Decode Certificate Signing Request (CSR)
All computation runs locally in your browser. Private keys and CSRs never leave your device, and we never collect or store them.
Decode and Verify Your CSR
Decode and verify your Certificate Signing Request (CSR). View all details including Common Name, Organization, and key information.
About Decode Certificate Signing Request (CSR)
The CSR.plus CSR Decoder is a free online tool that decodes a Certificate Signing Request in PEM or DER form and shows exactly what will be submitted to a Certificate Authority. Inspect the subject, organization, public key algorithm and size, and the requested extensions before you hand the CSR to your CA — entirely in your browser, with no upload.
Most SSL order rejections trace back to typos in the CSR: a misspelled common name, a SAN that does not match the domains you ordered, or wrong organization details. Running your CSR through this decoder before submission is the fastest way to verify a CSR and avoid reissues. It also shows the raw OpenSSL output and the Debian weak-key check for advanced validation.
Why use
- Decode and verify a CSR before submitting it to your CA
- Check the CN, SANs, organization, and key details for typos
- View raw OpenSSL data and ASN.1 structure of the request
- CSR decoding is fully local — private keys are never involved
How to use
- Paste your CSR in PEM format, or upload a .csr, .pem, or .der file.
- The decoder parses the request and displays the subject, public key, and requested extensions.
- Compare the CN and SAN list against the domains you are ordering.
- Verify every field is correct so the issued certificate matches your expectations.
Frequently asked questions
▸Does decoding a CSR reveal my private key?
No. A CSR contains only the public key; the private key is never included or uploaded.
▸Which CSR formats are supported?
PEM text and uploaded .csr, .pem, and .der files are all parsed automatically.
▸Should the subject match my domain?
The CN and SAN should list the hostnames you intend to secure; mismatches cause certificate warnings.
▸Why is my CSR rejected by the CA?
Common causes: typos in the common name, SANs that exceed your order, unsupported key types, or organization details that fail validation. Decode and check the CSR before submitting.