Certificate Guide

How to Decode an X.509 Certificate Online

X.509 certificates contain information about a website, organization, public key, certificate authority, validity period, and supported identities. Decoding a certificate makes those details readable without manually working through ASN.1 or OpenSSL output.

What is an X.509 certificate?

X.509 is the standard format used for digital certificates in TLS, HTTPS, PKI, code signing, client authentication, email security, and many other cryptographic systems.

A certificate binds a public key to an identity. That identity may be a domain name, organization, person, device, or service. The certificate is normally signed by a Certificate Authority so other systems can verify that the certificate is trusted.

How to decode an X.509 certificate

The easiest method is to paste the PEM-encoded certificate into a certificate decoder.

  1. 1. Copy your certificate, including the BEGIN CERTIFICATE and END CERTIFICATE lines.
  2. 2. Open the Certificate Decoder.
  3. 3. Paste the certificate into the input field.
  4. 4. Decode the certificate and review its identity, validity, public key, fingerprints, and extensions.

What does a PEM certificate look like?

A PEM-encoded X.509 certificate normally looks like this:

-----BEGIN CERTIFICATE-----
MIID...
...certificate data...
-----END CERTIFICATE-----

The Base64 text represents the DER-encoded certificate. A decoder converts that binary certificate structure into readable fields.

Important certificate fields to inspect

Subject

The subject identifies the entity the certificate was issued to. Older certificates may place the primary hostname in the Common Name field.

Issuer

The issuer identifies the Certificate Authority or intermediate CA that signed the certificate.

Subject Alternative Names

Subject Alternative Name, or SAN, lists the DNS names or other identities covered by the certificate. Modern TLS clients primarily use SAN entries when validating hostnames.

Validity period

The Not Before and Not After values indicate when the certificate becomes valid and when it expires.

Public key

The certificate contains the subject's public key, including the key algorithm and related parameters.

Fingerprints

Certificate fingerprints such as SHA-256 provide a compact identifier that can be used to compare certificates.

Signature algorithm

The signature algorithm tells you how the issuer signed the certificate.

Certificate decoding vs. checking a live SSL/TLS server

Decoding a certificate and testing a live TLS server solve different problems.

Certificate Decoder

Use it when you already have a certificate and want to inspect its contents.

SSL/TLS Checker

Use it when you want to connect to a live hostname and inspect the deployed certificate and TLS configuration.

To inspect a live server, use the SSL/TLS Checker.

Certificate vs. CSR

A Certificate Signing Request is not the same as a certificate. A CSR contains identity information and a public key that are submitted to a Certificate Authority when requesting a new certificate.

If your data starts with -----BEGIN CERTIFICATE REQUEST-----, use the CSR Decoder instead.

What is a certificate chain?

TLS certificates normally participate in a chain of trust. A typical chain contains:

  • the leaf or server certificate
  • one or more intermediate CA certificates
  • a trusted root CA certificate

Use the Certificate Chain Builder when you need to understand how multiple certificates relate to one another.

Can you decode a certificate with OpenSSL?

Yes. If OpenSSL is installed, a PEM certificate can be inspected from the command line with:

openssl x509 -in certificate.pem -text -noout

A browser-based decoder is convenient when you want structured certificate information without installing or remembering command-line options.

Is it safe to paste a certificate into an online decoder?

Public certificates are designed to be distributed and normally do not contain private key material. However, you should always verify what type of data you are working with before submitting it anywhere.

Never paste a private key into a certificate decoder.

Private keys commonly begin with text such as BEGIN PRIVATE KEY, BEGIN RSA PRIVATE KEY, or BEGIN EC PRIVATE KEY.

Related certificate tools

Decode an X.509 certificate now

Paste a PEM certificate into Security Toolbox to inspect its identity, issuer, validity, extensions, algorithms, public key, and fingerprints.

Open Certificate Decoder