> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iotools.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# X.509 Certificate Parser

> Parse a PEM-encoded X.509 certificate or certificate signing request (CSR) — subject, issuer, validity window, serial number, signature/public-key algorithms, extensions (SANs, key usage, basic constraints…), CSR signature verification, and SHA-256/SHA-1/SHA-512 fingerprints. Parsed entirely in your browser; nothing is uploaded.

[Try X.509 Certificate Parser in your browser →](https://iotools.cloud/tool/x509-certificate-parser/)



## OpenAPI

````yaml https://api.iotools.cloud/v1/openapi post /v1/tool/x509-certificate-parser
openapi: 3.1.0
info:
  title: iotools.cloud API
  version: 1.0.0
  description: >-
    Run any iotools.cloud tool over HTTP.


    Authenticate with `Authorization: Bearer iot_live_…`.


    **Only `POST /v1/tool/{slug}` costs credits.** Every GET here — the catalog,
    a tool's schema, your balance — is free. A tool call is charged its own
    weight or your plan's per-call minimum, whichever is larger;
    `x-iotools-credit-cost` on each operation is quoted at the free-tier
    minimum, and `GET /v1/tools/list` returns the exact figure for your key.
    `GET /v1/me/credits` reports what you have left, and `GET /v1/me/usage`
    reports what it went on.


    Failures are RFC 9457 problem documents — branch on `code`.
servers:
  - url: https://api.iotools.cloud
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Catalog
    description: Find a tool and read its contract. Free.
  - name: Converters
    description: >-
      Convert between formats, encodings, and units — Base64, CSV and JSON,
      timestamps, and more. Fast, free, and processed right in your browser.
  - name: Formatters
    description: >-
      Format, beautify, minify, and validate code and data — JSON, HTML, CSS,
      SQL, and regex. Clean up messy input in one click, with nothing to upload.
  - name: Generators
    description: >-
      Generate exactly what you need and on demand — passwords, UUIDs, QR codes,
      hashes, random numbers, and more. Secure, instant, and free.
  - name: Calculators
    description: >-
      Crunch the numbers fast — from everyday math to specialized conversions
      and unit work. Free online calculators that run entirely in your browser.
  - name: Editors
    description: >-
      Edit and transform text, code, and images with quick, focused editors that
      run entirely in your browser — nothing to install, and no sign-up needed.
  - name: Utilities
    description: >-
      Everyday developer and web utilities — DNS and IP lookups, redirect and
      certificate checkers, and other quick diagnostics. Free and
      privacy-friendly.
  - name: Account
    description: Your key's allowance, limits and usage history.
paths:
  /v1/tool/x509-certificate-parser:
    post:
      tags:
        - Utilities
      summary: X.509 Certificate Parser
      description: >-
        Parse a PEM-encoded X.509 certificate or certificate signing request
        (CSR) — subject, issuer, validity window, serial number,
        signature/public-key algorithms, extensions (SANs, key usage, basic
        constraints…), CSR signature verification, and SHA-256/SHA-1/SHA-512
        fingerprints. Parsed entirely in your browser; nothing is uploaded.


