Digital ToolPad.

Runs 100% in your browser

Your data never leaves your device. zero uploads.

SSL Certificate Decoder

Paste a PEM certificate or a full chain to see who it was issued to, which domains it covers, when it expires and whether each signature checks out.

  • Chain signatures verified
  • Expiry & key checks
  • SHA-256 fingerprints
  • Nothing uploaded
Found: 3 certificates

#1 Certificate

www.example.com

DV
Subject
  • Common name: www.example.com
Issuer
  • Country: GB
  • Organization: Digital ToolPad Example
  • Common name: Example TLS Issuing CA E1
Valid from
2026-10-01 00:00:00 UTC
Valid until
2031-10-01 00:00:00 UTC
Names (SAN)
  • www.example.com
  • example.com
  • api.example.com
Public key
EC 256-bit (P-256, prime256v1)
Signature
ecdsa-with-SHA256
Serial number
04:D2:A1:B3:C4:D5:E6:F7:08
Version
X.509 v3

Extensions (9)

Basic Constraints
CriticalCA: FALSE
Key Usage
CriticalDigital signature
Extended Key Usage
TLS server authentication
Subject Alternative Name
DNS: www.example.com DNS: example.com DNS: api.example.com
Subject Key Identifier
C9:2D:54:FC:59:B8:81:D5:08:63:C7:09:CB:ED:05:43:C0:14:06:99
Authority Key Identifier
Key ID: AD:A8:BA:C9:B2:99:02:5B:24:40:64:9F:8D:E3:A5:C8:A8:C1:76:54
Authority Information Access
OCSP: http://ocsp.example.com CA issuers: http://ca.example.com/e1.crt
CRL Distribution Points
URI: http://crl.example.com/e1.crl
Certificate Policies
CA/Browser Forum domain validated (2.23.140.1.2.1)

#2 CA certificate

Example TLS Issuing CA E1

Subject
  • Country: GB
  • Organization: Digital ToolPad Example
  • Common name: Example TLS Issuing CA E1
Issuer
  • Country: GB
  • Organization: Digital ToolPad Example
  • Common name: Example Root CA R1
Valid from
2026-01-01 00:00:00 UTC
Valid until
2036-01-01 00:00:00 UTC
Names (SAN)
None
Public key
EC 256-bit (P-256, prime256v1)
Signature
ecdsa-with-SHA384
Serial number
5A:1E:7F:00:C0:FF:EE:01
Version
X.509 v3

Extensions (5)

Basic Constraints
CriticalCA: TRUE Path length: 0
Key Usage
CriticalDigital signature Certificate signing CRL signing
Extended Key Usage
TLS server authentication TLS client authentication
Subject Key Identifier
AD:A8:BA:C9:B2:99:02:5B:24:40:64:9F:8D:E3:A5:C8:A8:C1:76:54
Authority Key Identifier
Key ID: ED:AD:1E:F1:5A:DA:94:57:B3:78:85:2B:00:84:16:BB:E9:D1:06:6F

#3 CA certificate

Example Root CA R1

Subject
  • Country: GB
  • Organization: Digital ToolPad Example
  • Common name: Example Root CA R1
Issuer
  • Country: GB
  • Organization: Digital ToolPad Example
  • Common name: Example Root CA R1
Valid from
2026-01-01 00:00:00 UTC
Valid until
2046-01-01 00:00:00 UTC
Names (SAN)
None
Public key
EC 384-bit (P-384, secp384r1)
Signature
ecdsa-with-SHA384
Serial number
3C:4F:38:EB:FD:A1:9A:FD:D0:65:AC:C8:00:84:05:49:7B:B5:26:1C
Version
X.509 v3

Extensions (4)

Authority Key Identifier
Key ID: ED:AD:1E:F1:5A:DA:94:57:B3:78:85:2B:00:84:16:BB:E9:D1:06:6F
Basic Constraints
CriticalCA: TRUE
Key Usage
CriticalCertificate signing CRL signing
Subject Key Identifier
ED:AD:1E:F1:5A:DA:94:57:B3:78:85:2B:00:84:16:BB:E9:D1:06:6F

What is an SSL certificate decoder?

