Certificate Decoder

Decode PEM or DER X.509 certificates to read expiry, SANs, issuer, fingerprints, and chain order.

Input

Related tools

What it does

Decodes X.509 certificates and shows what is actually inside them: subject and issuer distinguished names, serial number, the not before and not after dates with a plain-English expiry countdown, public key algorithm and size, signature algorithm, SHA-256 and SHA-1 fingerprints, subject alternative names, key usage and extended key usage in words rather than OIDs, basic constraints, and the subject and authority key identifiers. Paste one certificate or a whole bundle. When you paste several, it also checks whether each certificate's issuer name matches the next certificate's subject name and tells you if the chain order is right, reversed, or broken. Full detail mode adds every extension OID with its raw hex value and the complete RDN component list.

How to use it

Paste a PEM block, a whole nginx or Apache config that contains one, the output of openssl s_client, or a bare base64 DER blob. You can also drop a .crt, .cer, .pem, or .der file straight onto the input. Certificates are decoded in the order they appear, so paste your leaf first and its issuers after it if you want the chain verdict to be meaningful. Switch the detail dropdown to Full detail when you need the raw extension bytes.

Why this one

The usual certificate decoder sites make you paste a certificate into a form and press a button on someone else's server, which is a strange thing to do with a document you are trying to inspect. This one decodes in your browser, so your inputs never leave your device, and it works offline after the first load. It reads bundles, not just single certificates, and it says what key usage and extended key usage mean instead of printing bare OIDs.

FAQ
Is my certificate uploaded anywhere?
Not from this page. Decoding happens in your browser and your inputs never leave your device. There is also an optional POST endpoint for scripts, and if you choose to call that one the certificate obviously does travel to the server, so use the page when that matters.
Does it verify the chain signatures?
No. It decodes each certificate and sanity-checks the chain by name, comparing every certificate's issuer to the next certificate's subject, then reports whether the order looks correct, reversed, or broken. It never checks a signature, so a matching name is not proof of a valid chain. Use openssl verify for that.
How do I get the PEM for a website?
Run openssl s_client -showcerts -servername example.com -connect example.com:443 </dev/null and paste the whole output here. The surrounding noise is fine, every certificate block gets picked out of it.

Keyboard shortcuts: press ? anywhere on this page to see them.