        [Try X.509 Certificate Parser in your browser
        →](https://iotools.cloud/tool/x509-certificate-parser/)
      operationId: run_x509_certificate_parser
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                pemInput:
                  type: string
                  description: PEM Certificate or CSR
                referenceTime:
                  type: string
                  description: Reference Time (now)
              required: []
            examples:
              isrg_root_x1_real_self_signed_rsa_4096_root_ca:
                summary: ISRG Root X1 (real self-signed RSA-4096 root CA)
                value:
                  pemInput: >-
                    -----BEGIN CERTIFICATE-----

                    MIIFazCCA1OgAwIBAgIRAIIQz7DSQONZRGPgu2OCiwAwDQYJKoZIhvcNAQELBQAw

                    TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh

                    cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMTUwNjA0MTEwNDM4

                    WhcNMzUwNjA0MTEwNDM4WjBPMQswCQYDVQQGEwJVUzEpMCcGA1UEChMgSW50ZXJu

                    ZXQgU2VjdXJpdHkgUmVzZWFyY2ggR3JvdXAxFTATBgNVBAMTDElTUkcgUm9vdCBY

                    MTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAK3oJHP0FDfzm54rVygc

                    h77ct984kIxuPOZXoHj3dcKi/vVqbvYATyjb3miGbESTtrFj/RQSa78f0uoxmyF+

                    0TM8ukj13Xnfs7j/EvEhmkvBioZxaUpmZmyPfjxwv60pIgbz5MDmgK7iS4+3mX6U

                    A5/TR5d8mUgjU+g4rk8Kb4Mu0UlXjIB0ttov0DiNewNwIRt18jA8+o+u3dpjq+sW

                    T8KOEUt+zwvo/7V3LvSye0rgTBIlDHCNAymg4VMk7BPZ7hm/ELNKjD+Jo2FR3qyH

                    B5T0Y3HsLuJvW5iB4YlcNHlsdu87kGJ55tukmi8mxdAQ4Q7e2RCOFvu396j3x+UC

                    B5iPNgiV5+I3lg02dZ77DnKxHZu8A/lJBdiB3QW0KtZB6awBdpUKD9jf1b0SHzUv

                    KBds0pjBqAlkd25HN7rOrFleaJ1/ctaJxQZBKT5ZPt0m9STJEadao0xAH0ahmbWn

                    OlFuhjuefXKnEgV4We0+UXgVCwOPjdAvBbI+e0ocS3MFEvzG6uBQE3xDk3SzynTn

                    jh8BCNAw1FtxNrQHusEwMFxIt4I7mKZ9YIqioymCzLq9gwQbooMDQaHWBfEbwrbw

                    qHyGO0aoSCqI3Haadr8faqU9GY/rOPNk3sgrDQoo//fb4hVC1CLQJ13hef4Y53CI

                    rU7m2Ys6xt0nUW7/vGT1M0NPAgMBAAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNV

                    HRMBAf8EBTADAQH/MB0GA1UdDgQWBBR5tFnme7bl5AFzgAiIyBpY9umbbjANBgkq

                    hkiG9w0BAQsFAAOCAgEAVR9YqbyyqFDQDLHYGmkgJykIrGF1XIpu+ILlaS/V9lZL

                    ubhzEFnTIZd+50xx+7LSYK05qAvqFyFWhfFQDlnrzuBZ6brJFe+GnY+EgPbk6ZGQ

                    3BebYhtF8GaV0nxvwuo77x/Py9auJ/GpsMiu/X1+mvoiBOv/2X/qkSsisRcOj/KK

                    NFtY2PwByVS5uCbMiogziUwthDyC3+6WVwW6LLv3xLfHTjuCvjHIInNzktHCgKQ5

                    ORAzI4JMPJ+GslWYHb4phowim57iaztXOoJwTdwJx4nLCgdNbOhdjsnvzqvHu7Ur

                    TkXWStAmzOVyyghqpZXjFaH3pO3JLF+l+/+sKAIuvtd7u+Nxe5AW0wdeRlN8NwdC