An SSL (TLS) certificate is an X.509 document that binds a domain name to a public key and is signed by a certificate authority. In PEM form it is just Base64 text between BEGIN CERTIFICATE and END CERTIFICATE lines, which is unreadable without a decoder. This decoder parses the certificate in your browser and shows the subject and issuer, every domain in the Subject Alternative Name, the validity dates, the key type and size, the serial number, SHA-1 and SHA-256 fingerprints and all extensions, including key usage, OCSP and CRL addresses, certificate policies (DV, OV or EV) and Certificate Transparency timestamps. Paste a whole chain and it links each certificate to its issuer and verifies the signatures cryptographically.

How to decode an SSL certificate

  1. Paste one or more PEM certificates, or choose Open File for .pem, .crt, .cer, .der or .p7b files.
  2. Read the summary for each certificate: names, dates, key and status.
  3. Check the warnings list for expiry, weak keys or missing names.
  4. Switch to ASN.1 to inspect the raw structure, or PEM & DER to convert and download.

Do the same with OpenSSL

Prefer the command line? These OpenSSL commands do the same job on your own machine.

Show a certificate as text
openssl x509 -in cert.pem -noout -text
Get the certificate a server sends
openssl s_client -connect example.com:443 -servername example.com -showcerts </dev/null
Check the expiry date
openssl x509 -in cert.pem -noout -enddate
SHA-256 fingerprint
openssl x509 -in cert.pem -noout -fingerprint -sha256

Why use this SSL Certificate decoder

  • Real chain verificationEach certificate’s signature is checked against its issuer’s public key (RSA, RSA-PSS, ECDSA and Ed25519), not just matched by name.
  • Problems flagged for youExpiry, weak keys, SHA-1 signatures, missing SANs, lifetimes over the CA/Browser Forum limit and CN mismatches are called out in plain English.
  • Every field, readableSANs, key usage, extended key usage, AIA, CRL, policies, SCTs and must-staple are decoded rather than shown as hex.
  • Nothing is uploadedDecoding and signature checks run in your browser with the Web Crypto API. Certificates and CSRs never reach a server, which matters for internal hosts and unreleased domains.

Common uses

  • Before installing. Confirm a new certificate covers every host name and matches the expected issuer.
  • Chain problems. Find a missing or misordered intermediate behind “unable to get local issuer certificate”.
  • Expiry audits. Check exactly when a certificate expires, down to the second, in UTC.
  • Internal PKI. Inspect certificates from private CAs, Kubernetes, VPNs and service meshes without uploading them.

More developer tools: the JWT decoder, Base64 decoder, hash generator and subnet calculator.

Example: a three-certificate chain

The sample shows a site certificate for www.example.com, its issuing CA and a root. Each signature is verified with the next certificate’s key, and the site certificate is flagged because its five-year lifetime exceeds what public CAs may issue.

What to expect from the result

Signature checks need a browser with Web Crypto; Ed25519 needs a recent browser. Revocation (OCSP and CRL) is not checked because that requires contacting the CA. Trust is not evaluated against a browser root store.

SSL Certificate Decoder questions

How do I decode an SSL certificate?

Paste the PEM text, including the BEGIN and END lines, or open the .crt, .cer or .pem file. The decoded fields appear instantly.

How can I check when a certificate expires?

The Valid until row shows the exact expiry in UTC, and the status badge shows how many days are left. Certificates expiring within 30 days are flagged.

Why does my certificate chain fail?

Usually an intermediate certificate is missing or the order is wrong. Paste the full chain: the decoder shows which certificate signed which and warns when the order is not leaf first.

Which formats can I decode?

PEM (BEGIN CERTIFICATE, CERTIFICATE REQUEST, PUBLIC KEY, RSA PUBLIC KEY, PKCS7), binary DER files (.der, .cer, .crt), PKCS#7 bundles (.p7b, .p7c), bare Base64 and hex. Several PEM blocks can be pasted at once.

Is it safe to paste my certificate here?

Yes. Certificates and CSRs contain only public information, and this tool decodes them in your browser without sending anything to a server. Never paste a private key into any website; if you do, this tool refuses to decode it.

100% private — your data never leaves your browser

No registration, no tracking of your content, no server uploads. Don't just take our word for it:

  • No server, no uploads

    Your files and text are processed entirely on your device. Nothing is ever sent to us.

  • Works offline

    Once loaded, this tool keeps working with your Wi-Fi turned off. Try it.

  • Verify it yourself

    Open your browser's DevTools → Network tab. You'll see zero requests carrying your data.

Explore more tools

More utilities for your next task.

Browse all tools