>_devtools

PEM Parser & ASN.1 Viewer

Detect what a PEM block is (certificate, CSR, public or private key in PKCS#1, PKCS#8, or SEC1) and explore its ASN.1 structure as a tree.

What this does

PEM is Base64 wrapped in -----BEGIN ...----- lines, and the label is the only hint of what is inside. This parser reads every block in your input, tells you what it is, and shows the DER (ASN.1) structure underneath as an expandable tree with byte offsets, lengths, and human-readable OID names.

What it recognizes

  • CERTIFICATE and CERTIFICATE REQUEST (X.509 and PKCS#10).
  • PUBLIC KEY (SPKI) and RSA PUBLIC KEY (PKCS#1).
  • PRIVATE KEY (PKCS#8, any algorithm), RSA PRIVATE KEY (PKCS#1), and EC PRIVATE KEY (SEC1).
  • ENCRYPTED PRIVATE KEY and traditional Proc-Type: 4,ENCRYPTED keys. These are reported as encrypted, with the cipher and key derivation shown when it can be read, but never decrypted; no passphrase is requested.
  • Unlabeled Base64 and mislabeled blocks are identified from their structure. Other labels (CRLs, PKCS#7, DH parameters) get a generic ASN.1 tree.

PKCS#1, PKCS#8, and SEC1 in one minute

BEGIN RSA PRIVATE KEY is PKCS#1: just the RSA numbers. BEGIN PRIVATE KEYis PKCS#8: the same key wrapped with an algorithm identifier, so it works for RSA, EC, and Ed25519.BEGIN EC PRIVATE KEY is SEC1, the older EC-specific format. Use thePEM to JWK converter to change formats or convert to JWK.

Limits and privacy

Input is capped at 2 MB, trees at 5,000 elements, and nesting at 24 levels, so hostile input cannot freeze the tab. Parsing is local: nothing is uploaded or saved, and private keys are never put in the URL.