Navigation

X.509 Certificate Decoder

Paste a PEM certificate to parse the subject, issuer, validity, Subject Alternative Names, serial, public key and signature algorithm. Parsed locally · never paste a private key.

PEM certificate
Decoded certificate
Paste a PEM certificate and click Decode.
Related tools
How to use
1
Paste the PEM

Include the BEGIN/END CERTIFICATE lines, or just the base64 body.

2
Decode

Subject, issuer, dates, SAN and key details are extracted locally.

3
Check validity

Expired or not-yet-valid certificates are flagged.

Frequently Asked Questions

A base64 text encoding of a DER X.509 certificate, wrapped in BEGIN/END CERTIFICATE lines · the most common way certificates are shared as text.

The SAN extension lists every identity a certificate covers · DNS names, IPs, emails, URIs. Browsers validate the hostname against the SAN, not the Common Name.

No · it is parsed entirely in your browser. Still, never paste a private key into any online tool. This decoder is for public certificates only.

No, and it should not. It decodes X.509 certificates only. Keep private keys on trusted, offline systems.

A free tool from mlab, the intelligence platform for IOC, domain and file analysis. Rolling this out across a team? Talk to us.