CertView: X.509 Certificate Inspector for VS Code
Answer who issued a certificate, when it expires, which names it covers, and how its local structure is assembled without leaving the editor.
Open source and maintained by Juan Torchia.
- Current release
- v0.5.0
- Compatibility
- VS Code 1.85+
- License
- MIT
- VS Code Marketplace
- 210 installs Observed 2026-09-29; totals change over time.
A focused tool for a specific workflow
Inspect certificates, chains, CSRs, CRLs, PKCS#7, PKCS#12, keys, and JWK files locally in VS Code without telemetry or uploads.
- Certificate identity, validity, fingerprints, key metadata, extensions, chains, CSRs, CRLs, and advisory lint findings
- Local PKCS#7 and PKCS#12 inspection plus public, private, encrypted-key metadata, and JWK views where supported
- A bounded workspace explorer with configurable file limits, exclusions, and automatic refresh
From install to a safer decision
- Install CertView and open a supported certificate-like file; key and JWK files can be opened through Open With or the CertView command.
- Review identity, validity, fingerprints, extensions, key information, chain tabs, and advisory findings in the custom editor.
- For protected PKCS#12/PFX inputs, provide the password only in the local editor prompt.
- Use a dedicated PKI validation process when trust, revocation, WebPKI, or organizational policy decisions are required.
How the pieces fit together
This is a textual architecture map grounded in the public implementation. Follow the source link to inspect the exact modules, tests, and release history.
VS Code file associations, commands, and the Certificates explorer route supported local files into the extension.
Bounded readers detect the format and parse certificate, keystore, CSR, CRL, PKCS#7, or key material in the extension host.
A normalized local model supplies the custom webview and Problems diagnostics with certificate fields, fingerprints, extensions, chain structure, and advisory findings.
Supported scope
- PEM, DER, CRT, and CER
- CSR and CRL
- PKCS#7 / P7B / P7C / P7
- PKCS#12 / PFX
- KEY, PUB, and JWK
Explicit boundaries
- The extension works offline, includes no telemetry, and does not send certificate, key, password, or PKI material outside the machine.
- Files larger than 5 MiB are rejected before parsing. Encrypted private keys are detected but are not decrypted or password-prompted.
- Lint and chain-structure findings do not establish trust, revocation status, WebPKI compliance, RFC 5280 path validation, FIPS compliance, or organizational approval.
- Never attach private keys, production certificates, customer material, tokens, or passwords to a public issue.
Get help, verify changes, or contribute
Issues and release history stay with the source repository so the evidence remains public.