SSL & Certificates

SSL Certificate Decoder

Read what is actually inside a certificate — who it was issued to, who signed it, when it expires, and every domain it covers.

PEM certificate
Output

Result appears here after you select

{ } How to use

  1. Paste the certificate, including its BEGIN and END lines.
  2. Select Process to read it.
  3. The details appear as a table; switch to Text to copy or download them.

{ } How it works

SSL Certificate Decoder works on the text you provide. Select Process ▸ and it runs entirely in your browser — nothing is uploaded to a server — then shows the result in the Output panel.

Input

  • PEM certificate — paste or type your input in the left panel (use Sample for an example)

Output

TXT text — copy or download it from the Output panel.

{ } Common uses

  • Confirm a certificate covers every domain you expected before you install it.
  • Find out how many days are left before a certificate expires.
  • Check which authority issued a certificate, and whether it is self-signed.
  • Read a certificate a supplier sent you, without installing anything.

{ } Limitations

  • This reads a certificate; it does not verify one. Nothing here checks the signature, follows the chain to a trusted root, or looks for revocation — a forged certificate would be described exactly as accurately as a genuine one.
  • It reads certificates you already have. To inspect what a live website is serving, use a checker that connects to the site: a browser will not let a page read another site’s certificate.
  • Binary DER files (.der, .cer) need converting with DER to PEM first.

{ } FAQ

Is my data uploaded to a server?

No. Everything runs locally in your browser — your files never leave your device.

Can I process more than one file at once?

This tool works on one input at a time.

Is this tool free?

Yes — it’s completely free and needs no sign-up.

Why does it say "self-signed"?

Because the subject and the issuer are the same name, which means the certificate vouches for itself. That is normal for a root certificate or one you generated for testing, and a problem for a certificate a browser is meant to trust.

Is my private key uploaded anywhere?

No. Every one of these tools runs entirely in your browser — the certificate and key are read, converted and shown without a byte being sent anywhere. That is what makes it safe to paste a private key, which you should never do on a site that converts it on a server.

Does this work with ECDSA certificates?

Yes. RSA, ECDSA and Ed25519 are all read the same way, because the structure is read directly rather than through a library that only understands RSA keys.