Certificate Decoder

Paste or drop a PEM/DER certificate and get the full X.509 breakdown: SANs, EKUs, key usage, thumbprints and expiry — without the certificate leaving your browser.

✓ runs 100% in your browser — no data leaves this page

Frequently asked

Is my certificate uploaded anywhere?
No. Parsing happens in WebAssembly in your browser tab; the site has no upload endpoint for this tool.
Which formats are supported?
PEM blocks (BEGIN CERTIFICATE), bare base64, and binary DER files (.cer/.crt/.der). PFX/P12 containers are password-protected archives — export the certificate first.
Why does it warn about a missing SAN?
Modern TLS clients ignore the CN field; without a Subject Alternative Name most validation fails. The same applies to EAP-TLS identity mapping.
An unhandled error has occurred. Reload 🗙