Digital ToolPad.

Runs 100% in your browser

Your data never leaves your device. zero uploads.

PEM Decoder

Paste or open any PEM, CRT, CER, DER or P7B file to see what is inside and convert it between PEM and DER.

  • Certificates, CSRs & keys
  • PEM ↔ DER
  • P7B bundles split
  • Nothing uploaded
Found: 3 certificates

#1 Certificate

www.example.com

DV
Subject
  • Common name: www.example.com
Issuer
  • Country: GB
  • Organization: Digital ToolPad Example
  • Common name: Example TLS Issuing CA E1
Valid from
2026-10-01 00:00:00 UTC
Valid until
2031-10-01 00:00:00 UTC
Names (SAN)
  • www.example.com
  • example.com
  • api.example.com
Public key
EC 256-bit (P-256, prime256v1)
Signature
ecdsa-with-SHA256
Serial number
04:D2:A1:B3:C4:D5:E6:F7:08
Version
X.509 v3

Extensions (9)

Basic Constraints
CriticalCA: FALSE
Key Usage
CriticalDigital signature
Extended Key Usage
TLS server authentication
Subject Alternative Name
DNS: www.example.com DNS: example.com DNS: api.example.com
Subject Key Identifier
C9:2D:54:FC:59:B8:81:D5:08:63:C7:09:CB:ED:05:43:C0:14:06:99
Authority Key Identifier
Key ID: AD:A8:BA:C9:B2:99:02:5B:24:40:64:9F:8D:E3:A5:C8:A8:C1:76:54
Authority Information Access
OCSP: http://ocsp.example.com CA issuers: http://ca.example.com/e1.crt
CRL Distribution Points
URI: http://crl.example.com/e1.crl
Certificate Policies
CA/Browser Forum domain validated (2.23.140.1.2.1)

#2 CA certificate

Example TLS Issuing CA E1

Subject
  • Country: GB
  • Organization: Digital ToolPad Example
  • Common name: Example TLS Issuing CA E1
Issuer
  • Country: GB
  • Organization: Digital ToolPad Example
  • Common name: Example Root CA R1
Valid from
2026-01-01 00:00:00 UTC
Valid until
2036-01-01 00:00:00 UTC
Names (SAN)
None
Public key
EC 256-bit (P-256, prime256v1)
Signature
ecdsa-with-SHA384
Serial number
5A:1E:7F:00:C0:FF:EE:01
Version
X.509 v3

Extensions (5)

Basic Constraints
CriticalCA: TRUE Path length: 0
Key Usage
CriticalDigital signature Certificate signing CRL signing
Extended Key Usage
TLS server authentication TLS client authentication
Subject Key Identifier
AD:A8:BA:C9:B2:99:02:5B:24:40:64:9F:8D:E3:A5:C8:A8:C1:76:54
Authority Key Identifier
Key ID: ED:AD:1E:F1:5A:DA:94:57:B3:78:85:2B:00:84:16:BB:E9:D1:06:6F

#3 CA certificate

Example Root CA R1

Subject
  • Country: GB
  • Organization: Digital ToolPad Example
  • Common name: Example Root CA R1
Issuer
  • Country: GB
  • Organization: Digital ToolPad Example
  • Common name: Example Root CA R1
Valid from
2026-01-01 00:00:00 UTC
Valid until
2046-01-01 00:00:00 UTC
Names (SAN)
None
Public key
EC 384-bit (P-384, secp384r1)
Signature
ecdsa-with-SHA384
Serial number
3C:4F:38:EB:FD:A1:9A:FD:D0:65:AC:C8:00:84:05:49:7B:B5:26:1C
Version
X.509 v3

Extensions (4)

Authority Key Identifier
Key ID: ED:AD:1E:F1:5A:DA:94:57:B3:78:85:2B:00:84:16:BB:E9:D1:06:6F
Basic Constraints
CriticalCA: TRUE
Key Usage
CriticalCertificate signing CRL signing
Subject Key Identifier
ED:AD:1E:F1:5A:DA:94:57:B3:78:85:2B:00:84:16:BB:E9:D1:06:6F

What is a PEM file?

