Security
Key & Certificate Inspector
Paste a certificate, a private key, a public key or a CSR — together or one at a time — and find out what algorithm it uses, how big it is, when it expires, and whether the key and the certificate actually belong to each other. Everything is parsed in this tab, which is the only sane place to paste a private key.
PEM input
Nothing here is uploaded. Parsing happens in this tab, which is the only reason it is safe to paste a private key. Any site that asks for one and does the work on a server has your key.
Do they match?
Worth knowing
The same thing with openssl
These are the commands behind what you just read, plus the ones worth keeping in your notes.
How the match is actually decided
- A key pair is matched on its public half. For RSA the modulus in the private key is compared against the modulus in the certificate. For an elliptic curve key it is the public point and the curve. Nothing is signed or decrypted to prove it, because the comparison is exact — two keys either share a modulus or they do not.
- Encrypted private keys cannot be read without the passphrase. If you paste
one, this page will say so rather than guess. Decrypt it first with
openssl pkey -in key.pem -out plain.pem, and delete the plaintext copy after. - A certificate proves nothing on its own. This page reads what a certificate
claims — subject, validity, extensions. It does not verify the signature chain up to a
trusted root, so a self-signed certificate claiming to be a bank looks structurally fine here.
Chain verification is
openssl verify -CAfile ca.pem cert.pem. - For mutual TLS, the extended key usage is what bites. A client certificate
needs
clientAuthin its EKU, and a server certificate needsserverAuth. A certificate with only one of them will fail in the other role, and the error message is rarely that clear.
Runs entirely in your browser — nothing you type here is uploaded, logged or stored. Privacy policy