Certificate & CSR Decoder

Read certificates, CSRs, .p7b bundles and CRLs — then check the chain reaches a trusted root, covers your host name, follows the CA/Browser Forum rules, and isn’t revoked.

Runs entirely in your browser. Your browser blocks this page from opening connections or loading anything from other sites. Nothing you enter is uploaded or saved.

requests since opened: 0
How to verify this yourself
  1. Open your browser’s developer tools (F12, or ⌥⌘I on Mac) → Network tab, then use the tool. No new requests appear.
  2. Or disconnect from the internet after the page loads — the tool keeps working, because it never needed the network.
  3. See the rule itself: in the Network tab, select this page’s document → Response Headers → content-security-policy contains connect-src 'none' and no 'unsafe-inline' for scripts.
  4. Press Test the lock: the page tries a harmless request and the browser blocks it (the Console shows the refusal).
How to use
  1. Paste PEM blocks or open a file — or use “Get the chain from a server” for a ready command.
  2. Read the trust verdict, the expiry overview (for several certificates), then the lint and details.
  3. Type a host name to check coverage; add the CA’s CRL to check revocation.
Get the chain from a server

This page cannot connect to servers. Run this command, then paste its output in the box above.

Common questions

Is it safe to paste a certificate here?

Yes. Certificates and CSRs are public by design, and this page cannot send anything anywhere: your browser blocks every connection it tries to make. Never paste a private key — the decoder refuses them.

How do I check a website’s certificate chain?

Open “Get the chain from a server”, enter the host name and run the command it gives you. Paste the output here to see whether the chain reaches a trusted root, covers the host name and is in the right order.

Why does my certificate show “not trusted”?

Usually an intermediate certificate is missing from what the server sends, or the certificate comes from a private CA. The chain check shows exactly which link is missing.

Known limitations

  • No network: revocation is checked only against a CRL you paste (no OCSP), and Certificate Transparency logs are not queried.
  • Trust uses a bundled snapshot of Mozilla’s root store; Microsoft, Apple and Google stores differ slightly, and your organisation may add private roots.
  • The lint covers the most common Baseline Requirements rules, not all of them. Name constraints and policy mapping are not evaluated.
  • Private keys are refused on purpose.
  • Files over 50 MB are not opened — certificates, bundles and CRLs are far smaller, so it is almost certainly the wrong file.
  • Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works

tools v0.9.0 · build 7317bbb · 2026-10-07