What this does
PEM is Base64 wrapped in -----BEGIN ...----- lines, and the label is the only hint of what is inside. This parser reads every block in your input, tells you what it is, and shows the DER (ASN.1) structure underneath as an expandable tree with byte offsets, lengths, and human-readable OID names.
What it recognizes
CERTIFICATEandCERTIFICATE REQUEST(X.509 and PKCS#10).PUBLIC KEY(SPKI) andRSA PUBLIC KEY(PKCS#1).PRIVATE KEY(PKCS#8, any algorithm),RSA PRIVATE KEY(PKCS#1), andEC PRIVATE KEY(SEC1).ENCRYPTED PRIVATE KEYand traditionalProc-Type: 4,ENCRYPTEDkeys. These are reported as encrypted, with the cipher and key derivation shown when it can be read, but never decrypted; no passphrase is requested.- Unlabeled Base64 and mislabeled blocks are identified from their structure. Other labels (CRLs, PKCS#7, DH parameters) get a generic ASN.1 tree.
PKCS#1, PKCS#8, and SEC1 in one minute
BEGIN RSA PRIVATE KEY is PKCS#1: just the RSA numbers. BEGIN PRIVATE KEYis PKCS#8: the same key wrapped with an algorithm identifier, so it works for RSA, EC, and Ed25519.BEGIN EC PRIVATE KEY is SEC1, the older EC-specific format. Use thePEM to JWK converter to change formats or convert to JWK.
Limits and privacy
Input is capped at 2 MB, trees at 5,000 elements, and nesting at 24 levels, so hostile input cannot freeze the tab. Parsing is local: nothing is uploaded or saved, and private keys are never put in the URL.