PEM is a text wrapper for binary cryptographic data: Base64 between -----BEGIN …----- and -----END …----- lines. The label says what is inside: a CERTIFICATE, a CERTIFICATE REQUEST, a PUBLIC KEY, a PKCS7 bundle or a private key. The same data in raw binary form is called DER, and .crt or .cer files can be either. This decoder recognises each block, decodes certificates, CSRs and public keys into readable fields, splits PKCS#7 (.p7b) bundles into individual certificates, shows the ASN.1 structure of anything else, and converts between PEM and DER.
How to decode and convert a PEM file
Paste PEM text or open a .pem, .crt, .cer, .der, .p7b or .pub file. Binary DER files are converted to PEM automatically.
Each block is decoded into its own card.
Open PEM & DER to copy the PEM or download .pem, .crt or binary DER.
Use the ASN.1 tab for blocks that are not certificates, such as EC parameters.
The OpenSSL equivalents
Prefer the command line? These OpenSSL commands do the same job on your own machine.
DER (.cer/.crt) to PEM
openssl x509 -inform der -in cert.cer -out cert.pem
PEM to DER
openssl x509 -in cert.pem -outform der -out cert.der
Knows every common blockCertificates, trusted certificates, CSRs, PKCS#1 and SPKI public keys, PKCS#7 bundles and ASN.1 for the rest.
Converts both waysOpen a DER file to get PEM, or download DER from PEM: the CRT to PEM and PEM to DER jobs, without OpenSSL.
Keeps private keys privatePrivate key blocks are recognised but never decoded or displayed.
Nothing is uploadedDecoding and signature checks run in your browser with the Web Crypto API. Certificates and CSRs never reach a server, which matters for internal hosts and unreleased domains.
Common uses
Unknown .pem file. Find out whether it holds a certificate, a chain, a key or a CSR.
Server configuration. Convert a Windows .cer (DER) to PEM for nginx, Apache or HAProxy.
P7B from a CA. Split a PKCS#7 bundle into separate PEM certificates.
Java and Android. Produce the DER files some keystores and devices require.
A Let’s Encrypt fullchain.pem holds two or three CERTIFICATE blocks. Pasting it shows each certificate in order, with the issuing relationships verified.
What to expect from the result
Encrypted and unencrypted private keys are not decoded. PKCS#12 (.pfx, .p12) files are password-protected and not supported. CRLs are shown as an ASN.1 structure.
PEM Decoder questions
How do I open a PEM file?
PEM files are plain text. Open one here, or in any text editor; this decoder turns the Base64 content into readable fields.
How do I convert CRT to PEM?
Open the .crt file. If it is binary DER, it is converted to PEM automatically; copy the PEM or download a .pem file from the PEM & DER tab.
What is the difference between PEM and DER?
They hold the same data. DER is binary; PEM is DER encoded in Base64 with BEGIN and END lines, so it can be pasted into text files and emails.
Which formats can I decode?
PEM (BEGIN CERTIFICATE, CERTIFICATE REQUEST, PUBLIC KEY, RSA PUBLIC KEY, PKCS7), binary DER files (.der, .cer, .crt), PKCS#7 bundles (.p7b, .p7c), bare Base64 and hex. Several PEM blocks can be pasted at once.
Is it safe to paste my certificate here?
Yes. Certificates and CSRs contain only public information, and this tool decodes them in your browser without sending anything to a server. Never paste a private key into any website; if you do, this tool refuses to decode it.
100% private — your data never leaves your browser
No registration, no tracking of your content, no server uploads. Don't just take our word for it:
No server, no uploads
Your files and text are processed entirely on your device. Nothing is ever sent to us.
Works offline
Once loaded, this tool keeps working with your Wi-Fi turned off. Try it.
Verify it yourself
Open your browser's DevTools → Network tab. You'll see zero requests carrying your data.