Encode & identify / Certificates

Certificate Decoder: Read X.509 PEM Certificates Online

Paste a PEM certificate, or a whole chain, and read it: subject and issuer, validity dates and days left, subject alternative names, public key type and size, signature algorithm, serial number, CA flag, key usage and extended key usage, key identifiers, OCSP, CA issuer and CRL links, and SHA-256 and SHA-1 fingerprints.

Certificate Decoder: Read X.509 PEM Certificates Online: The certificate's DER structure is read field by field in your browser, the same fields openssl x509 -text shows: names, dates converted to UTC, RSA key size or elliptic curve, the extensions that say what the certificate may be used for, and fingerprints hashed from the exact bytes. Expired certificates, and those expiring within 30 days, are flagged. Runs 100% locally in your browser with zero server file uploads.

Runs
In your browser
Cost
Free · no sign-up
Availability
Ready to use
Certificate decoderLocal processing

Runs entirely in your browser

The certificate is decoded in your browser from its DER structure; it is not uploaded, and the signature and chain are not checked against any trust store. To test a live website's certificate and chain, use the SSL checker. Certificates are public; never paste a private key.

Fingerprints

A fingerprint is a hash of the whole certificate, handy for pinning or for comparing two copies; SHA-256 is the one to use.

Live sites

To fetch and check the certificate a website serves, use the SSL checker.

How to use it

  1. Paste the certificate text, from -----BEGIN CERTIFICATE----- to -----END CERTIFICATE-----.
  2. Read the decoded fields for each certificate in the chain.
  3. Check the dates, names, and fingerprints.

Privacy & limitations

The certificate is decoded in your browser and never uploaded.

Related tools

Frequently asked questions

Does this check that the certificate is trusted?

No: it reads the certificate but does not verify signatures or chains; to test a live site, use the SSL checker.

Can I paste a private key?

Never paste private keys anywhere online; this tool only needs the public certificate.

Why does my certificate show several names?

Modern certificates list every host name they cover in the subject alternative names; browsers ignore the common name.

Free tool · runs in your browser · no account required