📐 PEM Base64 Line Wrapper

Paste a raw, unwrapped Base64 blob (no line breaks) and pick a label to wrap it into valid PEM format — 64-character lines with the right BEGIN/END header.

What the wrapper does to your text

Everything happens in the page. It strips all whitespace from what you paste, checks that only A-Z a-z 0-9 + / = remain, cuts the result into 64-character lines and puts the label you chose into BEGIN and END markers. That 64 is not decoration: RFC 7468 fixes it, with only the final line shorter.

What it does not do is decode anything. It never confirms the base64 is a complete DER object, and it cannot tell a certificate from a key, so the label is entirely your responsibility. Pick the wrong one and you get a file that looks perfect and fails to load. A useful check: a DER body almost always begins MII, which is the base64 of 0x30 0x82 - an ASN.1 SEQUENCE with a two-byte length.

Choosing the right label

CERTIFICATEAn X.509 certificate
CERTIFICATE REQUESTA PKCS#10 CSR
PRIVATE KEYPKCS#8, any algorithm
RSA PRIVATE KEYPKCS#1, RSA only
EC PRIVATE KEYSEC1, EC only
PUBLIC KEYSubjectPublicKeyInfo

Confirm the guess by loading the file: openssl x509 -in out.pem -noout -text for a certificate, openssl pkey for a key, openssl req for a CSR. If none of them accept it, openssl asn1parse -in out.pem will show whether the structure is even intact.

Save the result with a newline after the END line. Copying the block without one is a common cause of "bad end line" errors from OpenSSL and from Java keystore imports.

Frequently asked questions

How many characters per line does a PEM file need?

64. OpenSSL will read 76-character MIME wrapping too, but 64 is what the standard specifies and what every tool writes, so anything that has to travel should use it.

Can I paste the base64url string out of a JWT?

Not directly. base64url swaps + for - and / for _ and drops the padding, so the input is rejected. Replace those two characters and add = until the length is a multiple of four.

Why does my wrapped file still fail to load?

Usually the label does not match the contents - a PKCS#8 body labelled RSA PRIVATE KEY, say - or the base64 was truncated on the way in. Both produce valid looking PEM, because the wrapper only formats characters; it never parses them.