RSA Key Pair Generator

Public and private keys, generated in your browser.

Free. Runs in your browser: nothing you enter or open is uploaded.

Good for testing, learning and personal use. Keys made in a browser use the browser's own cryptographic random generator and are sound, but for servers, certificates and production systems, generate keys on the machine that will use them (for example with ssh-keygen or openssl) so the private key never exists anywhere else.

Keys are generated with your browser's Web Crypto API and never leave this page. RSA keys use the public exponent 65537. The public key is given as PEM (SubjectPublicKeyInfo) and in the one line OpenSSH format, with its SHA-256 fingerprint as ssh-keygen -l shows it.

How to use it

  1. Choose RSA or elliptic curve, and the key size or curve. RSA 3072 or ECDSA P-256 are sensible defaults.
  2. Press Generate key pair. RSA 4096 can take a few seconds.
  3. Copy or download the public and private keys. The OpenSSH line goes into ~/.ssh/authorized_keys on a server.

Questions

Which key size should I choose?

RSA 2048 is still accepted but is the minimum; 3072 is recommended for anything meant to last past 2030. ECDSA P-256 gives similar strength to RSA 3072 with much shorter keys and faster signing.

What is the difference between PEM and OpenSSH formats?

PEM is the Base64 text block between BEGIN and END lines used by OpenSSL, web servers and most libraries. The OpenSSH public key format is the single line starting ssh-rsa or ecdsa-sha2 that SSH servers read from authorized_keys.

Why is there no Ed25519 option?

Ed25519 is only available in the newest browsers' Web Crypto, so results would vary by browser. For an Ed25519 SSH key, run ssh-keygen -t ed25519 on your own computer.

Is the private key encrypted?

No. It is a plain PKCS#8 key, which is what most tools expect when importing. Add a passphrase with the openssl command shown under the key before you store it anywhere shared.