Free to use, no account

X.509 Certificate Decoder

Inspect an X.509 certificate on this device. Paste a PEM/base64 certificate or choose a PEM, CER, CRT or DER file to read its subject, issuer, validity dates, alternative names and SHA-256 fingerprint.

PEM, CER, CRT and DER files are supported. Maximum size: 1 MiB.

Decoding does not verify a signature, trust chain, hostname, revocation status or whether a site is safe. Dates alone do not establish trust.

How do I decode an X.509 certificate?

Paste one PEM certificate or base64-encoded DER, or select a local PEM, CER, CRT or DER file. The decoder displays certificate fields and a SHA-256 fingerprint in your browser.

Frequently asked questions

How do I decode an X.509 certificate?

Paste one PEM certificate or base64-encoded DER, or select a local PEM, CER, CRT or DER file. The decoder displays certificate fields and a SHA-256 fingerprint in your browser.

Is my certificate uploaded?

No. The selected certificate is read and decoded in this browser. It is not sent to a server. Files are limited to 1 MiB.

Does decoding prove that a certificate is trusted?

No. This tool reads certificate fields only. It does not validate signatures, issuer chains, hostnames, revocation status or browser trust.

Can I decode a DER certificate?

Yes. Choose a local DER file. You can also paste its base64-encoded DER representation.

What does the SHA-256 fingerprint identify?

It is a digest of the certificate file bytes, useful for comparing copies. It is not a trust or safety verdict.