AI Tools Free

CSR Decoder

Inspect a PEM PKCS#10 certificate signing request with this CSR decoder. Read its subject, public key and requested extensions, keeping self-signature status separate from CA trust.

Free to useNo sign-upRuns in your browser
Enter your details

Enter the inputs, then select Decode CSR.

Your result
Enter your details

Result will appear here

How CSR Decoder works

The decoder reads one PEM certificate request, checks its ASN.1 structure, and extracts subject attributes, public-key information, and requested extensions.

Self-signature verification is attempted when the algorithm and crypto context support it. This concerns the included key and request signature; it does not establish CA trust, domain ownership, or issuance.

Use one matching PEM block and valid request data.

A certificate request connected to subject, public-key, and extension field groups.
Illustration of the CSR Decoder workflow.

How to use CSR Decoder

Paste one PEM certificate signing request to inspect the information it contains.

Paste one certificate request

Enter one PEM CERTIFICATE REQUEST block, preserving its markers and encoded body. Do not use a private key or an issued certificate. The tool inspects the public information in a PKCS#10 request.

PEM certificate signing…
CSR Decoder native input panel with the actual PEM certificate signing request settings used for this example.
Configure PEM certificate signing request; select Decode CSR.

Decode the request fields

Run the decoder and inspect the subject, public-key, and requested-extension rows. The result also attempts to report self-signature status when the algorithm and crypto environment support that check.

CSR decoded
CSR Decoder actual result panel showing CSR decoded.
Submitted result: CSR decoded. Self-signature: Verified.

Read the trust boundary

Review the self-signature status with the explicit CA-trust note. Verified concerns the request signature and included public key; it does not establish domain ownership, certificate issuance, or trust by a certificate authority.

Output details
CSR Decoder actual output details region and result note after submitting the pictured settings.
Review the actual CSR Decoder output. Read the result note.

When to use CSR Decoder

Review the request before comparing it with the intended certificate application.

Review a prepared request

Inspect a CSR before handing it to a certificate issuance workflow. Check the subject and alternative names against the request requirements. A readable request does not establish that the submitter controls those names or that a certificate will be issued.

Developer input and configuration represented by document cards.
Prepare the input. Concept illustration.

Review certificate request names

Decode a request when investigating why its requested names differ from an expected list. Examine alternative names as well as the subject. The result can identify the request contents, but it cannot explain later certificate authority policy decisions.

A developer example flowing from input to reviewed output.
Inspect an example. Concept illustration.

Inspect public key information

Read the key algorithm and available public key details when reviewing which request was prepared. If a SHA-256 fingerprint is available, keep its public key context in the notes. It is not a fingerprint of an issued certificate.

Developer output handed to the next stage of a workflow.
Use the result in your workflow. Concept illustration.

Interpret CSR self-signature without CA trust

Read the requested identity details separately from the status of the request’s self-signature.

A Verified status concerns the request self signature where verification is supported. It does not show domain ownership, certificate issuance, or trust by a browser or certificate authority.

Unsupported algorithms or unavailable crypto can leave the signature Not checked. Extension identifiers can be shown even when their contents are not presented as a fully interpreted field.

A developer result reviewed alongside its source.
Review the returned output. Concept illustration.

Check request format and verification scope

Compare the request fields with the intended certificate application before handing the CSR to a certificate authority.

Use one matching PEM block and valid request data. Extra trailing ASN1 data or an unrelated PEM type is rejected. Recopy the original request rather than altering its encoded bytes to make parsing succeed.

If a status is Invalid, inspect the original request generation workflow separately. The decoder does not repair a signature, generate a replacement request, or inspect the private key.

Input format and assumptions reviewed for a developer task.
Check format and assumptions. Concept illustration.

Decode a certificate signing request

Paste one PEM certificate signing request to inspect the information it contains.

Inspect a CSR

CSR Decoder: common questions

Answers about using CSR Decoder and understanding its results.

Can I paste a private key?

No. Paste a CERTIFICATE REQUEST PEM block only.

What does signature verified mean?

It checks that the request's signature matches its included public key, not that a CA trusts the requester.

Why can self-signature say Not checked?

An unsupported algorithm or crypto context can prevent the check. The status does not mean a CA approved or rejected the request.

Is a CSR the same as an issued certificate?

No. A CSR is a request. The decoder does not issue a certificate or perform a CA trust decision.