SSL & Security
SSL Certificate Decoder
Decode a Certificate
Tool features
4 checks
Certificate Parsing
Parse and decode X.509 certificates in PEM format
Public Key Info
Extract public key details including algorithm and key size
Detailed Analysis
View subject, issuer, validity, extensions, and more
Chain Support
Decode certificate chains with multiple certificates
What is certificate decoding & how it works
An X.509 certificate binds a public key to an identity (a domain, organisation or person) and is signed by a certificate authority. In PEM form it is just Base64 between -----BEGIN CERTIFICATE----- markers, so you cannot read the details without decoding it.
Decoding unpacks the ASN.1 structure into readable fields: who it was issued to and by, the validity window, the Subject Alternative Names it covers, the key type and size, and extensions such as key usage. That is how you confirm a certificate is the one you expect before installing it or debugging a trust error.
Subject / Issuer
Who the certificate identifies, and the CA that signed it.
SAN
Subject Alternative Names: every hostname the certificate is valid for.
Validity
The notBefore / notAfter window outside which clients reject the certificate.
How to use this tool
1
Paste the certificate
Paste one or more PEM certificates, including the
BEGIN/END CERTIFICATE lines, or upload the file.2
Decode
Run the decoder to parse every certificate in the input.
3
Check the key fields
Review subject, issuer, SANs, validity dates, key algorithm and size, and extensions.
4
Confirm before deploying
Make sure the hostnames, expiry and issuer are what you ordered before installing the certificate.
Related tools
4 tools
SSL Checker
Comprehensive SSL certificate analysis including validity, expiration, chain verification, TLS versions, and security assessment
Certificate CSR Matcher
Verify if SSL certificate matches its Certificate Signing Request (CSR)
Certificate Key Matcher
Verify if SSL certificate matches its private key to ensure proper key pair configuration
CSR Decoder
Decode Certificate Signing Request (CSR) files and view all details including subject, key type, and extensions
Frequently asked questions
5 Q&A
Yes. Paste the leaf and intermediates together and each certificate is decoded separately, so you can check the issuer of one against the subject of the next.
Yes. A certificate is public: servers send it to every visitor. Never paste the private key, which is a different block starting with
BEGIN PRIVATE KEY.Run
openssl x509 -in cert.pem -noout -text. For a DER file add -inform der.Browsers ignore the Common Name and only match hostnames against the Subject Alternative Name list. Check that the exact hostname (or a matching wildcard) is in the SANs.