                    jNPElpzVmbUq4JUagEiuTDkHzsxHpFKVK7q4+63SM1N95R1NbdWhscdCb+ZAJzVc

                    oyi3B43njTOQ5yOf+1CceWxG1bQVs5ZufpsMljq4Ui0/1lvh+wjChP4kqKOJ2qxq

                    4RgqsahDYVvTH9w7jXbyLeiNdd8XM2w9U/t7y0Ff/9yi0GE44Za4rF2LN9d11TPA

                    mRGunUHBcnWEvgJBQl9nJEiU0Zsnvgc/ubhPgXRR4Xq37Z0j4r7g1SgEEzwxA57d

                    emyPxgcYxn/eR44/KJ4EBs+lVDR3veyJm+kXQ99b21/+jh5Xos1AnX5iItreGCc=

                    -----END CERTIFICATE-----
                  referenceTime: '2024-01-01T00:00:00Z'
              same_certificate_evaluated_after_its_2035_expiry:
                summary: Same certificate, evaluated after its 2035 expiry
                value:
                  pemInput: >-
                    -----BEGIN CERTIFICATE-----

                    MIIFazCCA1OgAwIBAgIRAIIQz7DSQONZRGPgu2OCiwAwDQYJKoZIhvcNAQELBQAw

                    TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh

                    cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMTUwNjA0MTEwNDM4

                    WhcNMzUwNjA0MTEwNDM4WjBPMQswCQYDVQQGEwJVUzEpMCcGA1UEChMgSW50ZXJu

                    ZXQgU2VjdXJpdHkgUmVzZWFyY2ggR3JvdXAxFTATBgNVBAMTDElTUkcgUm9vdCBY

                    MTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAK3oJHP0FDfzm54rVygc

                    h77ct984kIxuPOZXoHj3dcKi/vVqbvYATyjb3miGbESTtrFj/RQSa78f0uoxmyF+

                    0TM8ukj13Xnfs7j/EvEhmkvBioZxaUpmZmyPfjxwv60pIgbz5MDmgK7iS4+3mX6U

                    A5/TR5d8mUgjU+g4rk8Kb4Mu0UlXjIB0ttov0DiNewNwIRt18jA8+o+u3dpjq+sW

                    T8KOEUt+zwvo/7V3LvSye0rgTBIlDHCNAymg4VMk7BPZ7hm/ELNKjD+Jo2FR3qyH

                    B5T0Y3HsLuJvW5iB4YlcNHlsdu87kGJ55tukmi8mxdAQ4Q7e2RCOFvu396j3x+UC

                    B5iPNgiV5+I3lg02dZ77DnKxHZu8A/lJBdiB3QW0KtZB6awBdpUKD9jf1b0SHzUv

                    KBds0pjBqAlkd25HN7rOrFleaJ1/ctaJxQZBKT5ZPt0m9STJEadao0xAH0ahmbWn

                    OlFuhjuefXKnEgV4We0+UXgVCwOPjdAvBbI+e0ocS3MFEvzG6uBQE3xDk3SzynTn

                    jh8BCNAw1FtxNrQHusEwMFxIt4I7mKZ9YIqioymCzLq9gwQbooMDQaHWBfEbwrbw

                    qHyGO0aoSCqI3Haadr8faqU9GY/rOPNk3sgrDQoo//fb4hVC1CLQJ13hef4Y53CI

                    rU7m2Ys6xt0nUW7/vGT1M0NPAgMBAAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNV

                    HRMBAf8EBTADAQH/MB0GA1UdDgQWBBR5tFnme7bl5AFzgAiIyBpY9umbbjANBgkq

                    hkiG9w0BAQsFAAOCAgEAVR9YqbyyqFDQDLHYGmkgJykIrGF1XIpu+ILlaS/V9lZL

                    ubhzEFnTIZd+50xx+7LSYK05qAvqFyFWhfFQDlnrzuBZ6brJFe+GnY+EgPbk6ZGQ

                    3BebYhtF8GaV0nxvwuo77x/Py9auJ/GpsMiu/X1+mvoiBOv/2X/qkSsisRcOj/KK

                    NFtY2PwByVS5uCbMiogziUwthDyC3+6WVwW6LLv3xLfHTjuCvjHIInNzktHCgKQ5

                    ORAzI4JMPJ+GslWYHb4phowim57iaztXOoJwTdwJx4nLCgdNbOhdjsnvzqvHu7Ur

                    TkXWStAmzOVyyghqpZXjFaH3pO3JLF+l+/+sKAIuvtd7u+Nxe5AW0wdeRlN8NwdC

