X.509 Certificate Decoder
Decode and inspect X.509 certificates locally without uploading your certificate.
Certificate input
Paste a PEM certificate or upload a PEM, CRT, CER, or DER file.
Certificate inspection
Understand what's inside an X.509 certificate
Certificate decoding helps developers, administrators, and security engineers inspect certificate metadata, cryptographic algorithms, identities, and extensions without exposing sensitive information.
What you can inspect
View the subject, issuer, serial number, validity period, Subject Alternative Names (SAN), public key information, fingerprints, key usage, and certificate extensions.
What this tool does not do
Decoding a certificate does not verify trust, validate the certificate chain, check revocation status, or determine whether a certificate should be accepted by a browser.
Guide
About X.509 Certificate Decoder
X.509 certificates bind public keys to identities for TLS, client authentication, code signing, and other PKI systems.
This decoder turns PEM or DER certificate data into readable fields, extensions, and fingerprints.
Decoding explains certificate contents but does not establish that the certificate is trusted.
Certificate details you can inspect
The exact output depends on the certificate profile and included extensions.
- Subject and issuer names
- Serial number and validity
- Public key algorithm and size
- Subject Alternative Names
- Key Usage and Extended Key Usage
- Basic Constraints and fingerprints
PEM and DER formats
DER is a binary ASN.1 representation. PEM wraps DER bytes in Base64 text with BEGIN and END labels.
Decoding versus trust validation
Trust evaluation also requires issuer signature checks, chain building, hostname matching, time validation, revocation checks, and an appropriate trust store.
When to use this tool
Use it to troubleshoot TLS certificates, review requested identities, inspect CA capabilities, or compare certificate metadata before deployment.
FAQ
Frequently asked questions
Can this confirm that a certificate is trusted?
No. Trust requires validating the certificate chain and other policy checks.
What is a Subject Alternative Name?
SAN entries identify DNS names, IP addresses, email addresses, or other identities covered by the certificate.
What is Basic Constraints?
Basic Constraints indicates whether the certificate may act as a certificate authority and may include a path-length limit.
Can I inspect a self-signed certificate?
Yes. Self-signed certificates can be decoded like any other certificate.
What are certificate fingerprints?
Fingerprints are hashes of the encoded certificate used to identify and compare certificates.
Is the certificate uploaded?
Certificate parsing is intended to occur locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
Certificate Lint
Check X.509 certificates for common RFC 5280, CA/B Forum, and security best-practice issues.
PKI & Certificates
Certificate Chain Builder
Order X.509 certificates and generate fullchain.pem and chain.pem locally.
PKI & Certificates
Certificate & Private Key Match Checker
Verify whether an X.509 certificate and RSA private key contain the same public key.
PKI & Certificates
OCSP Checker
Inspect certificate OCSP responder metadata and revocation-check readiness.
PKI & Certificates
CSR Decoder
Decode PKCS#10 certificate signing requests and review requested identities, keys, and extensions.
PKI & Certificates
Public & Private Key Analyzer
Identify PEM and OpenSSH key algorithms, formats, sizes, curves, and fingerprints locally.
PKI & Certificates