Elliptic Curve Key Generator (ECDSA / Ed25519 / X25519)
EC key pairs in PEM, JWK, raw hex and OpenSSH formats, generated in your browser.
Public key
Private key
Keep the private key secret: anyone who has it can sign as you or decrypt what is sent to you. It was made in this tab and is not stored or sent anywhere — save it now if you need it.
Adds an encrypted PKCS#8 file (“BEGIN ENCRYPTED PRIVATE KEY”): PBKDF2-HMAC-SHA256 with 600,000 iterations and AES-256-CBC, as openssl pkcs8 -topk8 -v2 aes-256-cbc writes. OpenSSL, Node.js and Java (tested with OpenJDK 21) open it with the passphrase. The other private formats stay unencrypted.
About the Elliptic Curve Key Generator (ECDSA / Ed25519 / X25519)
Create elliptic-curve key pairs for signing (ECDSA on P-256, P-384 or P-521, and Ed25519) or key agreement (ECDH on the same NIST curves, and X25519), using your browser’s Web Crypto generator. Every key is shown in the formats tools actually ask for: PEM (PKCS#8 private key, SubjectPublicKeyInfo public key and the older SEC 1 “EC PRIVATE KEY”), JWK with optional kid, use and alg, raw hex (uncompressed and compressed points), and OpenSSH public and private key files for SSH.
You also get the RFC 7638 JWK thumbprint and the SSH SHA256 fingerprint, so you can match keys across systems. The formats are tested against OpenSSL and ssh-keygen. Keys are generated and kept in the page only: nothing is uploaded or stored.
How to use it
- Choose the algorithm: ECDSA P-256 or Ed25519 for signatures (JWT, SSH, code signing), ECDH or X25519 for key agreement.
- For SSH keys, enter a comment such as you@laptop; for JWKs, choose whether to add kid, use and alg.
- Press Generate key pair (a P-256 pair is ready when the page opens).
- Optionally type a passphrase to get an encrypted PKCS#8 copy of the private key as well.
- Copy or download the format you need, or Download all (ZIP) to save every format at once. Store the private key safely — it cannot be recovered.
Examples
Ed25519 · comment priya@laptop
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAI… priya@laptop (paste into GitHub → Settings → SSH keys), plus id_ed25519
Save the private key as ~/.ssh/id_ed25519, run chmod 600 on it, and add a passphrase with ssh-keygen -p -f ~/.ssh/id_ed25519.
ECDSA P-256 · kid and alg on
{"crv":"P-256","kty":"EC","x":"…","y":"…","alg":"ES256","kid":"<thumbprint>"}Publish the public JWK in your JWKS; sign with the private PEM or JWK.
{"crv":"Ed25519","kty":"OKP","x":"11qYAYKxCrfVS_7TyWQHOg7hcvPapiMlrwIaaPcHURo"}kPrK_qmxVWaYVA9wwBF6Iuo3vVzz7TxHCTwXBygrS4k
SHA-256 over the required members in alphabetical order, Base64url-encoded — what the thumbprint row shows.
Common uses
- Making an SSH key on a computer where you cannot run ssh-keygen.
- Creating ES256 or EdDSA keys and a JWKS entry for testing JWT signing.
- Generating test keys for Web Crypto, TLS, WebAuthn or ECDH code in the format the code expects.
- Getting the compressed or uncompressed point of a public key for a protocol or hardware token.
Which key should I choose?
- ECDSA P-256 — the most widely supported signature key (TLS certificates, JWT ES256, WebAuthn, cloud KMS). P-384 and P-521 are larger NIST curves (FIPS 186-5) for stricter policies.
- Ed25519 (RFC 8032) — fast, compact and with deterministic signatures; the usual choice for new SSH keys. In JOSE its alg is now "Ed25519" (RFC 9864), which replaces the older "EdDSA".
- ECDH and X25519 (RFC 7748) — for agreeing on a shared secret, not for signing; they have no OpenSSH form.
The formats
- PKCS#8 PEM ("BEGIN PRIVATE KEY") and SubjectPublicKeyInfo PEM ("BEGIN PUBLIC KEY") are what OpenSSL, Java, .NET, Node.js and Web Crypto import; Ed25519 and X25519 use the RFC 8410 identifiers.
- SEC 1 PEM ("BEGIN EC PRIVATE KEY", RFC 5915) is the older OpenSSL format some tools still expect.
- Encrypted PKCS#8 ("BEGIN ENCRYPTED PRIVATE KEY"): type a passphrase to get the private key encrypted with PBES2 (RFC 8018) — PBKDF2-HMAC-SHA256 with 600,000 iterations, the OWASP recommendation, and AES-256-CBC, the scheme
openssl pkcs8 -topk8 -v2 aes-256-cbcwrites. - JWK (RFC 7517/7518, RFC 8037 for OKP keys); the thumbprint is RFC 7638’s SHA-256 hash of the required members, a stable key ID.
- Raw: the uncompressed point 04‖x‖y or the compressed 02/03‖x (SEC 1 §2.3.3), and the private scalar d; for Ed25519/X25519, the 32-byte keys.
- OpenSSH: the public line for authorized_keys (RFC 5656, RFC 8709) and an "OPENSSH PRIVATE KEY" file without a passphrase; ssh-keygen accepts both.
Browser support
Keys come from your browser’s Web Crypto generator. P-256, P-384 and P-521 work in every current browser. According to MDN’s compatibility data, Ed25519 needs Chrome or Edge 137, Firefox 129 or Safari 17, and X25519 needs Chrome or Edge 133, Firefox 130 or Safari 17; older browsers show a message instead of a key.
Limitations
- No pure-JavaScript fallback: on browsers without Web Crypto Ed25519/X25519 support, only the NIST curves work.
- Only the PKCS#8 file can be encrypted here. The OpenSSH private key is not passphrase-protected; add a passphrase with
ssh-keygen -p -f <file>before using it. - secp256k1 (Bitcoin/Ethereum), Ed448 and X448 are not offered.
- Importing and converting existing keys is not supported yet — this tool creates new key pairs.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
Is it safe to generate keys in a browser?
The keys come from your browser’s built-in Web Crypto API, which is designed for generating keys, and they never leave this tab: nothing is uploaded, logged or stored. For long-lived production keys, many teams still prefer to generate keys on the machine (or in the HSM) that will use them.
How do I use the SSH key?
Download the private key (id_ed25519 or id_ecdsa) to ~/.ssh/, run chmod 600 ~/.ssh/id_ed25519, add a passphrase with ssh-keygen -p -f ~/.ssh/id_ed25519, and put the one-line public key in the server’s ~/.ssh/authorized_keys or your Git host’s SSH settings.
What is the difference between PKCS#8 and “EC PRIVATE KEY”?
Both hold the same private key. PKCS#8 ("BEGIN PRIVATE KEY") is the modern, algorithm-neutral wrapper that almost everything reads; SEC 1 ("BEGIN EC PRIVATE KEY") is the older EC-only format from OpenSSL. Use PKCS#8 unless a tool asks for the other.
Should the JWK alg for Ed25519 be "EdDSA" or "Ed25519"?
RFC 9864 registered "Ed25519" and deprecated the older, polymorphic "EdDSA". New code should use "Ed25519"; choose "EdDSA" only for libraries that do not know the new name yet.
Can I use an ECDH key for signing?
No. ECDH and X25519 keys are for key agreement; use ECDSA or Ed25519 keys for signatures. RFC 8037 says the X25519 curve must not be used for signing, and keeping the purposes separate is good practice for NIST curves too.