Skip to content
UniKit

PEM decoder

Parse PEM certificates and keys (RFC 7468): see the type, base64 length and DER hex, plus a built-in ASN.1 reader for PKCS#8, SPKI, PKCS#1, SEC1 and X.509 — with algorithm OIDs and names, key size, curve, certificate subject, issuer and validity.

Runs in your browserEvery computation happens in your browser — your data never leaves this device.

ASN.1 structure

Every node shows its type, value and offset in the DER; OIDs come with their name.

Paste PEM content to decode it

What this tool does

  • Verify a certificate before deploying: paste the PEM and see the subject, issuer, validity window, serial number, version and signature algorithm — faster than running openssl on the server.
  • Check whether a key and certificate belong together: parse both and compare the algorithm, key size and curve (for example a 256-bit EC key on prime256v1) before going live.
  • Inspect the actual DER bytes: the tool shows the DER hex and a collapsible ASN.1 tree where every node reports its type, value and offset, which is handy when debugging a parser.
  • Process several blocks at once: pasting multiple -----BEGIN … ----- blocks decodes each one, so you can review both the server and intermediate certificate of a chain.

Example

Input

-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEFDA5jGyRsN7hOghOeQ6pXoHZ1GKZ
RRyqy6Vfdh+KCqldxloEX/RmMGUioEWrSwMyJBGy5Ch8vgrZ9dgB4QM49A==
-----END PUBLIC KEY-----

Output

Type: SPKI public key
Base64 length: 124
DER bytes: 91
Algorithm: id-ecPublicKey (EC)
Key size: 256 bits
Curve: prime256v1 (P-256)
DER: 30 59 30 13 06 07 2A 86 48 CE 3D 02 01 06 08 2A 86 48 CE 3D 03 01 07 03 42 00 04 …

The 91 DER bytes are what the 124 base64 characters decode to once padding is removed. Parsing only reads the outer ASN.1 structure; certificate chains and key usability are not checked.

Frequently asked questions

Does it verify that a certificate is trusted?

No. It only parses the structure — algorithm OIDs, key size, curve, subject and validity — with no signature verification, chain building or revocation checking. Use openssl verify or a browser when trust is what you need to establish.

What can I see in an encrypted private key (EncryptedPrivateKeyInfo or a DEK-Info header)?

Only the PEM headers, the ciphertext length and the structure type, because the payload is encrypted and cannot be read without the passphrase. The tool labels it an encrypted PEM and makes no attempt to crack the passphrase.

Does the order of pasted PEM blocks matter?

Blocks are parsed in the order they appear and numbered accordingly. When reviewing a chain, paste the server certificate before the intermediates so it is easy to see who signed whom. Every BEGIN must have a matching END; a label mismatch fails the whole input.

Do line breaks and indentation break the parsing?

No, whitespace and newlines inside the base64 body are ignored, so indented content copied from a shell session or a config file still parses. A wrong label, a missing END line or an invalid base64 length raise "not valid PEM".

Is the certificate or key content safe here?

Nothing is uploaded. All parsing, including the built-in ASN.1 reader, happens in the browser with no network requests. Private keys are still sensitive, so work on a trusted device and clear the input afterwards.

Keywords:pemcertificatex509pkcs8spkiasn1derbase64PEM 解析证书私钥公钥密钥长度

Related tools