                    jNPElpzVmbUq4JUagEiuTDkHzsxHpFKVK7q4+63SM1N95R1NbdWhscdCb+ZAJzVc

                    oyi3B43njTOQ5yOf+1CceWxG1bQVs5ZufpsMljq4Ui0/1lvh+wjChP4kqKOJ2qxq

                    4RgqsahDYVvTH9w7jXbyLeiNdd8XM2w9U/t7y0Ff/9yi0GE44Za4rF2LN9d11TPA

                    mRGunUHBcnWEvgJBQl9nJEiU0Zsnvgc/ubhPgXRR4Xq37Z0j4r7g1SgEEzwxA57d

                    emyPxgcYxn/eR44/KJ4EBs+lVDR3veyJm+kXQ99b21/+jh5Xos1AnX5iItreGCc=

                    -----END CERTIFICATE-----
                  referenceTime: '2036-01-01T00:00:00Z'
              certificate_signing_request_csr_with_a_san_extension:
                summary: Certificate Signing Request (CSR) with a SAN extension
                value:
                  pemInput: >-
                    -----BEGIN CERTIFICATE REQUEST-----

                    MIICuTCCAaECAQAwOjEUMBIGA1UEAxMLZXhhbXBsZS5jb20xFTATBgNVBAoTDEV4

                    YW1wbGUgSW5jLjELMAkGA1UEBhMCVVMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw

                    ggEKAoIBAQDFJU/zCxn6eL/66gQcU+uWSm51NnZoV/YEs8hqfTfEKgUWNtrCjpx9

                    Ft6RrE4nugoMAQkHALgBDWG82V8M7VScYiVhAF8P1/yP9vPfjuXhM5ZJ4Mf10nuL

                    QO367wBzO9NBZD4QCAjvxd6Xnn0AvCpKMTOyOfTkDgUy/GHa14KpYxGOGg9ewsyx

                    9uEAPvkl8npfhskcHn5sfD2E/VUAIvlumo1rtCzURboiaptIj0JysfNovAxC4I0a

                    o6ZH+BrgbBHKTbjsTmIWHhdCLdzoKzpkJMrYtSVW/CZJEtQQXePF8+xJaiRNqRtj

                    hA11nSbR9UjLzMaAH0VhKz2Biv8kNrE1AgMBAAGgOjA4BgkqhkiG9w0BCQ4xKzAp

                    MCcGA1UdEQQgMB6CC2V4YW1wbGUuY29tgg93d3cuZXhhbXBsZS5jb20wDQYJKoZI

                    hvcNAQELBQADggEBAIawtWiMBC6GDQ0zmSslvf2UfxhPoWzauaO5V5EwA10UmisT

                    TZKVuDA01nhQqnlSFdG6YugPYv9yJn/JXBeAP3o9Cviw3DTO6ISJgX4Vh1B7dzkp

                    ADWjWiGUM00P59aogAY3byFEA8LA259bB1VIWQ6m8RK99zZCY4EJI6WHAL6S/AYT

                    lj2JsiaPvYY3GAX4Iex+tI/cBW1LLn+z+TGY3V38OhVew7lQu1YrsmDA0Nu0vJo3

                    1Hyu6hZIAxD6oNufBu7AHtInv23X6tSKl5BW6a2ZvRfVagXfa0M7/d0PKzug8taA

                    WE5tGZiJ3F9y9eMgewMtfb3NJ3A98cJ1pA2ILhY=

                    -----END CERTIFICATE REQUEST-----
                  referenceTime: ''
      responses:
        '200':
          description: Tool output
          content:
            application/json:
              examples:
                isrg_root_x1_real_self_signed_rsa_4096_root_ca:
                  summary: ISRG Root X1 (real self-signed RSA-4096 root CA)
                  value:
                    tool: x509-certificate-parser
                    tool_version: 1.0.1
                    outputs:
                      warnings:
                        - severity: Warning
                          message: >-
                            This is a self-signed certificate (Subject =
                            Issuer).
