Certificate Decoder
Paste a certificate (or a whole chain) or a certificate signing request to read everything inside it. Decoding happens locally in your browser.
Runs in your browser — nothing is uploadedHow to use Certificate Decoder
- Paste one or more PEM blocks starting with -----BEGIN CERTIFICATE----- or -----BEGIN CERTIFICATE REQUEST-----.
- Read the subject, SANs, validity dates, key details and extensions.
- Copy the SHA-256 fingerprint to compare certificates.
Questions
Do I need to paste my private key?
No — never. Certificates and CSRs are public information; the matching private key must stay on your server. The tool refuses private keys if you paste one by mistake.
Does it check whether the certificate is trusted?
It decodes the contents and shows validity dates, but it does not verify signatures or the trust chain. To test a live website’s certificate and chain, use the SSL Checker.
What is a SAN?
Subject Alternative Names list every hostname (and sometimes IP address) the certificate is valid for. Browsers ignore the Common Name and only check SANs.