WW Tools
X.509 Certificate Decoder & CSR Checker

CSR Decoder

A certificate signing request is the thing you hand a CA, and it is the last point at which a mistake is cheap. Paste a PKCS#10 CSR here and every field is rendered: the subject DN attribute by attribute, the subject alternative names inside the extensionRequest attribute, the key algorithm and size, the signature algorithm, and any other attributes the request carries. A challengePassword is reported as present and its value is deliberately not shown, because it is a shared secret between you and the CA. The checks run on a CSR too: a request with no SAN list, a Common Name that the SAN list does not cover, an RSA key under 2048 bits, a SHA-1 signature. Paste a CSR and a certificate together and the Compare tab says whether they share a public key, comparing the key bytes rather than an RSA modulus, so it is correct for EC keys as well. Everything is parsed in this page. Nothing is uploaded and nothing is stored. Signatures are not verified, and a private key pasted by mistake is detected and refused rather than decoded.

Worked example

-----BEGIN CERTIFICATE REQUEST----- → CN=csr.example.com, SAN: DNS:csr.example.com, DNS:www.csr.example.com, RSA 2048-bit

The subject gives the Common Name and organization fields the CA will copy or verify. The SAN list lives in the extensionRequest attribute rather than the subject, which is why a request can look correct in the subject line and still produce a certificate no browser accepts.

Warn at
Dates
Parsed in your browser. Open the network tab and watch: this page makes no requests while you type.
Paste a certificate or a CSR to decode it.

Frequently asked questions

What is a CSR decoder?

A CSR decoder parses the PKCS#10 structure and shows what is actually inside it: the subject DN, the requested subject alternative names, the public key and its size, and the request's attributes. A CSR is base64-wrapped DER, so none of that is readable until something decodes it. The reason to read it before sending is simpler still: a mistake in the SAN list or the key size becomes a reissue once the CA has signed it.

Can a CSR contain a private key?

No. A CSR carries the public half of the key pair and a signature made with the private half, which proves you hold it without disclosing it. That is why pasting a CSR into a decoder is safe in a way that pasting a private key never is. This page detects a pasted private key and refuses to decode it.

How do I check that a CSR matches a certificate?

Paste both into the box, one after the other, and open the Compare tab. Pick the CSR on one side and the certificate on the other, and you get a verdict on whether the CSR matches the certificate, plus both SubjectPublicKeyInfo SHA-256 digests. The comparison reads the raw public key bytes, so it works for EC keys, unlike the widespread openssl -modulus | md5 recipe that only covers RSA.