Search 100+ free tools… (e.g. json, vpn, password) ⌘K
Link Tools Dereferer Hide Referrer Link URL Shortener Affiliate Cloaker PayPal Links PayPal DonationPayPal Links Privacy Tools Password Generator Cloudflare Resolver My Referrer Torrent Tools Magnet → Torrent Torrent → Magnet Torrent Editor Pirate Bay Proxies Movierulz Proxies ExtraTorrent Proxies Dev Tools Base64 Encoder Hash Generator HTTP Headers Disposable Email Checker Company Blog About Us Contact Anonymize Free
SSL Tool

CSR Decoder

Paste any Certificate Signing Request to decode and inspect all fields — domain, organisation, key algorithm, key size, SANs and a security analysis.

📋 Paste Your CSR

Frequently Asked Questions

How do I read a CSR file?
A raw CSR file appears as Base64-encoded text between BEGIN CERTIFICATE REQUEST and END CERTIFICATE REQUEST headers — it is not human-readable in that form. Paste it into the CSR Decoder and it will extract and display all the contained fields in plain text.
What information is stored in a CSR?
A CSR contains the domain name (Common Name), organisation name and details, country and state, the public key to be included in the certificate, and any Subject Alternative Names for multi-domain certificates. It does not contain the private key.
Why should I check my CSR before submitting it?
Verifying your CSR before submission prevents costly delays. If the common name is misspelled, the organisation details are incorrect, or the key size does not meet the CA's requirements, you will need to regenerate the CSR — decoding first catches these errors immediately.
What is the difference between CSR Decoder and Check CSR?
Both decode CSR fields. CSR Decoder provides a more detailed security analysis including key strength assessment and SAN validation. Check CSR is a quick validity check. Use the decoder when auditing a CSR before submitting to a CA.
What key size should I use?
2048-bit RSA is the current minimum standard. 4096-bit provides stronger security at the cost of slightly slower handshakes. EC (Elliptic Curve) keys at 256-bit offer equivalent security to 3072-bit RSA with better performance.
Why are SAN entries important?
Modern browsers require Subject Alternative Names. A certificate with only a CN and no SAN entries will cause certificate errors in Chrome, Firefox and Edge even if the CN matches. Always include at least one SAN entry matching your domain.
🛡️
Your IP address and DNS queries are visible to your ISP. Protect your privacy with a trusted VPN — tested and recommended by Anonymiz.
See Recommended VPNs →

Why decode a CSR before submitting it

A certificate authority issues exactly what your request asks for. If a domain is missing or misspelled, or the key is too weak, you only find out after the certificate is issued, and fixing it means a new request and another wait. Decoding the CSR first shows you exactly what is inside.

What to verify

Is it safe to paste a CSR?

Yes. A CSR contains only public information: your public key and the details that will appear in the certificate. It is designed to be shared. Never paste a private key into any website. A CSR starts with -----BEGIN CERTIFICATE REQUEST-----; a private key starts with -----BEGIN PRIVATE KEY----- or -----BEGIN RSA PRIVATE KEY-----.

On the command line

You can decode the same file locally with openssl req -in request.csr -noout -text. Need a new request? Use the CSR generator.

Related articles

Related Tools

🔒
SSL Certificate Check
Check SSL certificate validity
📜
CSR Generator
Generate a CSR online
🔄
SSL Converter
Convert SSL certificate formats
🗝️
Certificate Key Match
Check SSL cert matches private key
🔏
Hash Generator
Generate MD5, SHA-256 hashes
📋
JSON Formatter
Format and validate JSON
Done!