com -connect example.com:443 </dev/null and paste the whole output here. The surrounding noise is fine, every certificate block gets picked out of it.
Keyboard shortcuts: press ? anywhere on this page to see them.