X.509 Certificate Decoder

Decode and inspect X.509 certificates locally without uploading your certificate.

Browser onlyPEM & DERX.509

Certificate input

Paste a PEM certificate or upload a PEM, CRT, CER, or DER file.

Certificate inspection

Understand what's inside an X.509 certificate

Certificate decoding helps developers, administrators, and security engineers inspect certificate metadata, cryptographic algorithms, identities, and extensions without exposing sensitive information.

What you can inspect

View the subject, issuer, serial number, validity period, Subject Alternative Names (SAN), public key information, fingerprints, key usage, and certificate extensions.

What this tool does not do

Decoding a certificate does not verify trust, validate the certificate chain, check revocation status, or determine whether a certificate should be accepted by a browser.

Guide

About X.509 Certificate Decoder

X.509 certificates bind public keys to identities for TLS, client authentication, code signing, and other PKI systems.

This decoder turns PEM or DER certificate data into readable fields, extensions, and fingerprints.

Decoding explains certificate contents but does not establish that the certificate is trusted.

Certificate details you can inspect

The exact output depends on the certificate profile and included extensions.

  • Subject and issuer names
  • Serial number and validity
  • Public key algorithm and size
  • Subject Alternative Names
  • Key Usage and Extended Key Usage
  • Basic Constraints and fingerprints

PEM and DER formats

DER is a binary ASN.1 representation. PEM wraps DER bytes in Base64 text with BEGIN and END labels.

Decoding versus trust validation

Trust evaluation also requires issuer signature checks, chain building, hostname matching, time validation, revocation checks, and an appropriate trust store.

When to use this tool

Use it to troubleshoot TLS certificates, review requested identities, inspect CA capabilities, or compare certificate metadata before deployment.

FAQ

Frequently asked questions

Can this confirm that a certificate is trusted?

No. Trust requires validating the certificate chain and other policy checks.

What is a Subject Alternative Name?

SAN entries identify DNS names, IP addresses, email addresses, or other identities covered by the certificate.

What is Basic Constraints?

Basic Constraints indicates whether the certificate may act as a certificate authority and may include a path-length limit.

Can I inspect a self-signed certificate?

Yes. Self-signed certificates can be decoded like any other certificate.

What are certificate fingerprints?

Fingerprints are hashes of the encoded certificate used to identify and compare certificates.

Is the certificate uploaded?

Certificate parsing is intended to occur locally in your browser.

Continue exploring

Useful tools for the next step in the same workflow.