Try
Decoded
Paste a certificate to see what’s in it. Nothing is fetched: links inside it are shown as text.
About this tool
- Runs in
- your browser
- Your input sent to our servers
- Nothing
- Kept on this device
- nothing
More in the privacy policy.
How to use it
- 01Paste a certificate (-----BEGIN CERTIFICATE-----), several in a row for a chain, or a certificate request; or open a .pem, .crt, .cer, .der or .csr file, or drop one on the page. Or pick one under Try.
- 02Read each certificate’s card: who it’s for and who issued it, how long it’s valid, its names, key, extensions and fingerprints. In a chain, each card says whether its signature checks out against the next certificate’s key.
- 03Copy any value, a certificate’s PEM on its own, or the whole summary as text.
Related tools
Questions
Does it check whether the certificate is trusted or revoked?
No. It shows what’s inside and checks signatures between the certificates you paste, with your browser’s own cryptography. Trust depends on the root certificates your system or browser holds, and revocation on the issuer’s OCSP or CRL service; checking either means sending requests, which this page doesn’t do. The OCSP and CRL addresses are shown as text.
What does “checked against the next certificate” mean?
In a chain, each certificate is signed with the key of the one after it: the leaf by an intermediate, the intermediate by a root. The page checks each signature against the next certificate’s public key. A root signs itself. If your browser can’t do a signature’s algorithm, the card names the algorithm and says it can’t check. RSA-PSS signatures are checked; a public key restricted to RSA-PSS may not be accepted by your browser (Chrome doesn’t accept it), and then the card says so. If the next certificate’s name doesn’t match this certificate’s issuer, the chain is in the wrong order or a certificate is missing.
Can I paste a private key?
Don’t. The page recognises a private key and doesn’t decode it, but a private key shouldn’t be pasted into any website. If one was in use and you pasted it somewhere, replace it.
What is the SHA-256 fingerprint?
A hash of the whole certificate, the same value browsers show in their certificate viewer and openssl x509 -fingerprint -sha256 prints. Two certificates with the same fingerprint are the same certificate.
Is my certificate sent anywhere?
No. It’s decoded in your browser, and a file you open is read there too. It isn’t sent to our servers, put into the page address or saved.