(Documentation in English)
What it does
The Certificate Decoder parses PEM-encoded X.509 certificates — the format used for TLS/HTTPS, S/MIME, and code signing — and turns them into a human-readable report, entirely in your browser. It decodes the
Base64Base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
DER bytes with anASNASNA number identifying one routing domain on the internet (one AS = one network under a single policy), used by BGP to exchange routes.Learn more
.1 parser written from scratch and extracts the subject, issuer, validity window, key information, extensions (Subject Alternative Names, Basic Constraints, Key Usage, Extended Key Usage), and the SHA-256 fingerprint. Paste a full chain (leaf → intermediate → root) and every certificate is decoded separately, in order, with its position in the chain labeled.The page is a split workspace: the PEM input sits on the left, the decoded report in a sticky panel on the right that follows you as you scroll. On small screens the two stack, input first. Decoding is live — as soon as the textarea holds a parseable PEM block the report fills in; there is no Decode button to press.
How to use it
- Paste a PEM certificate into the left text area. The input must start with
-----BEGIN CERTIFICATE-----and end with-----END CERTIFICATE-----. Click Sample to load a built-in test certificate, or Clear to reset. - The report appears immediately on the right, organized into sections: Identity, Issuer, Validity, Subject Alternative Names, Key Info, Extensions, and Fingerprint (SHA-256).
- The Validity section shows a color-coded status badge: red Expired once the current date is past
notAfter; yellow when 30 days or fewer remain; green beyond that. Both countdown badges show the exact number of days. - Copy the SHA-256 fingerprint with one click, or Download a
cert-summary.txtfrom the report header — the decoded report as plain text, onekey: valueper line (subject, issuer, validity dates and status, SANs, serial). - To decode a certificate chain, paste every PEM block at once (e.g. the whole
fullchain.pem). Each certificate gets its own card labeled with its chain position, and the header shows a “Chain: N certificates” badge.
Examples
Decode a web server certificate
Paste the PEM from cat fullchain.pem (or your CA’s issuance email). The report shows the server’s Common Name (e.g. www.example.com), the issuing CA, the SAN entries (DNS names, IPs, emails), the RSA or ECDSA key size, and whether the certificate is a CA.
Try the built-in sample
Click Sample. The loaded certificate is a self-signed v3 test CA for test.cosmolabs.org (O = CosmoLabs Test): RSA 2048-bit key, valid 2026-08-16 23:15:46 UTC → 2036-08-13 23:15:46 UTC, SANs cosmolabs.org and www.cosmolabs.org, IP 127.0.0.1, email admin@cosmolabs.org. Expiry is years out, so the status badge is green. The serial renders in openssl-style colon hex, starting 26:55:56:7E:….
Check if a certificate is expired
The Validity section shows the exact notBefore/notAfter dates plus the badge: red “Expired” past the deadline, a yellow warning at 30 days or fewer remaining, and a green day-count badge otherwise.
Export the summary
After a decode, click Download in the report header to save cert-summary.txt. For the sample it is exactly:
Subject: C=US, ST=California, L=San Francisco, O=CosmoLabs Test, OU=Engineering, CN=test.cosmolabs.org
Issuer: C=US, ST=California, L=San Francisco, O=CosmoLabs Test, OU=Engineering, CN=test.cosmolabs.org
Not Before: 2026-08-16 23:15:46 UTC
Not After: 2036-08-13 23:15:46 UTC
Status: 3641 days remaining
DNS SANs: cosmolabs.org, www.cosmolabs.org
SAN IPs: 127.0.0.1
Email SANs: admin@cosmolabs.org
Serial: 26:55:56:7E:A1:B2:9D:1E:68:B2:A3:8C:5B:65:41:D3:74:86:77:73
The Status: day count ticks down daily. For a chain, every certificate is written into the same file under a Certificate N of M header line.
Verify a certificate chain
Paste the full chain (leaf + intermediate + root). Each certificate is decoded separately into its own card — “Certificate #2 in chain”, “Certificate #3 in chain” — and the report header carries a “Chain: 3 certificates” badge.
Good to know
- Private: all parsing happens 100% in your browser — nothing is uploaded and no network request is made with your certificate data.
- No external
ASNASNA number identifying one routing domain on the internet (one AS = one network under a single policy), used by BGP to exchange routes.Learn more
.1 library — the DER parser is implemented from scratch, handling SEQUENCE, SET, INTEGER, BIT STRING, OCTET STRING, OID, UTF8String, PrintableString, IA5String, UTCTime, GeneralizedTime, and context-tagged elements. - SHA-256 fingerprint is computed via the Web Crypto API over the raw DER bytes — it matches
openssl x509 -fingerprint -sha256output. - Supported extensions: Subject Alternative Name (DNS, IP, email), Basic Constraints, Key Usage, Extended Key Usage. Other extensions are present in the certificate but not displayed.
- The Download button appears only after a successful decode and always reflects the current report — re-paste a different certificate and the next download contains that one.
- Related tools:
ChecksumChecksumA short digest computed from a block of data, compared after transfer or storage to detect corruption. Changing one bit changes the checksum.
Verifier,HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
Type Identifier.