VS Code extension

CertView: X.509 Certificate Inspector for VS Code

Answer who issued a certificate, when it expires, which names it covers, and how its local structure is assembled without leaving the editor.

Open source and maintained by Juan Torchia.

Current release
v0.5.0
Compatibility
VS Code 1.85+
License
MIT
VS Code Marketplace
210 installs
Observed 2026-09-29; totals change over time.

A focused tool for a specific workflow

Inspect certificates, chains, CSRs, CRLs, PKCS#7, PKCS#12, keys, and JWK files locally in VS Code without telemetry or uploads.

  • Certificate identity, validity, fingerprints, key metadata, extensions, chains, CSRs, CRLs, and advisory lint findings
  • Local PKCS#7 and PKCS#12 inspection plus public, private, encrypted-key metadata, and JWK views where supported
  • A bounded workspace explorer with configurable file limits, exclusions, and automatic refresh

From install to a safer decision

  1. Install CertView and open a supported certificate-like file; key and JWK files can be opened through Open With or the CertView command.
  2. Review identity, validity, fingerprints, extensions, key information, chain tabs, and advisory findings in the custom editor.
  3. For protected PKCS#12/PFX inputs, provide the password only in the local editor prompt.
  4. Use a dedicated PKI validation process when trust, revocation, WebPKI, or organizational policy decisions are required.

How the pieces fit together

This is a textual architecture map grounded in the public implementation. Follow the source link to inspect the exact modules, tests, and release history.

  1. VS Code file associations, commands, and the Certificates explorer route supported local files into the extension.

  2. Bounded readers detect the format and parse certificate, keystore, CSR, CRL, PKCS#7, or key material in the extension host.

  3. A normalized local model supplies the custom webview and Problems diagnostics with certificate fields, fingerprints, extensions, chain structure, and advisory findings.

Inspect the implementation on GitHub

Supported scope

  • PEM, DER, CRT, and CER
  • CSR and CRL
  • PKCS#7 / P7B / P7C / P7
  • PKCS#12 / PFX
  • KEY, PUB, and JWK

Explicit boundaries

  • The extension works offline, includes no telemetry, and does not send certificate, key, password, or PKI material outside the machine.
  • Files larger than 5 MiB are rejected before parsing. Encrypted private keys are detected but are not decrypted or password-prompted.
  • Lint and chain-structure findings do not establish trust, revocation status, WebPKI compliance, RFC 5280 path validation, FIPS compliance, or organizational approval.
  • Never attach private keys, production certificates, customer material, tokens, or passwords to a public issue.
Read the security policy

Get help, verify changes, or contribute

Issues and release history stay with the source repository so the evidence remains public.