RSA Key Pair Generator

Configuration

Key size (bits)
Format

Keys are generated locally with the Web Crypto API (RSASSA-PKCS1-v1_5, SHA-256, exponent 65537) and never leave your browser.

Generated key pair

Generate to see the key pair here.

About this RSA Key Pair Generator

Generate a real RSA public/private key pair locally with the Web Crypto API, in PEM or DER (hex) format.

Keys are generated locally in your browser using the Web Crypto API's RSASSA-PKCS1-v1_5 algorithm and never leave it. The private key is never included in a share link — only the key size and format travel that way.

FAQ

What key size should I use?

2048 bits is the current minimum recommendation for most uses; 3072 or 4096 bits for longer-term or higher-security needs. Larger keys are slower to generate and use.

Is it safe to generate a real production key pair with an online tool?

Be cautious — generate keys for TLS certificates, SSH, or production signing on a secure machine with your own tooling. Use an online generator mainly for learning, testing, and prototyping — and specifically one that's verifiably client-side, like this one.

What's the difference between the public and private key?

The public key can be shared freely — it encrypts data or verifies signatures. The private key must stay secret — it decrypts data or creates signatures. Never share or upload it.

Does this generate PKCS#1 or PKCS#8 keys?

PKCS#8 for the private key (-----BEGIN PRIVATE KEY-----) and SPKI for the public key — the modern, algorithm-agnostic standard most current software expects. PKCS#1's legacy -----BEGIN RSA PRIVATE KEY----- format isn't offered here; if a tool specifically requires it, convert with openssl rsa -in key.pem -traditional.

What is RSA actually used for?

SSH authentication, TLS/SSL certificates, JWT signing (RS256), code signing, and email encryption (PGP/GPG).

Does my private key ever leave my browser?

No — key generation runs entirely client-side using the Web Crypto API; nothing is transmitted or logged.

Related tools