                      type:
                        - property: Type
                          value: X.509 Certificate
                      subject:
                        - field: Country (C)
                          value: US
                        - field: Organization (O)
                          value: Internet Security Research Group
                        - field: Common Name (CN)
                          value: ISRG Root X1
                      issuer:
                        - field: Country (C)
                          value: US
                        - field: Organization (O)
                          value: Internet Security Research Group
                        - field: Common Name (CN)
                          value: ISRG Root X1
                      validity:
                        - field: Not Before
                          value: '2015-06-04T11:04:38Z'
                        - field: Not After
                          value: '2035-06-04T11:04:38Z'
                        - field: Status
                          value: Valid (expires in 4172d 11h)
                      details:
                        - property: Version
                          value: v3
                        - property: Serial Number
                          value: 00:82:10:CF:B0:D2:40:E3:59:44:63:E0:BB:63:82:8B:00
                        - property: Signature Algorithm
                          value: SHA-256 with RSA
                        - property: Public Key Algorithm
                          value: RSA
                        - property: Public Key Size
                          value: 4096 bits
                        - property: Public Key Exponent
                          value: '65537'
                        - property: Self-Signed
                          value: 'Yes'
                      extensions:
                        - extension: Key Usage (critical)
                          value: Certificate Sign, CRL Sign
                        - extension: Basic Constraints (critical)
                          value: 'CA: TRUE'
                        - extension: Subject Key Identifier
                          value: >-
                            79:B4:59:E6:7B:B6:E5:E4:01:73:80:08:88:C8:1A:58:F6:E9:9B:6E
                      fingerprints:
                        - algorithm: SHA-256
                          fingerprint: >-
                            96:BC:EC:06:26:49:76:F3:74:60:77:9A:CF:28:C5:A7:CF:E8:A3:C0:AA:E1:1A:8F:FC:EE:05:C0:BD:DF:08:C6
                        - algorithm: SHA-1
                          fingerprint: >-
                            CA:BD:2A:79:A1:07:6A:31:F2:1D:25:36:35:CB:03:9D:43:29:A5:E8
                        - algorithm: SHA-512
                          fingerprint: >-
                            3B:40:F2:7E:82:83:23:F5:B9:1F:89:09:88:3A:78:A2:1C:86:55:17:61:F2:7B:38:02:9F:AA:EC:14:AF:5B:7A:A9:6F:B9:F9:CC:93:EE:20:1B:5E:B1:D0:FE:F1:7B:29:07:47:E8:B8:39:D2:E4:9A:8F:36:C5:EB:F3:C7:C9:10
                    credits_used: 3
                    credits_remaining: null
                same_certificate_evaluated_after_its_2035_expiry:
                  summary: Same certificate, evaluated after its 2035 expiry
                  value:
                    tool: x509-certificate-parser
                    tool_version: 1.0.1
                    outputs:
                      warnings:
                        - severity: Danger
                          message: >-
                            Certificate has expired — expired 210d 12h ago (at
                            2035-06-04T11:04:38Z).
                        - severity: Warning
                          message: >-
                            This is a self-signed certificate (Subject =
                            Issuer).
