Paste a PEM-encoded certificate to see its issuer, subject, validity window, Subject Alternative Names, key usage, extensions, and fingerprint — without OpenSSL or an online upload.
Copy the full PEM block, including the BEGIN/END CERTIFICATE lines.
Issuer, validity dates, SANs, key usage, and fingerprint appear immediately.
Catch an expired, mismatched, or wrong-domain certificate before it causes an outage.
Standard PEM-encoded X.509 certificates (the -----BEGIN CERTIFICATE----- format).
Paste the leaf certificate here for full details; use the Bulk Decoder or Chain Sorter tool for multi-certificate chains.
Yes — nothing is uploaded, decoding happens entirely in your browser.