azureblog.co.uk
← cd ~/tools
// tools/cert

Certificate decoder

Paste a certificate as PEM or base64, paste SAML federation metadata, or load a .cer, .crt or .pem file. You'll see who it's for, who issued it, when it expires and its SHA-1 and SHA-256 thumbprints.

Runs entirely in your browser. Nothing you paste is sent anywhere.

Entra shows SAML signing certificate thumbprints as SHA-1 in upper case without colons, which is the format used here. Only public certificates belong here: never paste a private key.