Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

PGP Key Generator

Your own PGP key pair, with revocation certificate, made privately in your browser.

Security No upload Works offline Free, no sign-up

Your key

The user ID is made from the name and the e-mail address.

Key format

    Next steps

    About the PGP Key Generator

    Create an OpenPGP key pair for encrypted e-mail, signing files or Git commits, or letting people send you files that only you can open. By default you get a Curve25519 key — an Ed25519 primary key for certifying and signing and an X25519 (Cv25519) subkey for encryption — in the widely compatible v4 format; RSA 3072 or 4096 keys are there for older software, and v6 keys from the current standard, RFC 9580, for software that supports it.

    The result is everything a key needs: the ASCII-armored public key to share, the private key protected with your passphrase, a revocation certificate for emergencies, the fingerprint and key ID, and the commands to import it all into GnuPG. Keys are generated by OpenPGP.js in a background worker on your device; nothing is uploaded or stored.

    How to use it

    1. Enter your name and e-mail address. Together they form the user ID people see when they import your key.
    2. Keep Curve25519 and v4 unless you have a reason not to: RSA only for software that cannot use Curve25519, v6 only if everyone you work with uses RFC 9580 software.
    3. Choose when the key expires — 2 years is a good default; you can extend it later with your private key.
    4. Enter a strong passphrase twice (or press Suggest a strong passphrase). It protects the private key file.
    5. Press Generate key pair, then download the three files: share the public key, keep the private key secret and backed up, and store the revocation certificate somewhere separate.

    Examples

    A key for encrypted e-mail
    Input
    Priya Sharma · [email protected] · Curve25519 · v4 · 2 years
    Result
    User ID “Priya Sharma <[email protected]>”, a 40-digit fingerprint such as 6213 DE3F 1010 19AF FEB9  5F56 E7A5 D3F2 C734 44B4, and priya-sharma_C73444B4_public.asc, _private.asc and _revocation.asc

    Import the private key into your mail program or GnuPG, and send the public key — or its fingerprint, to check it — to the people who will write to you.

    A v6 key (RFC 9580)
    Input
    The same, with Key format v6
    Result
    A 64-digit SHA-256 fingerprint and a private key protected with Argon2 and AEAD

    GnuPG 2.5.22 refuses such keys (“packet(6) with unknown version 6”); use v4 for anyone who uses GnuPG, Gpg4win or Kleopatra.

    Common uses

    • Setting up encrypted e-mail, or a key for people to send you confidential files.
    • Signing software releases, documents or Git commits so others can check they came from you.
    • Making a key on a computer where you cannot install GnuPG, for example a locked-down work laptop.
    • Creating test keys for developing or testing OpenPGP software.

    Curve25519 or RSA?

    Curve25519 keys are small and fast and give about 128-bit security; current OpenPGP software reads them — in our tests GnuPG 2.5.22 imported and used keys made here. RFC 9580 (§12.4) goes further: implementations “SHOULD NOT generate RSA keys” because the PKCS#1 v1.5 padding they use in OpenPGP is deprecated, and “MUST NOT generate RSA keys of a size less than 3072 bits”. So RSA is offered only at 3072 and 4096 bits, for software that cannot use Curve25519.

    v4 or v6?

    RFC 9580 replaced RFC 4880 and introduced v6 keys: fingerprints are SHA-256 (64 hex digits) instead of SHA-1 (40), the key ID is the first 8 bytes of the fingerprint instead of the last, Ed25519 and X25519 have their own algorithm IDs, and — as RFC 9580 §3.7.2 recommends — the private key here is protected with Argon2, which RFC 9580 uses only together with AEAD. GnuPG, however, follows the competing LibrePGP specification (librepgp.org) and does not read v6 keys. v4 keys work almost everywhere today; in our tests GnuPG 2.5.22 imported v4 keys made here and exchanged signed, encrypted messages with this tool.

    Keeping the key safe

    • The private key never leaves this tab until you download it. Store it — and a backup — where only you can reach it, and never send it to anyone.
    • The passphrase encrypts the private key file (iterated and salted S2K with AES-256 for v4, Argon2 for v6). Use four or more random words; without it the file alone is enough to impersonate you.
    • The revocation certificate tells others that the key must no longer be used. Keep it separate from the private key (for example printed, or on a USB stick): if the private key is lost or stolen, import it with gpg --import and publish the revoked public key. Anyone who has it can revoke your key, so protect it too.
    • The expiry date is a safety net if you lose both. Extend it in time with gpg --quick-set-expire <fingerprint> 2y for the primary key and gpg --quick-set-expire <fingerprint> 2y '*' for its subkeys — without the second command the encryption subkey still expires on the old date — then share the updated public key.

    Open-source software used

    Keys are made with OpenPGP.js 6.3.2 (openpgpjs.org), which is licensed under the GNU Lesser General Public License v3.0 or later. It is loaded as its own, unmodified file — licence header included — and runs in a background worker; its source code is available from the link above.

    Limitations

    • Keys are not uploaded to key servers — nothing leaves your device. Publish the public key yourself if you want others to find it.
    • One user ID per key. Add more e-mail addresses later with gpg --quick-add-uid.
    • The key has one encryption subkey; separate signing or authentication (SSH) subkeys can be added later in GnuPG.
    • Curve448 keys and smartcards or security keys (such as YubiKey) are not supported here.
    • A forgotten passphrase cannot be recovered — revoke the key with the revocation certificate and make a new one.

    Privacy

    Your name, e-mail address, passphrase and keys are processed only by OpenPGP.js in a background worker in this tab. Nothing is uploaded, logged or stored, and the keys are gone when you close the page — download them first.

    Frequently asked questions

    Is it safe to create a PGP key in a browser?

    The key is made on your device by OpenPGP.js using your browser’s cryptographically secure random number generator, and it is never sent anywhere. For keys that protect very valuable secrets, some people prefer to generate them on an offline computer; the format is the same either way.

    What is the revocation certificate for?

    If your private key is lost, stolen or its passphrase forgotten, importing the revocation certificate (gpg --import) and publishing the result tells everyone that the key must no longer be used. Make it now, while you still have the key, and keep it separate from the private key.

    Can I use the key in GnuPG, Gpg4win or Kleopatra?

    Yes, with v4 keys (the default): import the private key file with gpg --import (it asks for the passphrase). In our tests GnuPG 2.5.22 imported keys made here and decrypted and verified messages made with them. On import it warns that the key “contains preferences for unavailable algorithms” (digest algorithms 12 and 14, SHA3-256 and SHA3-512, which RFC 9580 added and GnuPG does not support). The key works anyway — GnuPG uses SHA-512 or SHA-256 instead — and gpg --edit-key <fingerprint> updpref save replaces the list with GnuPG’s own if you want the warning gone. v6 keys cannot be imported into GnuPG.

    What is the difference between the fingerprint and the key ID?

    The fingerprint is a hash of the public key — 40 hex digits for v4 keys (SHA-1), 64 for v6 (SHA-256) — and identifies the key reliably; compare it when you exchange keys. The key ID is a 16-digit part of it (the last 8 bytes for v4, the first 8 for v6), handy for display but not unique enough to rely on.

    Why should my key expire?

    An expiry date limits the damage if you lose the key and the revocation certificate: the key stops being accepted on its own. As long as you have the private key you can extend the date at any time, and people who refresh your key get the new date.

    Quick answers and tool search

    Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.