                      type:
                        - property: Type
                          value: X.509 Certificate
                      subject:
                        - field: Country (C)
                          value: US
                        - field: Organization (O)
                          value: Internet Security Research Group
                        - field: Common Name (CN)
                          value: ISRG Root X1
                      issuer:
                        - field: Country (C)
                          value: US
                        - field: Organization (O)
                          value: Internet Security Research Group
                        - field: Common Name (CN)
                          value: ISRG Root X1
                      validity:
                        - field: Not Before
                          value: '2015-06-04T11:04:38Z'
                        - field: Not After
                          value: '2035-06-04T11:04:38Z'
                        - field: Status
                          value: Expired (210d 12h ago)
                      details:
                        - property: Version
                          value: v3
                        - property: Serial Number
                          value: 00:82:10:CF:B0:D2:40:E3:59:44:63:E0:BB:63:82:8B:00
                        - property: Signature Algorithm
                          value: SHA-256 with RSA
                        - property: Public Key Algorithm
                          value: RSA
                        - property: Public Key Size
                          value: 4096 bits
                        - property: Public Key Exponent
                          value: '65537'
                        - property: Self-Signed
                          value: 'Yes'
                      extensions:
                        - extension: Key Usage (critical)
                          value: Certificate Sign, CRL Sign
                        - extension: Basic Constraints (critical)
                          value: 'CA: TRUE'
                        - extension: Subject Key Identifier
                          value: >-
                            79:B4:59:E6:7B:B6:E5:E4:01:73:80:08:88:C8:1A:58:F6:E9:9B:6E
                      fingerprints:
                        - algorithm: SHA-256
                          fingerprint: >-
                            96:BC:EC:06:26:49:76:F3:74:60:77:9A:CF:28:C5:A7:CF:E8:A3:C0:AA:E1:1A:8F:FC:EE:05:C0:BD:DF:08:C6
                        - algorithm: SHA-1
                          fingerprint: >-
                            CA:BD:2A:79:A1:07:6A:31:F2:1D:25:36:35:CB:03:9D:43:29:A5:E8
                        - algorithm: SHA-512
                          fingerprint: >-
                            3B:40:F2:7E:82:83:23:F5:B9:1F:89:09:88:3A:78:A2:1C:86:55:17:61:F2:7B:38:02:9F:AA:EC:14:AF:5B:7A:A9:6F:B9:F9:CC:93:EE:20:1B:5E:B1:D0:FE:F1:7B:29:07:47:E8:B8:39:D2:E4:9A:8F:36:C5:EB:F3:C7:C9:10
                    credits_used: 3
                    credits_remaining: null
                certificate_signing_request_csr_with_a_san_extension:
                  summary: Certificate Signing Request (CSR) with a SAN extension
                  value:
                    tool: x509-certificate-parser
                    tool_version: 1.0.1
                    outputs:
                      warnings: []
                      type:
                        - property: Type
                          value: Certificate Signing Request (CSR)
                        - property: Signature Valid
                          value: 'Yes'
                      subject:
                        - field: Common Name (CN)
                          value: example.com
                        - field: Organization (O)
                          value: Example Inc.
                        - field: Country (C)
                          value: US
                      issuer:
                        - field: Note
                          value: Not applicable for a CSR
                      validity:
                        - field: Note
                          value: Not applicable for a CSR
                      details:
                        - property: Version
                          value: v1
                        - property: Signature Algorithm
                          value: SHA-256 with RSA
                        - property: Public Key Algorithm
                          value: RSA
                        - property: Public Key Size
                          value: 2048 bits
                        - property: Public Key Exponent
                          value: '65537'
                      extensions:
                        - extension: Subject Alternative Name (SAN)
                          value: 'DNS: example.com, DNS: www.example.com'
                      fingerprints:
                        - algorithm: SHA-256
                          fingerprint: >-
                            38:47:4A:B0:7E:30:B9:00:0B:A4:E9:32:73:EE:B5:99:7A:0F:0A:24:70:79:B0:2E:97:F7:28:AA:33:95:CC:96
                        - algorithm: SHA-1
                          fingerprint: >-
                            EE:8C:0E:BE:FA:93:AD:80:86:C2:23:4E:B5:6C:5A:98:83:10:34:5A
                        - algorithm: SHA-512
                          fingerprint: >-
                            5D:66:50:E4:C8:56:96:60:33:E0:1A:BC:72:BA:45:68:70:90:20:6B:C1:2F:87:F3:F8:4B:54:2F:DC:EF:36:80:7A:CD:9E:8E:7F:2F:22:9A:99:35:49:90:45:77:BF:22:CC:B1:CD:42:68:94:26:20:C2:FE:7C:8D:14:4E:CB:D3
                    credits_used: 3
                    credits_remaining: null
              schema:
                type: object
                required:
                  - tool
                  - tool_version
                  - outputs
                  - credits_used
                  - credits_remaining
                properties:
                  outputs:
                    type: object
                    properties:
                      warnings:
                        type: array
                        items:
                          type: object
                          properties:
                            severity:
                              type: string
                              description: Severity
                            message:
                              type: string
                              description: Message
                        x-iotools-columns:
                          - severity
                          - message
                      type:
                        type: array
                        items:
                          type: object
                          properties:
                            property:
