Certificate Decoder — X.509, PKCS#7 and PKCS#10, local
Certificate Decoder
Paste a certificate, a whole chain, a .p7b container or a certificate signing
request and this page takes it apart: subject and issuer, validity dates, the public key,
every extension, the fingerprints and a normalised PEM copy. PEM text, bare base64, DER
pasted as hexadecimal and files read from your disk are all accepted, and a single paste may
hold several blocks at once — each one is decoded on its own and labelled in the output.
nothing decoded yet
Tip: a full chain is just several -----BEGIN CERTIFICATE----- blocks one after another.
Windows exports a chain as a .p7b file, which this page also reads.
Stays on this machine — nothing is sent anywhere.
Decoded output
Nothing decoded yet. Paste a certificate above and press Decode, or load one of the
samples to see what the output looks like.
What this page does: it reads the certificate structure itself — the ASN.1 DER
encoding, the distinguished names, the validity dates, the public key and the extensions — and prints
what it finds. It does not validate anything: a certificate that decodes cleanly here can still be expired,
revoked or signed by a CA your browser refuses. Use the
SSL certificate checker for the checks and the
HTTPS configuration audit for the headers.
Fingerprints are computed locally with the browser's own hashing. The SHA-256 fingerprint is
the one to compare against the value a CA publishes.
Privacy: everything runs in this page. No upload, no server, no cookies, no analytics —
you can open this file straight from disk and it still works.
🔒 SSL & TLS Tools
Certificate and key utilities that run entirely in your browser.