Digital ToolPad.

Runs 100% in your browser

Your data never leaves your device. zero uploads.

CSR Decoder

Paste a certificate signing request to check its domain names, organisation details and key, and confirm its signature is valid before you order a certificate.

  • Signature verified
  • SANs listed
  • Common mistakes flagged
  • Nothing uploaded
Found: CSR

#1 CSR

shop.example.com

Subject
  • Country: GB
  • State or province: England
  • Locality: London
  • Organization: Example Shop Ltd
  • Common name: shop.example.com
Requested names
  • shop.example.com
  • www.shop.example.com
Public key
EC 256-bit (P-256, prime256v1)
Signature
ecdsa-with-SHA256
Version
PKCS#10 v1

Extensions (1)

Subject Alternative Name
DNS: shop.example.com DNS: www.shop.example.com

What is a CSR decoder?

A certificate signing request (CSR, PKCS#10) is what you send to a certificate authority to get an SSL certificate. It contains the domain name and organisation details you want in the certificate, your public key, and a signature made with the matching private key. A CSR decoder turns the Base64 text back into readable fields so you can catch mistakes before the CA does. This one also verifies the CSR signature, which proves it was not altered and was created with the private key you hold, and lists the requested Subject Alternative Names.

How to check a CSR

  1. Paste the CSR, including -----BEGIN CERTIFICATE REQUEST-----, or open the .csr file.
  2. Check the subject: Common Name, organisation, locality and two-letter country code.
  3. Confirm every domain you need is in Requested names.
  4. Fix anything flagged, then submit the CSR to your CA.

Do the same with OpenSSL

Prefer the command line? These OpenSSL commands do the same job on your own machine.

Show a CSR as text and verify it
openssl req -in request.csr -noout -text -verify
Create a CSR with SANs (EC P-256)
openssl req -new -newkey ec -pkeyopt ec_paramgen_curve:P-256 -nodes -keyout site.key -subj "/CN=example.com" -addext "subjectAltName=DNS:example.com,DNS:www.example.com" -out site.csr
Check that a CSR matches a private key
openssl req -in site.csr -noout -pubkey | openssl sha256 && openssl pkey -in site.key -pubout | openssl sha256

Why use this CSR decoder

  • Signature checkVerifies the CSR’s self-signature, so you know it is intact and matches its public key.
  • Catches CA rejections earlyFlags lower-case or three-letter country codes, URLs or paths in the Common Name, weak keys and SHA-1.
  • Shows requested SANsReads the extension request so you can see every domain the certificate will cover.
  • Nothing is uploadedDecoding and signature checks run in your browser with the Web Crypto API. Certificates and CSRs never reach a server, which matters for internal hosts and unreleased domains.

Common uses

  • Before ordering. Make sure the details are right; most CAs cannot change them after issuance.
  • Received a CSR. Check what a colleague or hosting panel generated before buying a certificate.
  • Automation. Debug CSRs produced by scripts, ACME clients or Kubernetes cert-manager.
  • Key strength. Confirm RSA keys are at least 2048 bits or ECDSA uses P-256 or P-384.

More developer tools: the JWT decoder, Base64 decoder, hash generator and subnet calculator.

Example: a CSR for an online shop

The sample CSR requests shop.example.com and www.shop.example.com for Example Shop Ltd in London, GB, with an EC P-256 key. The signature verifies and no problems are found.

What to expect from the result

The decoder cannot tell whether you still have the matching private key, and it does not contact a CA. Challenge passwords are detected but not shown.

CSR Decoder questions

How do I decode a CSR?

Paste the CSR text, including the BEGIN and END lines, into the box or open the .csr file. The subject, requested names and key appear instantly.

What should I check in a CSR?

That the Common Name and SANs contain every domain you need, the country is a two-letter code such as US or GB, the organisation name is exact, and the key is RSA 2048-bit or larger or ECDSA P-256 or P-384.

What does “signature valid” mean?

A CSR is signed with the private key that matches its public key. A valid signature means the request was not changed after it was created.

Can I edit a CSR?

No. Changing any field breaks the signature. Generate a new CSR with the correct details instead.

Is it safe to paste my certificate here?

Yes. Certificates and CSRs contain only public information, and this tool decodes them in your browser without sending anything to a server. Never paste a private key into any website; if you do, this tool refuses to decode it.

100% private — your data never leaves your browser

No registration, no tracking of your content, no server uploads. Don't just take our word for it:

  • No server, no uploads

    Your files and text are processed entirely on your device. Nothing is ever sent to us.

  • Works offline

    Once loaded, this tool keeps working with your Wi-Fi turned off. Try it.

  • Verify it yourself

    Open your browser's DevTools → Network tab. You'll see zero requests carrying your data.

Explore more tools

More utilities for your next task.

Browse all tools