RSA Key Generator
Processed Client SideGenerate an RSA public/private key pair entirely in your browser and export it as PEM. Keys are created with the Web Crypto API and never leave your device.
Bookmark this tool now — skip the search next time you need it.
About RSA Key Generator
This tool runs entirely in your browser. Whatever you paste is processed on your own device and is never uploaded, logged, or sent to any server.
Generate an RSA public and private key pair in your browser and export both as PEM. Keys are created with the Web Crypto API using the operating system cryptographic random source, and because everything happens locally the private key never crosses the network. You choose the modulus size and the intended use, and that second choice matters more than it looks: a key generated for signing uses RSASSA-PKCS1-v1_5 and a key generated for encryption uses RSA-OAEP, and the Web Crypto API will refuse to use one in place of the other. The public key exports as SPKI and the private key as PKCS#8.
Key features
- Key sizes of 2048, 3072, and 4096 bits
- Choice of purpose: signing with RSASSA-PKCS1-v1_5, or encryption with RSA-OAEP
- Generated with the Web Crypto API and the system cryptographic random source
- Public key exported as SPKI in PEM format, private key as PKCS#8 in PEM format
- Standard 65537 public exponent
- Both keys displayed ready to copy
- Runs entirely in your browser — the private key is never transmitted anywhere
How to use it
- Choose a key size — 2048 bits is the practical minimum today.
- Choose whether the key is for signing or for encryption.
- Generate, and wait a moment; larger keys take longer.
- Copy both keys, and store the private key somewhere secure immediately.
Tips & common mistakes
- Pick the purpose deliberately. A key generated for signing cannot be used for encryption through the Web Crypto API and vice versa — the algorithm is bound into the key.
- 2048 bits is the current floor and is fine for most uses. 3072 or 4096 buys longer-term margin at the cost of noticeably slower operations.
- The private key is secret and the public key is not. Never paste a private key into a ticket, a chat, or a repository — and never commit one, even to a private repo.
- Keys generated in a browser tab are convenient for development and testing. For production infrastructure, generate on the target machine with ssh-keygen or openssl so the key never exists anywhere else.
- RSA is slow for bulk data and is not used to encrypt large payloads directly. In practice it encrypts a symmetric key, which then encrypts the actual data.
- PEM is the base64 text format with the BEGIN and END header lines. Keep those lines intact — most parsers reject the body on its own.
- These are not SSH keys. An SSH public key uses a different single-line format, so convert with ssh-keygen if that is what you need.
- Need to inspect an existing certificate’s fields and expiry instead of generating a new key? Use the SSL Certificate Decoder.