RSA key pair generator
Generate 2048 / 3072 / 4096-bit RSA key pairs with the built-in WebCrypto API and export the PKCS#8 private key and SPKI public key as PEM.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
Click “Generate key pair” to produce the public and private key
Usage notes
- Keep the private key secret: anyone who has it can decrypt data or forge signatures.
- The public key can be shared freely — it encrypts data and verifies signatures.
- Use RSA-OAEP for encryption/decryption and RSASSA-PKCS1-v1_5 for signing/verifying. The exported PEM fits straight into a .pem file.
- Keys are generated locally in your browser and never uploaded.
What this tool does
- Generate an RSA key pair locally for self-signed JWTs, encrypted API tests, or an internal service that needs a matching public/private pair — without handing the private key to an online generator.
- The PEM output drops straight into a .pem file, a service config, or Node’s crypto.createPrivateKey: a standard PKCS#8 private key and SPKI public key.
- Work around compatibility questions such as whether the other side expects RSA-OAEP or RSASSA-PKCS1-v1_5 — just regenerate with the right algorithm.
- Prepare key material on an offline or air-gapped machine: open the page and generate, no openssl install required.
Example
Input
Algorithm RSA-OAEP, key size 2048 bit, hash SHA-256, then press "Generate key pair"
Output
-----BEGIN PUBLIC KEY-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA…
(7 Base64 lines of 64 characters)
-----END PUBLIC KEY-----
{{PRIVATE_KEY_zgsljo2e}}The key material is random, so the Base64 differs on every run, but the fixed shape of a 2048-bit RSA key does not: the public key starts with MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A and wraps to 7 lines, the private key starts with MIIEvwIBADANBgkqhkiG9w0BAQEFAASCBK and wraps to 26 lines, both at 64 characters per line with a trailing newline.
Frequently asked questions
Are the generated keys uploaded anywhere?
No. The pair is created locally by the browser WebCrypto API (crypto.subtle.generateKey); the page makes no network requests and works offline. The only way the private key leaks is if you copy it somewhere yourself.
Should I pick 2048, 3072 or 4096 bits?
2048 bits meets current mainstream requirements and has the best compatibility. 3072 and 4096 are more resistant to future computing power but take seconds to tens of seconds longer to generate and are slower to sign with. Without a specific compliance requirement, 2048 is the right default.
What is the difference between RSA-OAEP and RSASSA-PKCS1-v1_5?
RSA-OAEP is an encryption algorithm, so the resulting key can only encrypt and decrypt. RSASSA-PKCS1-v1_5 is a signature algorithm, so the key can only sign and verify. WebCrypto fixes the key usages at generation time, so picking the wrong one makes the other side fail immediately and you have to regenerate.
Why does it say WebCrypto is not available?
Browsers only expose crypto.subtle on https or localhost pages, so opening the tool over plain http on a LAN IP — or using an outdated browser — leaves that API undefined. Switch to https or run it locally.
Can I recover the private key after closing the page?
No. There is no backup mechanism: refreshing the page or pressing Clear discards it. Save the private key to a keystore or an encrypted file right after generating it.
Keywords:rsa密钥对key pairwebcryptopempkcs8spki公钥私钥非对称加密