Certificate Decoder
Decode X.509 certificate PEM files in your browser: subject, issuer, serial, validity period, subject alternative names and public-key details. Certs never leave the page.
Decode a sample certificate
Loads a generated self-signed X.509 certificate for example.com and decodes its subject, issuer, validity, SANs and more.
This is a freshly generated self-signed cert, so it will show as not yet expired. Real site certificates work the same way.
FAQ
What does a certificate tell you?
It identifies who owns a domain (the subject), which authority issued it (issuer), when it is valid, which names it covers, and the public key — everything your browser relies on to establish a trusted, encrypted connection.
How do I get a site to decode?
In your browser, click the padlock next to the URL, go to the certificate details, and export or copy the PEM. Several tools and browsers offer an “export certificate” action.
Is it safe to paste a certificate here?
Yes. Certificates are public data — they contain no private key material — and decoding happens entirely in your browser. Nothing is uploaded.
PEM vs DER — what’s the difference?
DER is the raw binary encoding of a certificate; PEM is the base64 text version wrapped in BEGIN/END markers that this tool accepts. Most systems let you export either.