What key size should I use?
2048 bits is the current minimum recommendation for most uses; 3072 or 4096 bits for longer-term or higher-security needs. Larger keys are slower to generate and use.
Keys are generated locally with the Web Crypto API (RSASSA-PKCS1-v1_5, SHA-256, exponent 65537) and never leave your browser.
Generate to see the key pair here.
Generate a real RSA public/private key pair locally with the Web Crypto API, in PEM or DER (hex) format.
Keys are generated locally in your browser using the Web Crypto API's RSASSA-PKCS1-v1_5 algorithm and never leave it. The private key is never included in a share link — only the key size and format travel that way.
2048 bits is the current minimum recommendation for most uses; 3072 or 4096 bits for longer-term or higher-security needs. Larger keys are slower to generate and use.
Be cautious — generate keys for TLS certificates, SSH, or production signing on a secure machine with your own tooling. Use an online generator mainly for learning, testing, and prototyping — and specifically one that's verifiably client-side, like this one.
The public key can be shared freely — it encrypts data or verifies signatures. The private key must stay secret — it decrypts data or creates signatures. Never share or upload it.
PKCS#8 for the private key (-----BEGIN PRIVATE KEY-----) and SPKI for the public key — the modern, algorithm-agnostic standard most current software expects. PKCS#1's legacy -----BEGIN RSA PRIVATE KEY----- format isn't offered here; if a tool specifically requires it, convert with openssl rsa -in key.pem -traditional.
SSH authentication, TLS/SSL certificates, JWT signing (RS256), code signing, and email encryption (PGP/GPG).
No — key generation runs entirely client-side using the Web Crypto API; nothing is transmitted or logged.