Regex for PEM-encoded key/certificate
BEGIN ... END envelope of a PEM file.
The PEM-encoded key/certificate regex is -----BEGIN [A-Z ]+-----[\s\S]+?-----END [A-Z ]+----- — copy it below, or open it in the explainer for a token-by-token breakdown.
The pattern
-----BEGIN [A-Z ]+-----[\s\S]+?-----END [A-Z ]+-----
What it matches
-----BEGIN PRIVATE KEY----- ABC123... -----END PRIVATE KEY----------BEGIN CERTIFICATE----- ... -----END CERTIFICATE-----
What it doesn't match
some random text-----BEGIN-----
Notes & gotchas
Captures the entire PEM block. Common types: PRIVATE KEY, RSA PRIVATE KEY, EC PRIVATE KEY, PUBLIC KEY, CERTIFICATE, CERTIFICATE REQUEST. Body is base64.
Code in your language
Use the explainer's Code tab to generate ready-to-paste snippets in JavaScript, Python, Java, .NET, Go, Ruby, and PHP for this pattern.
Open in explainer →Token-by-token breakdown
Every part of the pattern, left to right:
| Token | Meaning |
|---|---|
-----BEGIN | literal text “-----BEGIN ” |
[A-Z ]+ | one or more: any of: uppercase letters, “ ” |
----- | literal text “-----” |
[\s\S]+? | one or more (lazy — as few as possible): any of: whitespace, non-whitespace |
-----END | literal text “-----END ” |
[A-Z ]+ | one or more: any of: uppercase letters, “ ” |
----- | literal text “-----” |
About this pattern
Identifier formats like UUIDs, hashes, and version strings have well-defined structures that regex captures cleanly. The pattern verifies format; checksums and validity against a registry need additional checks.
Quick usage in different languages
This exact pattern — with the correct escaping and idioms for each language:
- JavaScript:
/-----BEGIN [A-Z ]+-----[\s\S]+?-----END [A-Z ]+-----/.test(value) - Python:
re.match(r"-----BEGIN [A-Z ]+-----[\s\S]+?-----END [A-Z ]+-----", value) - Java:
Pattern.compile("-----BEGIN [A-Z ]+-----[\\s\\S]+?-----END [A-Z ]+-----").matcher(value).matches() - C# / .NET:
Regex.IsMatch(value, @"-----BEGIN [A-Z ]+-----[\s\S]+?-----END [A-Z ]+-----") - Go:
regexp.MustCompile(`-----BEGIN [A-Z ]+-----[\s\S]+?-----END [A-Z ]+-----`).MatchString(value) - Ruby:
/-----BEGIN [A-Z ]+-----[\s\S]+?-----END [A-Z ]+-----/.match?(value) - PHP:
preg_match('~-----BEGIN [A-Z ]+-----[\s\S]+?-----END [A-Z ]+-----~', $value)
The explainer’s Code tab regenerates these for any pattern you paste, and the downloadable cheat sheet bundles the breakdown, all seven snippets, and the pitfalls below onto one printable page.
Common pitfalls
- Not anchored. Without ^ and $ this can match a substring anywhere in the input — add anchors if you need the whole value to conform.
- Uppercase only. Ranges like [A-Z] won't match lowercase. Add a-z (or the i flag) if lowercase input should be accepted.
- Escape it correctly per language. In Java and JavaScript strings each backslash must be doubled (\\d); in Python, Go, and C# use raw/verbatim strings so the backslashes survive.
- Validate beyond format. Matching the format doesn't guarantee the value is real. Confirm the pem-encoded key/certificate against a source of truth (database, API, or checksum) where it matters.
Standards & sources
This pattern is based on the following authoritative specification(s) and issuing authorities. Formats can change — always confirm against the primary source.
Related patterns
More patterns in the Codes & IDs category:
- Solana address
- SSH public key
- Ethereum address
- Generic API key
- Bitcoin SegWit address (bech32)
- Semver range (npm style)
See also
Browse all 300 patterns in the library, or open this regex in the interactive explainer to see a token-by-token breakdown, test against custom input, and generate code in seven languages.