📐 PEM Base64 Line Wrapper
Paste a raw, unwrapped Base64 blob (no line breaks) and pick a label to wrap it into valid PEM format — 64-character lines with the right BEGIN/END header.
What the wrapper does to your text
Everything happens in the page. It strips all whitespace from what you paste,
checks that only A-Z a-z 0-9 + / = remain, cuts the result into
64-character lines and puts the label you chose into BEGIN and END markers. That
64 is not decoration: RFC 7468 fixes it, with only the final line shorter.
What it does not do is decode anything. It never confirms the base64 is a complete
DER object, and it cannot tell a certificate from a key, so the label is entirely
your responsibility. Pick the wrong one and you get a file that looks perfect and
fails to load. A useful check: a DER body almost always begins
MII, which is the base64 of 0x30 0x82 - an ASN.1 SEQUENCE with a
two-byte length.
Choosing the right label
| CERTIFICATE | An X.509 certificate |
| CERTIFICATE REQUEST | A PKCS#10 CSR |
| PRIVATE KEY | PKCS#8, any algorithm |
| RSA PRIVATE KEY | PKCS#1, RSA only |
| EC PRIVATE KEY | SEC1, EC only |
| PUBLIC KEY | SubjectPublicKeyInfo |
Confirm the guess by loading the file: openssl x509 -in out.pem -noout -text
for a certificate, openssl pkey for a key, openssl req
for a CSR. If none of them accept it, openssl asn1parse -in out.pem
will show whether the structure is even intact.
Frequently asked questions
How many characters per line does a PEM file need?
64. OpenSSL will read 76-character MIME wrapping too, but 64 is what the standard specifies and what every tool writes, so anything that has to travel should use it.
Can I paste the base64url string out of a JWT?
Not directly. base64url swaps + for - and /
for _ and drops the padding, so the input is rejected. Replace those
two characters and add = until the length is a multiple of four.
Why does my wrapped file still fail to load?
Usually the label does not match the contents - a PKCS#8 body labelled RSA PRIVATE KEY, say - or the base64 was truncated on the way in. Both produce valid looking PEM, because the wrapper only formats characters; it never parses them.