Certificate Inspector
Decode PEM certificates and keys
Inspect X.509 certificates, CSRs and public keys: subject, issuer, validity, SANs, key type and fingerprints.
- PEM
- X.509
- SSL
- TLS
How to use Certificate Inspector
- Paste one or more PEM blocks into PEM input, such as a certificate, a whole chain, a CSR or a public key. Or click Open file (or drop a file) for a
.pem,.crt,.cer,.der,.csr,.keyor.pubfile. - Try it with Load sample chain, a test leaf, intermediate and root.
- Read each block’s card: for a certificate, the subject, issuer, validity, public key, signature algorithm, serial, extensions and SHA-256 / SHA-1 fingerprints.
- If you pasted several certificates, check the Chain panel for their leaf-to-root order, missing issuers and signature checks.
- Click Copy next to a fingerprint to copy it, or Clear to start again.
How it works
The text is scanned for -----BEGIN …----- / -----END …----- blocks; each body is Base64-decoded to DER and read by a strict DER parser that rejects indefinite lengths, non-minimal encodings, truncated data and trailing bytes. The PEM label decides how a block is decoded. A file that starts with a DER SEQUENCE byte, or text that is bare Base64 without PEM lines, is decoded by recognising its structure.
Certificates are read as X.509: version, serial, issuer and subject names, validity, public key (RSA size and exponent, EC curve, Ed25519, Ed448, X25519, X448, DSA size) and signature algorithm, including RSA-PSS parameters. Decoded extensions include subject and issuer alternative names, key usage, extended key usage, basic constraints, subject and authority key identifiers, CRL distribution points, authority and subject information access, certificate policies, SCT counts, the precertificate flag and OCSP Must-Staple; others are listed by name. Fingerprints are SHA-256 and SHA-1 of the DER, from the Web Crypto API.
With several certificates, each one’s issuer name is matched against the others’ subject names, and key identifiers when both are present, to order the chain from leaf to root. Each signature is then checked with Web Crypto against the next certificate’s public key (or its own, for a self-signed root) for RSA PKCS#1 v1.5, ECDSA on P-256, P-384 and P-521, and Ed25519.
For private keys, only the format, key type and size are read; the key material is never shown.
Limits
- Files up to 5 MB, and up to 50 PEM blocks per input.
- The chain check doesn’t test trust in a root, revocation (CRL or OCSP) or hostnames, so a verified chain isn’t proof a browser would accept it.
- Signatures using RSA-PSS, DSA, Ed448 or curves other than P-256, P-384 and P-521 are shown as not checked. CSR signatures aren’t checked.
- Validity is measured against this device’s clock at the moment the page was opened.
- Encrypted private keys (
ENCRYPTED PRIVATE KEY, or PEM with aProc-Typeheader) and OpenSSH private keys are only identified, not decoded. PKCS#7 / PKCS#12 bundles and other PEM labels aren’t supported.
Privacy
Certificates, CSRs and keys are decoded only in your browser and never uploaded or stored; this tool has no share links. Private keys are recognised so you get a warning, but their contents aren’t shown. Even so, don’t paste real private keys into websites.
Frequently asked questions
How do I get a website’s certificate chain to paste here?
Run openssl s_client -connect example.com:443 -showcerts </dev/null and paste everything it prints. The tool picks out the certificate blocks.
Why does it say my chain is not in order?
The certificates weren’t pasted leaf first, then each issuer. Servers should send them in that order; the Chain panel shows the order it found.
What does “Issuer not included” mean?
No pasted certificate has a subject matching that certificate’s issuer. If the missing issuer is a root CA, that is normal: servers usually don’t send the root, because clients have roots built in. If it is an intermediate, add it.
Can I open a binary .der or .cer file?
Yes. Use Open file or drop it on the input. Binary DER is detected automatically, and PEM files work the same way.
Which fingerprint should I compare?
Prefer the SHA-256 fingerprint. SHA-1 is shown for older tools that still list it, but SHA-1 is no longer collision-resistant.