                              type: string
                              description: Property
                            value:
                              type: string
                              description: Value
                        x-iotools-columns:
                          - property
                          - value
                      subject:
                        type: array
                        items:
                          type: object
                          properties:
                            field:
                              type: string
                              description: Field
                            value:
                              type: string
                              description: Value
                        x-iotools-columns:
                          - field
                          - value
                      issuer:
                        type: array
                        items:
                          type: object
                          properties:
                            field:
                              type: string
                              description: Field
                            value:
                              type: string
                              description: Value
                        x-iotools-columns:
                          - field
                          - value
                      validity:
                        type: array
                        items:
                          type: object
                          properties:
                            field:
                              type: string
                              description: Field
                            value:
                              type: string
                              description: Value
                        x-iotools-columns:
                          - field
                          - value
                      details:
                        type: array
                        items:
                          type: object
                          properties:
                            property:
                              type: string
                              description: Property
                            value:
                              type: string
                              description: Value
                        x-iotools-columns:
                          - property
                          - value
                      extensions:
                        type: array
                        items:
                          type: object
                          properties:
                            extension:
                              type: string
                              description: Extension
                            value:
                              type: string
                              description: Value
                        x-iotools-columns:
                          - extension
                          - value
                      fingerprints:
                        type: array
                        items:
                          type: object
                          properties:
                            algorithm:
                              type: string
                              description: Algorithm
                            fingerprint:
                              type: string
                              description: Fingerprint
                        x-iotools-columns:
                          - algorithm
                          - fingerprint
                  tool:
                    type: string
                    description: The tool's slug, echoing the {slug} in the request path.
                  tool_version:
                    type: string
                    description: Output-contract version for this tool.
                  credits_used:
                    type: integer
                    description: >-
                      Credits this call consumed, after any settlement refund. 0
                      when metering is disabled.
                  credits_remaining:
                    type:
                      - integer
                      - 'null'
                    description: >-
                      Credits left in the current monthly allowance, or null
                      when metering is disabled.
                  request_id:
                    type: string
                    description: Correlation id, also sent as x-request-id.
        '400':
          $ref: '#/components/responses/ValidationError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '402':
          $ref: '#/components/responses/InsufficientCredits'
        '403':
          $ref: '#/components/responses/ToolNotAllowed'
        '404':
          $ref: '#/components/responses/ToolNotFound'
        '413':
          $ref: '#/components/responses/PayloadTooLarge'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/ToolFailed'
        '503':
          $ref: '#/components/responses/ToolDisabled'
      security:
        - bearerAuth: []
components:
  responses:
    ValidationError:
      description: Invalid request.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/validation_error
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Invalid request
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - validation_error
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
              fields:
                type:
                  - object
                  - string
                additionalProperties:
                  type: string
                description: >-
                  What failed: a map of field name → message. Absent when the
                  body itself is malformed; a single string when the failure
                  isn't tied to one field.
          example:
            type: https://iotools.cloud/docs/errors/validation_error
            title: Invalid request
            status: 400
            code: validation_error
            detail: One or more inputs are invalid — see `fields`.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
            fields:
              inputString: Required
    Unauthorized:
      description: Missing or invalid API key.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/invalid_api_key
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Invalid API key
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - invalid_api_key
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
          example:
            type: https://iotools.cloud/docs/errors/invalid_api_key
            title: Invalid API key
            status: 401
            code: invalid_api_key
            detail: 'Provide ''Authorization: Bearer <key>''.'
