An SSL (TLS) certificate is an X.509 document that binds a domain name to a public key and is signed by a certificate authority. In PEM form it is just Base64 text between BEGIN CERTIFICATE and END CERTIFICATE lines, which is unreadable without a decoder. This decoder parses the certificate in your browser and shows the subject and issuer, every domain in the Subject Alternative Name, the validity dates, the key type and size, the serial number, SHA-1 and SHA-256 fingerprints and all extensions, including key usage, OCSP and CRL addresses, certificate policies (DV, OV or EV) and Certificate Transparency timestamps. Paste a whole chain and it links each certificate to its issuer and verifies the signatures cryptographically.
How to decode an SSL certificate
Paste one or more PEM certificates, or choose Open File for .pem, .crt, .cer, .der or .p7b files.
Read the summary for each certificate: names, dates, key and status.
Check the warnings list for expiry, weak keys or missing names.
Switch to ASN.1 to inspect the raw structure, or PEM & DER to convert and download.
Do the same with OpenSSL
Prefer the command line? These OpenSSL commands do the same job on your own machine.
Real chain verificationEach certificate’s signature is checked against its issuer’s public key (RSA, RSA-PSS, ECDSA and Ed25519), not just matched by name.
Problems flagged for youExpiry, weak keys, SHA-1 signatures, missing SANs, lifetimes over the CA/Browser Forum limit and CN mismatches are called out in plain English.
Every field, readableSANs, key usage, extended key usage, AIA, CRL, policies, SCTs and must-staple are decoded rather than shown as hex.
Nothing is uploadedDecoding and signature checks run in your browser with the Web Crypto API. Certificates and CSRs never reach a server, which matters for internal hosts and unreleased domains.
Common uses
Before installing. Confirm a new certificate covers every host name and matches the expected issuer.
Chain problems. Find a missing or misordered intermediate behind “unable to get local issuer certificate”.
Expiry audits. Check exactly when a certificate expires, down to the second, in UTC.
Internal PKI. Inspect certificates from private CAs, Kubernetes, VPNs and service meshes without uploading them.
The sample shows a site certificate for www.example.com, its issuing CA and a root. Each signature is verified with the next certificate’s key, and the site certificate is flagged because its five-year lifetime exceeds what public CAs may issue.
What to expect from the result
Signature checks need a browser with Web Crypto; Ed25519 needs a recent browser. Revocation (OCSP and CRL) is not checked because that requires contacting the CA. Trust is not evaluated against a browser root store.
SSL Certificate Decoder questions
How do I decode an SSL certificate?
Paste the PEM text, including the BEGIN and END lines, or open the .crt, .cer or .pem file. The decoded fields appear instantly.
How can I check when a certificate expires?
The Valid until row shows the exact expiry in UTC, and the status badge shows how many days are left. Certificates expiring within 30 days are flagged.
Why does my certificate chain fail?
Usually an intermediate certificate is missing or the order is wrong. Paste the full chain: the decoder shows which certificate signed which and warns when the order is not leaf first.
Which formats can I decode?
PEM (BEGIN CERTIFICATE, CERTIFICATE REQUEST, PUBLIC KEY, RSA PUBLIC KEY, PKCS7), binary DER files (.der, .cer, .crt), PKCS#7 bundles (.p7b, .p7c), bare Base64 and hex. Several PEM blocks can be pasted at once.
Is it safe to paste my certificate here?
Yes. Certificates and CSRs contain only public information, and this tool decodes them in your browser without sending anything to a server. Never paste a private key into any website; if you do, this tool refuses to decode it.
100% private — your data never leaves your browser
No registration, no tracking of your content, no server uploads. Don't just take our word for it:
No server, no uploads
Your files and text are processed entirely on your device. Nothing is ever sent to us.
Works offline
Once loaded, this tool keeps working with your Wi-Fi turned off. Try it.
Verify it yourself
Open your browser's DevTools → Network tab. You'll see zero requests carrying your data.