More tools
- Clean Image: Inspect and remove hidden image metadata
- JWT Decoder: Decode and verify JSON Web Tokens
- Diff Checker: Compare two texts line by line
- JS Runner: Run JavaScript and TypeScript in your browser
- JSON Formatter: Format, validate and minify JSON
- Encode / Decode: Base64, URL, HTML entity and hex
- Hash Generator: MD5, SHA and HMAC of any text
- UUID Generator: Generate UUID v4 and v7 in bulk
- Timestamp Converter: Unix time ↔ human dates
- Regex Tester: Test regular expressions live
- URL Parser: Break a URL into its parts
- HTTP Status Codes: Look up any HTTP status code
- MIME Type Lookup: File extension ↔ MIME type
- Password Generator: Strong random passwords and passphrases
- Random String Generator: Random tokens, IDs and keys
- Slug Generator: Turn titles into URL slugs
- Case Converter: camelCase, snake_case, Title Case and more
- Word Counter: Count words, characters and reading time
- JSON to TypeScript: Generate TypeScript types from JSON
- JSON Diff: Compare two JSON documents structurally
- JSON to SQL: Turn JSON arrays into SQL inserts
- YAML ↔ JSON: Convert between YAML and JSON
- XML ↔ JSON: Convert between XML and JSON
- CSV ↔ JSON: Convert between CSV and JSON
- CSV Viewer: View, sort and filter CSV files
- SQL Formatter: Format and beautify SQL queries
- cURL ↔ Fetch: Convert cURL commands to fetch and back
- Markdown Editor: Write Markdown with a live preview
- Text Cleaner: Remove duplicate lines, empty lines and extra spaces
- Find & Replace: Find and replace in any text
- Cron Expression Builder: Build and explain cron schedules
- User-Agent Parser: Identify browser, OS and device from a user agent
- HTTP Headers Inspector: Paste response headers and get them explained
- JWT Generator: Create and sign test JSON Web Tokens
- Meta Tag Inspector: Check a page's SEO and social tags
- UTM Builder: Build campaign URLs with UTM parameters
- URL Cleaner: Strip tracking parameters from links
- Robots.txt Generator: Create and test a robots.txt file
- Sitemap Generator: Create an XML sitemap from a list of URLs
- Image Compressor: Shrink JPEG, WebP and AVIF images in your browser
- Image Resizer: Resize images by pixels, percentage or to fit a box
- Image Converter: Convert between PNG, JPEG, WebP and AVIF
- Image to Base64: Encode images as Base64 data URIs and decode them back
- SVG Optimizer: Minify and sanitize SVG files
- Favicon Generator: Make favicon.ico, Apple and Android icons from an image or emoji
- Color Converter: HEX, RGB, HSL, OKLCH and contrast checks
- Number Base Converter: Binary, octal, decimal, hex and float bits
- IP / CIDR Calculator: Subnets, masks and IP ranges for IPv4 and IPv6
- JSONPath Query: Query JSON with JSONPath expressions
- JSON Schema Validator: Validate JSON against a schema, or generate one
- Semver Checker: Check versions against semver ranges
- chmod Calculator: Unix permissions: rwx ↔ octal
- .env Diff: Compare and validate .env files
- TOTP Generator: Generate and verify 2FA codes
- String Escaper: Escape and unescape strings for any language
- Unicode Inspector: See every character, code point and hidden symbol
- Mock Data Generator: Generate realistic fake data
- QR Code Generator: Create QR codes for links, Wi-Fi and contacts
- Lorem Ipsum Generator: Placeholder text in paragraphs, sentences or words
- Date Calculator: Date differences, business days and durations
- Unit Converter: Convert bytes, lengths, weights, temperatures and more
- Query CSV with SQL: Run SQL queries on CSV files
- PDF Merge & Split: Merge, split, reorder and rotate PDFs
- PDF Metadata Cleaner: See and remove hidden PDF metadata
- Office Metadata Cleaner: Remove author and revision data from Word, Excel and PowerPoint
- Images to PDF: Combine images into one PDF
- Image Editor: Crop, rotate, resize and adjust images
- Encrypt / Decrypt Text: Encrypt text with a passphrase (AES-GCM)
- SSH Key Generator: Generate Ed25519 and RSA SSH keys locally
- Email Header Analyzer: Trace an email's path and check SPF, DKIM and DMARC
- JSON to Code: Generate Go, Python, Rust, Java, C# and Kotlin models from JSON
- docker run ↔ Compose: Convert docker run commands to docker-compose and back
- Color Palette Extractor: Pull the dominant colours out of any image
- Password Strength Checker: How long would your password take to crack?
- SPF / DKIM / DMARC Checker: Validate and explain email DNS records
- Kubernetes YAML Checker: Validate and explain Kubernetes manifests
- .gitignore Generator: Build a .gitignore from presets
- CSP Builder: Build and check a Content-Security-Policy
- JSON-LD Generator: Create schema.org structured data
- Open Graph Image Generator: Make 1200×630 social preview images
- CSS Generator: Gradients, shadows, clamp() and more
- Time Zone Meeting Planner: Find meeting times across time zones