Certificate Decoder

Paste a certificate, a whole chain, a .p7b container or a certificate signing request and this page takes it apart: subject and issuer, validity dates, the public key, every extension, the fingerprints and a normalised PEM copy. PEM text, bare base64, DER pasted as hexadecimal and files read from your disk are all accepted, and a single paste may hold several blocks at once — each one is decoded on its own and labelled in the output.
nothing decoded yet
Tip: a full chain is just several -----BEGIN CERTIFICATE----- blocks one after another. Windows exports a chain as a .p7b file, which this page also reads.
Stays on this machine — nothing is sent anywhere.
Nothing decoded yet. Paste a certificate above and press Decode, or load one of the samples to see what the output looks like.
What this page does: it reads the certificate structure itself — the ASN.1 DER encoding, the distinguished names, the validity dates, the public key and the extensions — and prints what it finds. It does not validate anything: a certificate that decodes cleanly here can still be expired, revoked or signed by a CA your browser refuses. Use the SSL certificate checker for the checks and the HTTPS configuration audit for the headers.

Fingerprints are computed locally with the browser's own hashing. The SHA-256 fingerprint is the one to compare against the value a CA publishes.

Privacy: everything runs in this page. No upload, no server, no cookies, no analytics — you can open this file straight from disk and it still works.