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
    InsufficientCredits:
      description: Monthly credit allowance exhausted.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/insufficient_credits
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Insufficient credits
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - insufficient_credits
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
              credits_used:
                type: integer
                description: Always 0 — a refused call charges nothing.
              credits_remaining:
                type: integer
                description: Credits left in the allowance — fewer than this call costs.
          example:
            type: https://iotools.cloud/docs/errors/insufficient_credits
            title: Insufficient credits
            status: 402
            code: insufficient_credits
            detail: This call costs 1 credit and 0 remain in this month's allowance.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
            credits_used: 0
            credits_remaining: 0
    ToolNotAllowed:
      description: Tool exists but has no API surface.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/tool_not_allowed
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Tool not available over the API
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - tool_not_allowed
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
          example:
            type: https://iotools.cloud/docs/errors/tool_not_allowed
            title: Tool not available over the API
            status: 403
            code: tool_not_allowed
            detail: >-
              "Background Remover" is available on iotools.cloud but has no API
              endpoint.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
    ToolNotFound:
      description: No such tool.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/tool_not_found
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Tool not found
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - tool_not_found
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
          example:
            type: https://iotools.cloud/docs/errors/tool_not_found
            title: Tool not found
            status: 404
            code: tool_not_found
            detail: No tool with that slug. See GET /v1/tools/list.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
    PayloadTooLarge:
      description: Body too large.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/payload_too_large
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Payload too large
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - payload_too_large
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
          example:
            type: https://iotools.cloud/docs/errors/payload_too_large
            title: Payload too large
            status: 413
            code: payload_too_large
            detail: Request body exceeds this tool's size limit.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
    RateLimited:
      description: Per-minute rate limit exceeded.
      headers:
        Retry-After:
          description: Seconds to wait before retrying (RFC 9110 delta-seconds).
          schema:
            type: integer
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/rate_limited
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Rate limit exceeded
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - rate_limited
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
              retry_after:
                type: integer
                description: >-
                  Seconds until the window resets — the same value as the
                  `Retry-After` header.
          example:
            type: https://iotools.cloud/docs/errors/rate_limited
            title: Rate limit exceeded
            status: 429
            code: rate_limited
            detail: Too many requests. Retry in 30s.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
            retry_after: 30
    ToolFailed:
      description: Tool failed to run.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/processing_error
                  - https://iotools.cloud/docs/errors/internal_error
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Tool failed to run
                  - Internal error
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - processing_error
                  - internal_error
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
              credits_used:
                type: integer
                description: >-
                  Always 0 on `processing_error` — a failed run is refunded,
                  floor included.
              credits_remaining:
                type: integer
                description: >-
                  Credits left after the refund. Absent when metering is
                  disabled.
          example:
            type: https://iotools.cloud/docs/errors/processing_error
            title: Tool failed to run
            status: 500
            code: processing_error
            detail: The tool failed to run. Please try again.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
            credits_used: 0
    ToolDisabled:
      description: Tool temporarily disabled.
      content:
        application/problem+json:
          schema:
            type: object
            description: >-
              RFC 9457 problem document, served as application/problem+json.
              Branch on `code`; `title` is human prose and may be reworded
              without notice. Some failures add extension members — `fields` on
              validation errors, `retry_after` on 429s,
              `credits_used`/`credits_remaining` on billing-adjacent failures —
              documented on the responses that carry them.
            required:
              - type
              - title
              - status
              - code
            properties:
              type:
                type: string
                format: uri
                description: Stable documentation URI for this failure.
                examples:
                  - https://iotools.cloud/docs/errors/tool_disabled
                  - https://iotools.cloud/docs/errors/api_unconfigured
              title:
                type: string
                description: Short human-readable summary of the failure.
                examples:
                  - Tool temporarily disabled
                  - API not configured
              status:
                type: integer
                description: HTTP status code, matching the response's own status.
              code:
                type: string
                description: >-
                  Stable machine-readable error code — branch on this, not
                  `title`.
                enum:
                  - tool_disabled
                  - api_unconfigured
              detail:
                type: string
                description: Human explanation of this occurrence.
              request_id:
                type: string
                description: Correlation id, also sent as x-request-id.
          example:
            type: https://iotools.cloud/docs/errors/tool_disabled
            title: Tool temporarily disabled
            status: 503
            code: tool_disabled
            detail: This tool is temporarily unavailable. Try again shortly.
            request_id: e4042b29-8f1e-4c7a-9b52-6f0d1a3c7e11
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: iot_live_…

````