Developer / Certificates
CSR Decoder
Decode a PEM certificate signing request: subject, alternative names, public key, signature algorithm and extensions, with a local signature check.
CSR Decoder: Reads a PKCS#10 request and shows its subject fields, subject alternative names, RSA or EC public key size, signature algorithm and requested extensions. It checks supported RSA and ECDSA signatures against the embedded public key. Runs 100% locally in your browser with zero server file uploads.
- Category
- Developer tools
- Runs
- In your browser
- Cost
- Free · no sign-up
- Availability
- Ready to use
Runs entirely in your browser
Certificate requests
PKCS#10 defines the signed request containing your subject, public key and requested extensions. RFC 2986 (https://www.rfc-editor.org/rfc/rfc2986) describes its structure.
PEM and certificate structures
RFC 7468 (https://www.rfc-editor.org/rfc/rfc7468) defines textual PEM labels. RFC 5280 (https://www.rfc-editor.org/rfc/rfc5280) describes certificate subjects and alternative names. These formats carry data; they do not establish trust by themselves.
How to use it
- Paste one PEM certificate signing request.
- Choose Decode and verify.
- Review the subject, requested extensions and signature result.
Privacy & limitations
Everything runs in your browser. Your images, keys and pasted data are not uploaded or saved by this tool.
Related tools
Frequently asked questions
What does a valid signature mean?
It shows the request was signed with the corresponding private key and its signed contents have not changed. It does not establish identity, certificate authority approval or trust.
Which signatures can be checked?
RSA PKCS#1 signatures with SHA-1, SHA-256, SHA-384 or SHA-512 and ECDSA with SHA-256, SHA-384 or SHA-512 are supported. An unsupported signature, including RSA-PSS, is shown as unchecked.
Is a CSR a private key?
No. It contains a public key and requested certificate details. Its subject data can still be sensitive, so this decoder keeps it in your browser.
Free tool · runs in your browser · no account required