Generate RSA, ECDSA, ECDH and Ed25519 key pairs in your browser and export them as PEM (PKCS#8 / SPKI) or JWK. Set key length, exponent, hash or curve. Keys are created with the browser's Web Crypto API and are never sent to a server. Useful for testing JWT signing, encryption and signature code.
Public-key (asymmetric) cryptography uses a pair of keys: a public key that you can share, and a private key that you keep secret. The private key signs or decrypts; the public key verifies or encrypts. This tool creates such key pairs with the browser's Web Crypto API and shows both keys in PEM or JWK format, ready to copy or download.
publickey.pem / privatekey.pem, or .json for JWK).| Algorithm | Purpose | Options |
|---|---|---|
| RSASSA-PKCS1-v1_5 | Signatures (JWT RS256/384/512) | Modulus length, exponent 3 or 65537, SHA-256/384/512 |
| RSA-PSS | Signatures (JWT PS256/384/512) | Same as above |
| RSA-OAEP | Encryption | Same as above |
| ECDSA | Signatures (JWT ES256/384/512) | P-256, P-384, P-521 |
| ECDH | Key agreement | P-256, P-384, P-521 |
| Ed25519 | Signatures | None (requires a recent browser) |
BEGIN PRIVATE KEY), public key as SPKI (BEGIN PUBLIC KEY)key_ops, and alg for RSA keys)For signatures, ECDSA P-256 or Ed25519 give small keys and fast operations; RSA 2048 or larger offers the widest compatibility. Use RSA-OAEP when you need to encrypt small pieces of data with a public key, and ECDH to derive a shared secret between two parties. The Hash option for RSA is part of the key's intended algorithm (it appears in the JWK alg), not part of the key material itself.
No. Keys are generated in your browser and not transmitted. However, the last generated key pair is saved in this browser's storage so it is still shown next time. For production keys, generate them on a trusted machine and click Regenerate afterwards if you share the device.
No. The output is PEM (PKCS#8 / SPKI) or JWK. Convert it with ssh-keygen -i -m PKCS8 -f publickey.pem if you need the OpenSSH public key format.
RSA keys require finding large random primes. 2048-bit keys are usually quick, but 8192 bits and above can take several seconds, and the browser may refuse very large sizes.
Ed25519 support in Web Crypto is relatively new. Update your browser or use ECDSA instead.