Paste a certificate signing request to check its domain names, organisation details and key, and confirm its signature is valid before you order a certificate.
Signature verified
SANs listed
Common mistakes flagged
Nothing uploaded
Found: CSR
#1 CSR
shop.example.com
Subject
Country: GB
State or province: England
Locality: London
Organization: Example Shop Ltd
Common name: shop.example.com
Requested names
shop.example.com
www.shop.example.com
Public key
EC 256-bit (P-256, prime256v1)
Signature
ecdsa-with-SHA256
Version
PKCS#10 v1
Extensions (1)
Subject Alternative Name
DNS: shop.example.com
DNS: www.shop.example.com
What is a CSR decoder?
A certificate signing request (CSR, PKCS#10) is what you send to a certificate authority to get an SSL certificate. It contains the domain name and organisation details you want in the certificate, your public key, and a signature made with the matching private key. A CSR decoder turns the Base64 text back into readable fields so you can catch mistakes before the CA does. This one also verifies the CSR signature, which proves it was not altered and was created with the private key you hold, and lists the requested Subject Alternative Names.
How to check a CSR
Paste the CSR, including -----BEGIN CERTIFICATE REQUEST-----, or open the .csr file.
Check the subject: Common Name, organisation, locality and two-letter country code.
Confirm every domain you need is in Requested names.
Fix anything flagged, then submit the CSR to your CA.
Do the same with OpenSSL
Prefer the command line? These OpenSSL commands do the same job on your own machine.
Signature checkVerifies the CSR’s self-signature, so you know it is intact and matches its public key.
Catches CA rejections earlyFlags lower-case or three-letter country codes, URLs or paths in the Common Name, weak keys and SHA-1.
Shows requested SANsReads the extension request so you can see every domain the certificate will cover.
Nothing is uploadedDecoding and signature checks run in your browser with the Web Crypto API. Certificates and CSRs never reach a server, which matters for internal hosts and unreleased domains.
Common uses
Before ordering. Make sure the details are right; most CAs cannot change them after issuance.
Received a CSR. Check what a colleague or hosting panel generated before buying a certificate.
Automation. Debug CSRs produced by scripts, ACME clients or Kubernetes cert-manager.
Key strength. Confirm RSA keys are at least 2048 bits or ECDSA uses P-256 or P-384.
The sample CSR requests shop.example.com and www.shop.example.com for Example Shop Ltd in London, GB, with an EC P-256 key. The signature verifies and no problems are found.
What to expect from the result
The decoder cannot tell whether you still have the matching private key, and it does not contact a CA. Challenge passwords are detected but not shown.
CSR Decoder questions
How do I decode a CSR?
Paste the CSR text, including the BEGIN and END lines, into the box or open the .csr file. The subject, requested names and key appear instantly.
What should I check in a CSR?
That the Common Name and SANs contain every domain you need, the country is a two-letter code such as US or GB, the organisation name is exact, and the key is RSA 2048-bit or larger or ECDSA P-256 or P-384.
What does “signature valid” mean?
A CSR is signed with the private key that matches its public key. A valid signature means the request was not changed after it was created.
Can I edit a CSR?
No. Changing any field breaks the signature. Generate a new CSR with the correct details instead.
Is it safe to paste my certificate here?
Yes. Certificates and CSRs contain only public information, and this tool decodes them in your browser without sending anything to a server. Never paste a private key into any website; if you do, this tool refuses to decode it.
100% private — your data never leaves your browser
No registration, no tracking of your content, no server uploads. Don't just take our word for it:
No server, no uploads
Your files and text are processed entirely on your device. Nothing is ever sent to us.
Works offline
Once loaded, this tool keeps working with your Wi-Fi turned off. Try it.
Verify it yourself
Open your browser's DevTools → Network tab. You'll see zero requests carrying your data.