CSR Decoder
Paste a PKCS#10 CSR to read its requested subject, key and Subject Alternative Names.
Paste a PEM CSR on the left.
How it works
A PKCS#10 Certificate Signing Request carries a requested subject and public key, signed with the corresponding private key as proof of possession — no issuer, no validity dates, since those are the CA's to assign. This reads that structure: subject DN, public key algorithm and size, signature algorithm, and any requested Subject Alternative Names.
What was requested is not what will be issued
A CA is free to drop or override requested SANs, reject the requested subject entirely, or reissue under a different key policy. Nothing here predicts what the resulting certificate will actually contain — it decodes the request, not a promise.
Example
Requested SANs live inside an extensionRequest attribute (OID
1.2.840.113549.1.9.14), not the top-level subject field — a CSR with SANs entirely outside that
attribute has none a CA will act on, no matter what the Subject CN reads.
Frequently asked questions
Where do the requested Subject Alternative Names come from in a CSR?
They live inside an extensionRequest attribute (a PKCS#9 attribute, OID 1.2.840.113549.1.9.14), not in the top-level subject field — a CSR with SANs entirely outside that attribute has none a CA will act on, no matter what the Subject CN says.
Can I use this to check if my CSR matches a specific private key?
No — that requires comparing the CSR's public key against the private key directly (e.g. openssl comparing modulus values), which needs the private key itself. This tool never asks for a private key and only ever sees the CSR you paste.
Why does the decoder reject a file that starts with '-----BEGIN CERTIFICATE-----'?
That PEM label is a certificate, not a request — this decoder specifically expects '-----BEGIN CERTIFICATE REQUEST-----' or '-----BEGIN NEW CERTIFICATE REQUEST-----'. Use the X.509 Certificate Decoder for an already-issued certificate instead.
Related tools
X.509 Certificate Decoder
Paste a PEM certificate to read its subject, issuer, validity, key and extensions.
LocalCertificate Fingerprint Calculator
Paste a PEM certificate, get its SHA-1 and SHA-256 fingerprint.
LocalSSH Public Key Inspector
Paste an OpenSSH public key line to read its type, size and SHA256 fingerprint.
LocalSecret Pattern Detector
Scan pasted text or code for the shape of a leaked API key, token or private key.
LocalPassword Entropy Checker
A charset-and-length entropy estimate, with the math and its limits shown, not a bare score.
LocalIOC Extractor
Pull indicators of compromise out of any block of text, log or report.
Local