X.509 Certificate Decoder
Paste a PEM certificate to read its subject, issuer, validity, key and extensions.
Paste a PEM certificate on the left.
How it works
An X.509 certificate is DER-encoded ASN.1 wrapped in Base64 — this reads that byte structure directly: version, serial number, issuer and subject distinguished names, validity window, public key algorithm and size, and every extension present, including Subject Alternative Names, basic constraints and key usage.
What this does not do
It does not verify the signature, build a trust chain to a root CA, check revocation, or compare the validity window against today's date — all of those need a live connection or a trust store this browser-local tool deliberately does not have. It reads what the certificate says about itself, nothing more.
Not a live SSL/TLS checker
This never connects to a host. Paste a certificate you already have — a file on disk, one exported from a browser,
one returned by openssl s_client — it never fetches one from a domain name.
Example
A certificate with SANs DNS:example.com, DNS:www.example.com but no DNS:api.example.com
entry will fail hostname validation for api.example.com in every current browser, even if the Subject
CN happens to read *.example.com — modern validation checks the SAN list, not the CN.
Frequently asked questions
Does this check if the certificate is currently valid or trusted?
No. It reports the notBefore/notAfter dates exactly as encoded and leaves the comparison to today's date to you — it does not verify the signature or walk a chain to a trusted root. Use openssl verify or a browser's own connection for an actual trust decision.
Why does it show the public key size but not the key itself?
The modulus/curve point length is the useful signal — 1024-bit RSA is weak, 2048+ is current baseline, P-256/Ed25519 are fine at their nominal size. The raw key material is shown too, since it is already public in the certificate, but the size is what actually answers "is this strong enough".
What is a Subject Alternative Name and why does it matter more than the Subject CN?
Modern browsers ignore the Subject Common Name for hostname matching entirely and check only the SAN list. A certificate with the right CN but no matching SAN entry fails validation in every current browser, which is why this tool lists SANs prominently rather than as a footnote.
Related tools
CSR Decoder
Paste a PKCS#10 CSR to read its requested subject, key and Subject Alternative Names.
LocalCertificate Fingerprint Calculator
Paste a PEM certificate, get its SHA-1 and SHA-256 fingerprint.
LocalSSH Public Key Inspector
Paste an OpenSSH public key line to read its type, size and SHA256 fingerprint.
LocalSSL Certificate Lookup
Every certificate publicly logged for a domain, decoded — via Certificate Transparency, not a live handshake.
Sends dataSecret Pattern Detector
Scan pasted text or code for the shape of a leaked API key, token or private key.
LocalPassword Entropy Checker
A charset-and-length entropy estimate, with the math and its limits shown, not a bare score.
Local