JWK ↔ PEM Converter

Convert cryptographic keys between JWK and PEM formats — entirely in your browser

Paste either format — direction is auto-detected
Supports RSA and EC (P-256 / P-384 / P-521) keys, public and private. The key class (public vs. private) is detected from the PEM header or the presence of a JWK d field. Nothing you paste here ever leaves your browser.

About this tool

The JWK ↔ PEM Converter converts cryptographic keys between the two formats you'll run into most often when working with JWTs, OAuth, and TLS: JWK (JSON Web Key — the JSON format used in JWKS endpoints and most JS/Node crypto libraries) and PEM (the base64-wrapped text format used by OpenSSL, most CLI tools, and most server configs). Paste either format and the direction is detected automatically — a PEM's `-----BEGIN...-----` header, or a JWK's JSON structure. The actual conversion is done entirely with the browser's native Web Crypto API (`importKey`/`exportKey`), not a hand-rolled ASN.1 encoder, so the DER encoding underneath the PEM output is exactly what a real crypto library would produce. Supports RSA and EC (P-256, P-384, P-521) keys, both public and private.

When to use it

  • →Converting a public key from a JWKS endpoint (JWK format) into PEM to use with a CLI tool or OpenSSL command
  • →Converting a PEM key pair generated with openssl or ssh-keygen-style tooling into JWK format for a Node.js or browser JS library
  • →Inspecting what's actually inside a JWK without writing a script
  • →Bridging between a service that only accepts PEM and one that only accepts JWK

Tips

  • ◆The key class (public vs. private) is auto-detected — from the PEM header for PEM input, or from the presence of a private-exponent `d` field for JWK input.
  • ◆For EC keys, the curve (P-256/P-384/P-521) is read directly from the JWK's `crv` field, or auto-detected by trying each curve in turn when converting from PEM, since PEM alone doesn't state the curve as plainly.
  • ◆The hash algorithm used internally during conversion (SHA-256) has no effect on the exported key bytes — RSA and EC key encodings are purely mathematical and don't depend on which hash you'd eventually sign or verify with.

Frequently asked questions

Does this tool support both public and private keys?

Yes, for both directions. Converting a private key (PEM PKCS8 or a JWK with a d field) never leaves your browser — the conversion happens entirely client-side via the Web Crypto API, the same way the rest of ToolNinja's key and signature tools work.

Why does it need a hash algorithm if I'm just converting formats, not signing anything?

The Web Crypto API's importKey/exportKey functions require a full algorithm descriptor to import a key, even for a pure format conversion — but the hash parameter only affects sign/verify operations, not the key's actual encoded bytes. Any hash choice produces an identical PEM/JWK output for the same key.

What key types are NOT supported?

Only RSA and EC (P-256/P-384/P-521) keys are supported — these cover the vast majority of JWT and TLS use cases. Ed25519/X25519 keys, and any key type not exposed through the standard Web Crypto API, aren't supported here.

Related tools

🥷 ToolNinja