Registry stack documentation: machine-readable Markdown.
Index of all pages: https://docs.registrystack.org/dev/llms.txt
Full corpus: https://docs.registrystack.org/dev/llms-full.txt

# evidencectl jwk from-pem command reference

> Generated syntax and options for evidencectl jwk from-pem.

{/* Generated from Clap command definitions by scripts/generate-cli-reference.mjs. Run npm run generate. */}

Convert one PEM public key into a public JWK whose kid is its RFC 7638 thumbprint.

## Contract status

This page is generated from the public Clap command tree for Registry Stack source version `0.40.0` and catalog SHA-256 `42b4f89103fb6b0fc57282f99a8d8ab8fc777b3c745d6243720ff4a99ba1f57f`. Hidden implementation commands are omitted.

## Description

Convert one PEM public key into a public JWK whose kid is its RFC 7638 thumbprint. Accepts a `PUBLIC KEY` (SubjectPublicKeyInfo) or `RSA PUBLIC KEY` (PKCS #1) block: EC P-256 becomes ES256, EC P-384 becomes ES384, and RSA takes the algorithm named by `--alg`. A private key is refused.

## Usage

```text
evidencectl jwk from-pem [OPTIONS] <PEM>
```

## Constraints

| Condition | Requirement |
| --- | --- |
| Command invocation | `--output <OUTPUT>` and `--output-dir <OUTPUT_DIR>` cannot be used together. |

## Arguments

| Argument | Always required | Default | Values | Environment | Description |
| --- | --- | --- | --- | --- | --- |
| `<PEM>` | Yes | n/a | n/a | n/a | PEM public key file, or `-` to read standard input |

## Options

| Option | Always required | Default | Values | Environment | Description |
| --- | --- | --- | --- | --- | --- |
| `--alg <ALG>` | No | n/a | `es256`, `es384`, `rs256`, `rs384` | n/a | JWS algorithm the key is published for; required for RSA keys |
| `--output <OUTPUT>` | No | n/a | n/a | n/a | Write the JWK to this file instead of standard output |
| `--output-dir <OUTPUT_DIR>` | No | n/a | n/a | n/a | Write the JWK into this existing directory as `<kid>.jwk.json` |
| `--force` | No | n/a | n/a | n/a | Overwrite an existing output file |
| `--format <output_format>` | No | `human` | `human`, `json`, `junit` | n/a | Select human-readable or machine-readable output. `junit` is accepted only by fixture runs (`test` and `fixtures run`) |
| `-h, --help` | No | n/a | n/a | n/a | Print help (see a summary with '-h') |

## Generation contract

Run `npm run generate` from `docs/site` after changing a public command, argument, option, default, environment binding, or help description.