CSR Decoder — Decode Certificate Signing Requests Online Free

Inspect a PEM CSR's subject, requested SANs, public key, and signature locally in your browser.

Jump to tool ↓
Browser-side processing — tool input is not uploaded

Frequently Asked Questions

Understanding CSR (Certificate Signing Requests)

A Certificate Signing Request (CSR) is a PKCS#10-formatted message submitted to a Certificate Authority to apply for a digital certificate. It contains the applicant's public key, identification information (subject fields), and is signed with the corresponding private key to prove ownership.

Before submitting a CSR, compare its requested SANs with the domains you intend to cover. A missing name can require a corrected CSR or certificate reissue. Check organization fields when requesting an organization-validated certificate.

This decoder verifies the CSR's signature, extracts all subject fields, lists all SANs from the extension request, and shows the public key algorithm and size. The private key is never part of a CSR and cannot be extracted from it.

To check the same file at a command line, run openssl req -in request.csr -noout -text -verify. Compare both outputs with the certificate you receive from the CA. A valid CSR signature confirms possession of the matching private key when the request was created; it does not prove domain ownership.

Standards & References

Built and maintained by DevDecode. This tool processes your input in your browser; it is not uploaded for processing. Found an issue? Let us know.

Related Tools

Related Guides