PEM Key Inspector is a free tool that tells you what a key file is and whether it belongs with a certificate or a certificate signing request. Paste a private key and a certificate together and it says whether they are the same key pair — the question behind most "key values mismatch" errors. It reads every common format, from PKCS#8 and old-style RSA and EC keys to OpenSSH keys, and it runs entirely in your browser: keys are never uploaded or saved.
How to check a private key matches a certificate
- Paste the private key and the certificate into the box, or use Open files and pick both at once.
- Read the banner at the top: it says whether they match, or which ones do when you paste several.
- Each item is numbered and lists what it matches, so you can see which key goes with which certificate.
- Clear the box when you are done.
When you need this
A web server that refuses to start with "key values mismatch", a load balancer or CDN that rejects an uploaded certificate, or a renewal where the old and new files have got mixed up: all of these come down to a certificate installed with the wrong private key. It also answers the reverse question — which of several keys on a server goes with this certificate — and whether a CSR was made from the key you think it was.
How the comparison works
Every certificate and CSR carries a public key, and every private key contains its public half. Two files belong together exactly when those public keys are identical. This tool extracts the public key from each item and compares them. The public key pin shown for each is a SHA-256 hash of that key: the same value appears for the private key, its CSR and every certificate issued for it, and it matches the pin on theX.509 Certificate Decoder.
With openssl, the usual way is to compare openssl x509 -noout -modulus -in cert.pem withopenssl rsa -noout -modulus -in key.pem. That only works for RSA; this works for EC and Ed25519 keys too, and needs no terminal.
Formats it reads
- Private keys: PKCS#8 (
BEGIN PRIVATE KEY), PKCS#1 (BEGIN RSA PRIVATE KEY) and SEC1 (BEGIN EC PRIVATE KEY). - Public keys:
BEGIN PUBLIC KEYandBEGIN RSA PUBLIC KEY. - Certificates and requests, in PEM or binary DER.
- SSH keys:
ssh-ed25519,ssh-rsaandecdsa-sha2public key lines, and OpenSSH private keys, including passphrase-protected ones, whose public half is stored unencrypted.
About pasting private keys
A private key is the one file that must stay secret: anyone who has it can impersonate your server. This page never sends what you paste anywhere and keeps nothing once you leave — it keeps working with your network switched off. Even so, the safest habit is to paste a production key into as few places as possible. Password-protected keys cannot be read without their password; decrypt a temporary copy with openssl pkey, check it, and delete it. To read the details of the certificate itself, use theX.509 Certificate Decoder, and for a request, theCSR Decoder.
Troubleshooting
- No match, but you are sure it is the right key: check the certificate file. A chain file often has your certificate plus its issuers; the issuers will not match, but your certificate should.
- “EC parameters”: openssl writes a curve name above some EC keys. It is not a key and can be ignored.
- Password-protected key: the page can say what it is, but not compare it. Decrypt a copy first.
Frequently asked questions
Is it safe to paste a private key here?
It is read in your browser and never sent to our servers or saved — the page works with your network switched off. Even so, the habit worth keeping is to paste production private keys into as few places as possible. Use a test key when you just want to see how something works.
How does it tell whether a key and a certificate match?
A private key contains its public half. The public key inside a certificate or CSR is compared with the one inside the private key: if they are identical, they are the same key pair. This is the same check as comparing the modulus with openssl, but it also works for EC, Ed25519 and SSH keys.
My key starts with ENCRYPTED PRIVATE KEY.
It is protected by a password, so its contents cannot be read without it. Make a decrypted copy with openssl pkey -in key.pem -out plain.pem, check that, then delete the copy.
What is the public key pin?
A SHA-256 hash of the public key, in base64. It is the same for every file that holds the same key — the private key, its CSR and every certificate issued for it — so it is an easy way to compare them by eye.
Can I compare an SSH key with a PEM key?
Yes. RSA, ECDSA and Ed25519 SSH keys are converted to the same form as PEM keys, so an id_ed25519.pub line and a PEM key match when they are the same key. The SHA256 fingerprint shown is the one ssh-keygen -l prints.
Last updated