Key Format Converter

Convert RSA PKCS#1 and general PKCS#8 private keys locally, optionally changing output password protection without changing the underlying key.

Privacy: all processing happens locally in your browser. Your input never leaves your device.

What is Key Format Converter?

RSA private keys can use PKCS#1 or PKCS#8, while EC and SM2 private keys can use general PKCS#8. A service that cannot read a private key may require a different container. This tool converts private-key containers without changing the mathematical key. PKCS#1 output is available only for RSA. Convert only to meet a confirmed target requirement; conversion is not key rotation and a private key must never be shared as if it were public.

How to Use

  1. Paste the PEM key and enter its password locally if needed
  2. Choose PKCS#8 or RSA-only PKCS#1, optionally setting an output protection password
  3. Check the PEM boundary and algorithm, then copy or download the result

FAQ

What is the difference between PKCS#1 and PKCS#8?
PKCS#1 is an RSA-specific private-key encoding. PKCS#8 is a general private-key container for RSA, EC, SM2 and other algorithms.
Does conversion make a new key?
No. It changes encoding only; the corresponding public key and fingerprint should remain the same.
Why does an encrypted key need a password?
The password decrypts the protected PEM locally. Wrong passwords or unsupported protection are rejected rather than bypassed.

Related Tools

Last updated 2026-10-09