PEM Viewer
All computation runs locally in your browser. Private keys and CSRs never leave your device, and we never collect or store them.
About PEM Viewer
The CSR.plus PEM Viewer is a free PEM file viewer that makes opaque Base64 blobs readable. Paste a PEM bundle containing one or more blocks — certificates, private and public keys, CSRs, or CRLs — and the viewer labels every block by type, decodes its headers, and shows the contents in a readable, colour-coded layout.
Developers and administrators often receive concatenated PEM files from CAs, load balancers, and certificate managers. This online PEM viewer separates each BEGIN/END block, identifies what it contains, and lets you inspect or export blocks one by one — a quick way to understand a certificate chain bundle or a PKCS#12 export without command-line tools.
Why use
- Identify every block type in a bundle: certificate, key, CSR, or CRL
- Split concatenated PEM files into individual inspectable blocks
- Read decoded headers and payloads in a colour-coded layout
- Fully local parsing — nothing is uploaded to a server
How to use
- Copy the complete PEM text — a single block or a concatenated bundle.
- Paste it into the viewer box; every BEGIN/END block is detected automatically.
- Each block is listed with its detected type, headers, and decoded payload.
- Click any block to expand its details or export it individually.
Frequently asked questions
▸What PEM block types are recognised?
Certificates, RSA/EC private and public keys, CSRs, and CRLs, plus common variations of their BEGIN headers.
▸Does it upload my data?
No. Parsing is fully local; nothing is sent to a server.
▸Can it split a bundle into individual certificates?
Yes. Each block is separated and listed so you can inspect or export them one by one.
▸What does a PEM file contain?
PEM files are Base64-encoded blocks delimited by BEGIN/END header lines. They typically hold certificates, private keys, CSRs, or CRLs — often several blocks in one file.
Namecheap
Need a new SSL certificate?
DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.
Affiliate link — we may earn a commission at no extra cost to you.
More free tools
Certificate Viewer
Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.
Certificate / Key Matcher
Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.
SSL Format Converter
Convert between PEM, PFX/PKCS#12 and P7B/PKCS#7 — all locally in your browser.
SSL Checker (A-F Grade)
Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.
SSL Bulk Checker
Check multiple SSL certificates at once
ACME Challenge Preflight
Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.
Let's Encrypt Checker
Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.
DNS Propagation Checker
Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.
LE Chain Compatibility
See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.
ACME Command Generator
Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.
Certificate Inspector
Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.
SSL Expiry Checker
Quickly check a domain's SSL certificate expiry date and remaining days.
Certificate Transparency Lookup
List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.
CAA Record Checker
Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.
Certificate Revocation Checker
Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.
SSL Handshake Tracer
Perform a real TLS handshake and record every step: DNS, TCP, negotiated TLS version and cipher, and each certificate returned.