PEM Certificate and CSR Decoder

Decode public certificate, CSR and public-key metadata from a bounded strict DER/PEM structure.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Inspect input controls

Showing an example. Edit to see your own.

One public PEM block only. Never paste a private key. The example is a synthetic self-signed certificate.

Processed in your browser. Your inputs stay on this device.

How to use PEM Certificate and CSR Decoder

  1. Paste one supported public certificate, CSR or public-key block.
  2. Read the decoded structure, algorithm, names and stored dates.
  3. Use a separate trust and signature workflow when you need to validate a certificate.

Example: PEM Certificate and CSR Decoder

Read the included public certificate’s metadata.

You add
Keep the supplied synthetic CERTIFICATE PEM in Public certificate, CSR or public-key PEM and run decoding.
You get
The report names synthetic.example.invalid, identifies the public RSA key and lists stored validity dates and a public fingerprint. The self-signed example is not trusted by this decoder.

Supported inputs and limits

One public certificate, PKCS#10 CSR, SPKI or RSA public-key PEM up to 256 KiB decoded; DER depth 32 and 2,000 nodes. RSA, P-256/P-384/P-521/secp256k1 EC and Edwards public structures only. Extensions report OIDs/critical flags/sizes, not complete interpretation. Refuses private keys, malformed/trailing DER and unsupported structures. No signature, chain, trust, revocation, ownership or security-strength validation.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Validity dates are fields rather than a trust decision

A certificate can contain an apparently current date range and still be untrusted or revoked. This tool reads public DER structure; it does not verify the signature, chain, hostname, ownership or revocation status. A CSR similarly contains requested identity details, not an issued trusted certificate.

Extensions are only partially described

The output reports extension identifiers, critical flags and sizes rather than fully interpreting every extension. Do not treat an absent decoded name as proof that a restriction is absent. Private keys, trailing DER and unsupported structures are refused. Keep the report’s parsing scope separate from security-strength or compliance claims.

Questions about PEM Certificate and CSR Decoder

Does a valid date mean a certificate is trusted?

No. Trust also requires verified signatures, chain and other checks outside this tool.

Does a CSR prove the requested names belong to someone?

No. Names in a request are unverified input.

Can private-key PEM be decoded?

No. Paste only the supported public material.

Project manager: Tony Hines · Content updated 3 October 2026 · Report a problem