Parse PEM

Parse PEM labels and decode the enclosed DER object.

freeworks offlinenothing uploaded
ToolPEM Parser
Input
Output
Put this on your own site

The frame below runs the same code as this page, in the reader's own browser. Nothing is sent to us, and nothing is sent to you.

Pick a dark background and the text and panels follow it, so the frame stays readable on a dark page.

Preview

How it works

PEM labels and Base64 body lines are parsed, whitespace is removed, DER bytes are decoded, and the object type is identified from ASN.1 structure when supported. Header labels remain metadata and do not authenticate the bytes.

  • BEGIN/END labels and 64-character Base64 lines follow RFC 7468 conventions.

Worked example

Parse PEM Block
Analyze a PEM-encoded public key to identify its type and size
Input
											-----BEGIN PUBLIC KEY-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzbcx4tfj8K+lXzGe7ihp
UO8AZSKtTIWOQIEeCYQjnoxv0GGBr9GU9viLZXvUdDi4weZkoyXBJGbdLsW2Otpo
tcsMUk2MRzxE61BB3QUJBlIK8h4SjmHGrrwQFbo48fKnDr7I/sk17TRmil94d6hA
sGhyyoJOqlQp4gJ5tRZpdwwzYNvMOm7jjYkTyTQ2q+Jyw1DDemwi0GRrtuB3ciD0
Ogl/B8lU8uekK8vq2iDiLXH6JWL997lLNJJBr/oH7NbhbpNDR2DZ7VA4lUyPNDBs
Xn99uVFw0ueo7SrlOe1Zuz7XQy1xdorISLfp4ZFUk5Iaf0JykysJLUA4u0lJ+SUF
VwIDAQAB
-----END PUBLIC KEY-----
										
Output
												=== PEM Block 1 ===
Type: PUBLIC KEY
Size: 294 bytes (2352 bits)
Base64 length: 392 characters
Format: SPKI (Subject Public Key Info)
First bytes: 30 82 01 22 30 0d 06 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 0f 00 30 82 01 0a 02 82 01 01 ...
											

When to use this

Certificate bundles, key migrations, and TLS troubleshooting parse PEM blocks.

Edge cases

  • A mismatched END label must be rejected.
  • A PEM block can be valid yet contain an unexpected key or certificate type.
  • Concatenated blocks need separate parsing and ordering.

References