RSA Key Pair Generator
RSA key pairs in every format — PEM, JWK, SSH — made in your browser, self-tested.
Your key pair
Check the key with OpenSSL or ssh-keygen
About the RSA Key Pair Generator
Create an RSA key pair for signing — RS256 or PS256 JWTs, code signing, SSH — or for encryption with RSA-OAEP, using your browser’s Web Crypto key generator. Every key comes in the formats tools ask for: PKCS#8 (BEGIN PRIVATE KEY) and PKCS#1 (BEGIN RSA PRIVATE KEY) private keys, SubjectPublicKeyInfo (BEGIN PUBLIC KEY) and PKCS#1 public keys, a passphrase-protected encrypted PKCS#8 copy (PBES2 with AES-256), JWK and JWKS with an RFC 7638 thumbprint as kid, and an OpenSSH ssh-rsa public key with its SHA256 fingerprint.
Each new key is used once — a test signature or encryption — before it is shown, and the formats are checked against OpenSSL and ssh-keygen in this tool’s tests. Key-size advice follows NIST SP 800-57. The keys exist only in this tab: nothing is uploaded or stored.
How to use it
- Choose the size. 3072-bit is the recommended default for new keys; 2048-bit where a system requires it; 4096-bit for extra margin.
- Choose what the key is for. It sets the JWK
algand the self-test; the key material itself works with any RSA algorithm. - Optionally enter a comment for the SSH public key, and a passphrase to get an encrypted copy of the private key.
- Press Generate key pair. A 4096-bit key can take several seconds — the page stays usable meanwhile.
- Copy or download each format, or Download all (.zip). Keep the private key secret; give out only the public key or JWK.
Examples
3072-bit · comment deploy@ci
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQ… deploy@ci
Put the line in the server’s ~/.ssh/authorized_keys. Save private.pem as ~/.ssh/id_rsa — or under another name, such as ~/.ssh/id_rsa_deploy used with ssh -i, if you already have a key there — and run chmod 600 on it: OpenSSH reads PKCS#8 and PKCS#1 key files directly (checked with ssh-keygen 10.3). ssh-keygen -p -f ~/.ssh/id_rsa adds a passphrase and rewrites it in OpenSSH’s own format.
2048-bit · Signing · RS256 · JWK alg, use and kid on
{"kty":"RSA","n":"…","e":"AQAB","alg":"RS256","use":"sig","kid":"<RFC 7638 thumbprint>"}Publish jwks.json at your JWKS URL; sign tokens with private.pem in the JWT Encoder and check them in the JWT Decoder.
openssl pkey -in private-encrypted.pem -check -noout
Enter pass phrase for private-encrypted.pem: … Key is valid
Common uses
- Creating RS256 or PS256 keys and a JWKS for testing JWT authentication.
- Making an RSA SSH key on a computer without ssh-keygen, or for systems that still require RSA.
- Generating test keys for TLS, SAML, webhook signatures or RSA-OAEP encryption code, in the exact format a library expects.
- Getting a key’s fingerprints — SSH SHA256, JWK thumbprint, SPKI SHA-256 pin — to match keys between systems.
Which key size?
NIST SP 800-57 Part 1 Rev. 5 (Table 2) rates RSA-2048 at 112-bit security and RSA-3072 at 128-bit; 7680-bit gives 192-bit. Its Table 4 makes 112-bit strength acceptable for protecting new data through 2030; from 2031 it is disallowed for new signatures and encryption and allowed only for processing data protected earlier (verifying, decrypting: “legacy use”), while 128-bit and above stay acceptable after 2030. So:
- 3072-bit — the default here: 128-bit security for keys that must last beyond 2030.
- 2048-bit — still widely required (many certificate authorities and older devices); fine for short-lived or test keys.
- 4096-bit — more margin than 3072-bit, at the cost of slower signing and generation and larger signatures.
