Certificate Transparency Inspector

Inspect an X.509 certificate and decode its embedded Signed Certificate Timestamps without contacting any Certificate Transparency log.

Browser onlyX.509 SCTsNo CT lookup

Certificate input

Paste a certificate or upload a PEM, CRT, or CER file. Only the first certificate is inspected.

Certificate Transparency

Inspect embedded Signed Certificate Timestamps

Signed Certificate Timestamps provide evidence that a certificate was submitted to one or more Certificate Transparency logs.

What this tool extracts

The inspector decodes embedded SCT entries and displays details such as the log identifier, timestamp, version, hash algorithm, signature algorithm, and signature bytes when available.

What this tool does not verify

It does not contact Certificate Transparency logs, confirm that an SCT is accepted by a browser, or independently verify the log signature against a current CT log key list.

Guide

About Certificate Transparency Inspector

Certificate Transparency logs provide public, append-only records of publicly trusted certificate issuance.

Certificates can carry Signed Certificate Timestamps proving that a log accepted a certificate or precertificate submission.

This inspector decodes embedded SCT data without performing network lookups.

What SCT data includes

Embedded entries can contain a CT log identifier, timestamp, version, extensions, and signature metadata.

Why Certificate Transparency matters

CT helps domain owners and ecosystem monitors detect unexpected or misissued certificates.

Decoding versus verification

Decoding an SCT does not verify its signature against a current CT log key list or prove browser acceptance.

Offline inspection

The tool analyzes certificate data locally and does not query CT logs or monitoring services.

FAQ

Frequently asked questions

What is a Signed Certificate Timestamp?

An SCT is a signed promise from a CT log that a certificate submission will be incorporated into the log.

Does every certificate contain embedded SCTs?

No. SCTs can also be delivered through TLS extensions or OCSP stapling.

Does this verify the SCT signature?

It decodes the SCT; verification may require a trusted, current CT log key list.

Can CT prove a certificate is trusted?

No. CT logging is separate from certificate-chain trust validation.

Why are multiple SCTs present?

Browser policy may require evidence from multiple independent logs.

Does this contact CT logs?

No. Inspection is local.

Continue exploring

Useful tools for the next step in the same workflow.