Security

Key & Certificate Inspector

Paste a certificate, a private key, a public key or a CSR — together or one at a time — and find out what algorithm it uses, how big it is, when it expires, and whether the key and the certificate actually belong to each other. Everything is parsed in this tab, which is the only sane place to paste a private key.

PEM input

Nothing here is uploaded. Parsing happens in this tab, which is the only reason it is safe to paste a private key. Any site that asks for one and does the work on a server has your key.

How the match is actually decided

  • A key pair is matched on its public half. For RSA the modulus in the private key is compared against the modulus in the certificate. For an elliptic curve key it is the public point and the curve. Nothing is signed or decrypted to prove it, because the comparison is exact — two keys either share a modulus or they do not.
  • Encrypted private keys cannot be read without the passphrase. If you paste one, this page will say so rather than guess. Decrypt it first with openssl pkey -in key.pem -out plain.pem, and delete the plaintext copy after.
  • A certificate proves nothing on its own. This page reads what a certificate claims — subject, validity, extensions. It does not verify the signature chain up to a trusted root, so a self-signed certificate claiming to be a bank looks structurally fine here. Chain verification is openssl verify -CAfile ca.pem cert.pem.
  • For mutual TLS, the extended key usage is what bites. A client certificate needs clientAuth in its EKU, and a server certificate needs serverAuth. A certificate with only one of them will fail in the other role, and the error message is rarely that clear.

Runs entirely in your browser — nothing you type here is uploaded, logged or stored. Privacy policy