NIST also notes that these estimates will change once quantum computers become practical. For new designs, elliptic-curve keys give 128-bit security in a fraction of the size — see the EC key generator.
The formats
- PKCS#8 PEM (
BEGIN PRIVATE KEY, RFC 5958): the modern private-key wrapper read by OpenSSL, Java, .NET, Node.js, Go and Web Crypto. - PKCS#1 PEM (
BEGIN RSA PRIVATE KEY/BEGIN RSA PUBLIC KEY, RFC 8017): the older RSA-only form that some tools still expect. - Encrypted PKCS#8 (
BEGIN ENCRYPTED PRIVATE KEY): PBES2 (RFC 8018) with PBKDF2-HMAC-SHA256 at 600,000 iterations — the OWASP figure — and AES-256-CBC: the schemeopenssl pkcs8 -topk8 -v2 aes-256-cbcwrites (OpenSSL itself uses 2,048 iterations unless told otherwise). - SubjectPublicKeyInfo PEM (
BEGIN PUBLIC KEY, RFC 5280): the usual public-key format. - JWK / JWKS (RFC 7517, RFC 7518): with optional
alg,useandkid= the RFC 7638 thumbprint. - OpenSSH (
ssh-rsa, RFC 4253): the one-line public key for authorized_keys, with the SHA256 fingerprint asssh-keygen -lshows it.
One key, one purpose
An RSA key pair is the same whether it is used for PKCS#1 v1.5 signatures, PSS signatures or OAEP encryption — the choice here only labels the JWK and picks the self-test. NIST SP 800-57 (§5.2) says that “in general, a single key shall be used for only one purpose”, so make separate keys for signing and for encryption. The public exponent is always 65537, the standard value.
Limitations
- The private key is not offered in OpenSSH’s own file format (
BEGIN OPENSSH PRIVATE KEY); OpenSSH reads the PEM files, andssh-keygen -p -f <file>converts one while adding a passphrase. - No certificate signing requests (CSRs) or certificates — this tool makes key pairs only.
- Keys come from your browser’s Web Crypto generator. For long-lived production keys, many teams prefer to generate them on the machine — or in the HSM or cloud KMS — that will use them, so the private key never exists anywhere else.
- 4096-bit keys can take several seconds to generate, depending on the browser and device.
Privacy
Keys are generated by your browser’s Web Crypto API and exist only in this tab: nothing is uploaded, logged or stored, and they are gone when you close the page or press Reset — download what you need first.
Frequently asked questions
Is it safe to generate an RSA key in a browser?
The key is made by your browser’s built-in Web Crypto API, with the browser’s own cryptographic library and random number generator, and it never leaves this tab. For production keys that will live for years, generating them where they are used (a server, an HSM, a cloud KMS) avoids ever having the private key on another device.
Which size should I choose: 2048, 3072 or 4096?
3072-bit for new keys that should stay acceptable after 2030 (128-bit security by NIST SP 800-57). Use 2048-bit only where a system or certificate authority requires it, and 4096-bit if you want extra margin and can accept slower operations.
What is the difference between “BEGIN PRIVATE KEY” and “BEGIN RSA PRIVATE KEY”?
Both hold the same key. BEGIN PRIVATE KEY is PKCS#8, the algorithm-neutral wrapper that almost every library reads; BEGIN RSA PRIVATE KEY is PKCS#1, the older RSA-only structure. Use PKCS#8 unless a tool asks for PKCS#1.
How do I use the passphrase-protected key?
Most software asks for the passphrase when it loads private-encrypted.pem — OpenSSL (openssl pkey -in private-encrypted.pem), Node.js (crypto.createPrivateKey({ key, passphrase })), Java and .NET. A forgotten passphrase cannot be recovered, so keep it in a password manager.
Why does the self-test matter?
It proves the pair works before you rely on it: the new private key signs (or decrypts) a test message and the public key verifies (or encrypts) it, using the algorithm you chose. If anything went wrong, you would see an error instead of keys.