CSR Decoder
Inspect PKCS#10 certificate signing requests, review requested identities, extensions, public keys, and signatures without uploading your CSR.
CSR input
Paste a PEM request or upload a PEM, CSR, REQ, or DER file.
Certificate enrollment
Review a certificate signing request before submitting it
A Certificate Signing Request (CSR) contains the public key and identity information that will be included in an issued certificate. Reviewing the CSR helps detect configuration mistakes before requesting a certificate.
What this tool shows
Inspect the subject, Subject Alternative Names (SAN), public key algorithm, key size, requested extensions, signature algorithm, fingerprints, and other PKCS#10 request attributes.
Privacy
CSR parsing is performed entirely in your browser. Certificate signing requests are not uploaded or stored. Never paste or upload a private key into this tool.
Guide
About CSR Decoder and PKCS#10 Analyzer
A Certificate Signing Request contains a public key, requested identity information, and a signature created by the corresponding private key.
This decoder makes PKCS#10 request fields readable and helps detect configuration problems before a CSR is submitted to a CA.
CSRs are generally public enrollment data, but they can still reveal internal hostnames and organizational details.
What this CSR decoder shows
Inspect the request structure and requested certificate identities.
- Subject distinguished name
- Subject Alternative Names
- Public key algorithm and size
- Signature algorithm
- Requested extensions
- Request fingerprints
CSR signature meaning
The CSR signature proves possession of the private key corresponding to the included public key, assuming verification succeeds.
Review before issuance
Check names, key strength, algorithms, and requested extensions before sending the CSR to a certificate authority.
Private-key warning
A CSR does not contain the private key. Never paste a private key into a CSR decoder.
FAQ
Frequently asked questions
What is a CSR?
A CSR is a signed PKCS#10 request containing a public key and requested certificate identity information.
Does a CSR contain the private key?
No. The private key remains with the requester.
Can I see SAN entries in a CSR?
Yes, when they are included in the requested extensions.
What does CSR signature verification prove?
It shows that the request was signed by the private key corresponding to the included public key.
Can a CA ignore CSR fields?
Yes. A CA can apply policy and issue a certificate with different or restricted values.
Is the CSR uploaded?
Decoding is intended to occur locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
CSR Generator
Generate RSA or EC PKCS#10 certificate signing requests and private keys locally.
PKI & Certificates
X.509 Certificate Decoder
Decode certificate identity, validity, algorithms, key details, and fingerprints locally.
PKI & Certificates
Certificate Generator
Generate self-signed Root CA, TLS server, and TLS client certificates with RSA or EC keys.
PKI & Certificates
Public & Private Key Analyzer
Identify PEM and OpenSSH key algorithms, formats, sizes, curves, and fingerprints locally.
PKI & Certificates
Certificate & Private Key Match Checker
Verify whether an X.509 certificate and RSA private key contain the same public key.
PKI & Certificates
PEM / DER Converter
Convert certificates, CSRs, public keys, and private keys between PEM, DER, and Base64.
PKI & Certificates