PEM is a text wrapper for binary cryptographic data: Base64 between -----BEGIN …----- and -----END …----- lines. The label says what is inside: a CERTIFICATE, a CERTIFICATE REQUEST, a PUBLIC KEY, a PKCS7 bundle or a private key. The same data in raw binary form is called DER, and .crt or .cer files can be either. This decoder recognises each block, decodes certificates, CSRs and public keys into readable fields, splits PKCS#7 (.p7b) bundles into individual certificates, shows the ASN.1 structure of anything else, and converts between PEM and DER.

How to decode and convert a PEM file

  1. Paste PEM text or open a .pem, .crt, .cer, .der, .p7b or .pub file. Binary DER files are converted to PEM automatically.
  2. Each block is decoded into its own card.
  3. Open PEM & DER to copy the PEM or download .pem, .crt or binary DER.
  4. Use the ASN.1 tab for blocks that are not certificates, such as EC parameters.

The OpenSSL equivalents

Prefer the command line? These OpenSSL commands do the same job on your own machine.

DER (.cer/.crt) to PEM
openssl x509 -inform der -in cert.cer -out cert.pem
PEM to DER
openssl x509 -in cert.pem -outform der -out cert.der
P7B bundle to PEM certificates
openssl pkcs7 -print_certs -in bundle.p7b -out bundle.pem

Why use this PEM decoder

  • Knows every common blockCertificates, trusted certificates, CSRs, PKCS#1 and SPKI public keys, PKCS#7 bundles and ASN.1 for the rest.
  • Converts both waysOpen a DER file to get PEM, or download DER from PEM: the CRT to PEM and PEM to DER jobs, without OpenSSL.
  • Keeps private keys privatePrivate key blocks are recognised but never decoded or displayed.
  • Nothing is uploadedDecoding and signature checks run in your browser with the Web Crypto API. Certificates and CSRs never reach a server, which matters for internal hosts and unreleased domains.

Common uses

  • Unknown .pem file. Find out whether it holds a certificate, a chain, a key or a CSR.
  • Server configuration. Convert a Windows .cer (DER) to PEM for nginx, Apache or HAProxy.
  • P7B from a CA. Split a PKCS#7 bundle into separate PEM certificates.
  • Java and Android. Produce the DER files some keystores and devices require.

More developer tools: the JWT decoder, Base64 decoder, hash generator and subnet calculator.

Example: a fullchain.pem file

A Let’s Encrypt fullchain.pem holds two or three CERTIFICATE blocks. Pasting it shows each certificate in order, with the issuing relationships verified.

What to expect from the result

Encrypted and unencrypted private keys are not decoded. PKCS#12 (.pfx, .p12) files are password-protected and not supported. CRLs are shown as an ASN.1 structure.

PEM Decoder questions

How do I open a PEM file?

PEM files are plain text. Open one here, or in any text editor; this decoder turns the Base64 content into readable fields.

How do I convert CRT to PEM?

Open the .crt file. If it is binary DER, it is converted to PEM automatically; copy the PEM or download a .pem file from the PEM & DER tab.

What is the difference between PEM and DER?

They hold the same data. DER is binary; PEM is DER encoded in Base64 with BEGIN and END lines, so it can be pasted into text files and emails.

Which formats can I decode?

PEM (BEGIN CERTIFICATE, CERTIFICATE REQUEST, PUBLIC KEY, RSA PUBLIC KEY, PKCS7), binary DER files (.der, .cer, .crt), PKCS#7 bundles (.p7b, .p7c), bare Base64 and hex. Several PEM blocks can be pasted at once.

Is it safe to paste my certificate here?

Yes. Certificates and CSRs contain only public information, and this tool decodes them in your browser without sending anything to a server. Never paste a private key into any website; if you do, this tool refuses to decode it.

100% private — your data never leaves your browser

No registration, no tracking of your content, no server uploads. Don't just take our word for it:

  • No server, no uploads

    Your files and text are processed entirely on your device. Nothing is ever sent to us.

  • Works offline

    Once loaded, this tool keeps working with your Wi-Fi turned off. Try it.

  • Verify it yourself

    Open your browser's DevTools → Network tab. You'll see zero requests carrying your data.

Explore more tools

More utilities for your next task.

Browse all tools