PEM JWK DER Converter
Convert PEM, JWK, and DER keys in any direction. RSA, EC, Ed25519. Nothing is uploaded.
Convert between PEM, JWK, and DER key formats. RSA, EC, and Ed25519. Private and public keys. Runs entirely in your browser. Read more Show less
The three key formats
Public and private keys are the same mathematical object, but they are written down in three different ways depending on what the surrounding software expects. PEM, JWK, and DER are the three formats you will encounter in practice, and converting between them is routine work when configuring TLS, signing JWTs, or integrating with an OAuth provider.
- PEM - text. Base64 content between
-----BEGINand-----ENDheader lines. Whatopenssl genrsawrites, what you paste into an.envfile, what most servers read. - DER - binary. The same bytes as a PEM file after base64 decoding. What is actually sent over the wire in TLS and what X.509 certificates are made of.
- JWK - JSON. A structured object with named fields (
kty,n,e,d,x,y, and so on). What OAuth/OIDC providers publish at their/.well-known/jwks.jsonendpoints, what the Web Crypto API consumes directly.
How to use
Paste a key in any of the three formats. The tool detects the input format and key type automatically and shows what it found in the info bar. Choose an output format, and the result appears in the output panel.
Supported input formats:
- PEM - PKCS#8 private keys (
-----BEGIN PRIVATE KEY-----) and SPKI public keys (-----BEGIN PUBLIC KEY-----). - JWK - any standard JSON Web Key object with a valid
ktyfield. - DER - raw base64-encoded binary. Paste the base64 text (whitespace is stripped).
Supported key types: RSA, EC (P-256, P-384, P-521), and Ed25519. Both private and public keys work.
When to use each format
Use PEM when a tool wants a file or a string that starts with -----BEGIN. OpenSSL, ssh-keygen, Nginx, Apache, and most server software. Human-readable and easy to paste into configuration.
Use JWK when a tool speaks JOSE, OAuth, or OIDC. JWT signing libraries (including jose), Auth0, Okta, and the browser's Web Crypto API all take JWK. Also the only format a JSON document can carry.
Use DER when a tool speaks bytes. TLS handshakes, X.509 certificates, hardware tokens, and any context where a base64 text wrapper is pure overhead.
Pasting private keys
Most online converters only accept public keys because they send your input to a server. This tool does not. Everything runs in the browser, nothing is uploaded, and nothing leaves the tab. That is what makes it safe (in the ordinary sense) to convert a private key here.
Caveat. If you paste a private key into any web page, you are trusting the browser, the loaded JavaScript, and any browser extensions you have installed. For a private key that protects production infrastructure, the safe path is still to use openssl locally. This tool exists because routine conversions should not require a shell, not because a browser is a substitute for one.
If you only need to convert a public key, use that. Public keys carry no secret and there is no risk.
FAQ
What is the difference between PKCS#8 and PKCS#1?
Both encode RSA private keys. PKCS#1 is the older format and begins with -----BEGIN RSA PRIVATE KEY-----. PKCS#8 is the modern, algorithm-agnostic format and begins with -----BEGIN PRIVATE KEY-----. This tool accepts PKCS#8 only. If your key starts with "RSA PRIVATE KEY", convert it first: openssl pkcs8 -topk8 -nocrypt -in old.pem -out new.pem.
Why does my EC key not convert?
Older OpenSSL versions write EC private keys in SEC1 format (-----BEGIN EC PRIVATE KEY-----). This tool accepts PKCS#8 (-----BEGIN PRIVATE KEY-----). Convert SEC1 to PKCS#8 with: openssl pkcs8 -topk8 -nocrypt -in ec.pem -out ec-pkcs8.pem.
What is the difference between a public key and a certificate?
A certificate contains a public key plus metadata (subject, issuer, validity dates, signature). If you have a certificate and want only the public key: openssl x509 -in cert.pem -pubkey -noout. Converting certificates themselves is a separate tool.
Does the JWK output include private fields?
Only if the input was a private key. A public key converts to a JWK with public fields only (n and e for RSA, x and y for EC, x for Ed25519). A private key adds the private fields (d for RSA and EC, d for Ed25519).
What does "kid" mean in a JWK?
Key ID. An optional hint that identifies which key in a set is being referenced. This tool does not add or modify a kid. If you need one, add it to the JWK JSON after conversion.
Is the output deterministic?
Yes for a given input. Converting the same PEM to JWK always produces the same JSON. Converting back to PEM may differ in line wrapping from the original but the underlying key bytes are identical.
Can I convert between different key sizes?
No. A 2048-bit RSA key converts to a 2048-bit RSA key. Changing the size is called key generation, which is a separate operation.
What about X.509 certificates?
That is a separate tool. This tool handles keys only. A certificate embeds a public key plus signature and metadata; converting a certificate to its constituent public key is a one-line openssl command shown in the CLI section below.
Command line equivalent
# PEM to JWK (Node, using jose)
node -e '
const jose = require("jose");
const fs = require("fs");
(async () => {
const pem = fs.readFileSync("key.pem", "utf8");
const key = await jose.importPKCS8(pem, "RS256", { extractable: true });
console.log(JSON.stringify(await jose.exportJWK(key), null, 2));
})();
'
# PEM to DER (openssl)
openssl pkcs8 -topk8 -nocrypt -in key.pem -outform DER -out key.der
# DER to PEM (openssl)
openssl pkey -inform DER -in key.der -out key.pem
# PKCS#1 to PKCS#8 (RSA private)
openssl pkcs8 -topk8 -nocrypt -in rsa-pkcs1.pem -out rsa-pkcs8.pem
# SEC1 to PKCS#8 (EC private)
openssl pkcs8 -topk8 -nocrypt -in ec-sec1.pem -out ec-pkcs8.pem
# Extract public key from private key
openssl pkey -in private.pem -pubout -out public.pem
# Inspect a key
openssl pkey -in key.pem -text -noout
# Extract public key from certificate
openssl x509 -in cert.pem -pubkey -noout