CertLens

CertLens

A passive certificate sensor for Chrome. Every certificate, key and chain your browser meets, inventoried locally. Network lookups are opt-in, and each one says what it sends and to whom.

CertLens turns your browser into a passive TLS certificate sensor. Every HTTPS connection your browser makes shows it a certificate; CertLens keeps every one, and the public keys, issuers and hosts behind them, in a local inventory, and runs 43 rules over it.

The Hosts tab: every host this browser has completed a TLS handshake with, its issuer, current certificate and when it was first seen

What you get

The Overview: what needs attention, and what this browser has been trusting

Privacy in one sentence

Nothing is sent anywhere unless you turn on a network feature, and each one says exactly what it sends and to whom. No account, no analytics, no telemetry. The full privacy policy is short and worth reading.

Setup, once

Chrome 144 or later. Chrome hands certificates to extensions only when its WebRequestSecurityInfo feature is on, and it ships off by default. Two clicks, once:

  1. Open chrome://flags/#web-request-security-info (paste it into the address bar; links to chrome:// pages do not open from a web page).
  2. Set Enable SecurityInfo in WebRequest API to Enabled, then click Relaunch.

It persists across restarts. Until it is on, the inventory stays empty and CertLens says so: the dashboard opens on install with these steps, the popup repeats them, and the Capture tab reports the moment certificates arrive. On a managed browser there is no policy for this flag; launch Chrome with --enable-features=WebRequestSecurityInfo instead.

Install

CertLens on the Chrome Web Store. The listing is unlisted for now: this link reaches it, store search does not. After Add to Chrome, the dashboard opens with the setup step above.

Support

Something wrong, or a certificate CertLens misread? See support.