Public-Key Generator

Generate RSA, ECDSA, ECDH and Ed25519 key pairs in your browser and export them as PEM (PKCS#8 / SPKI) or JWK. Set key length, exponent, hash or curve. Keys are created with the browser's Web Crypto API and are never sent to a server. Useful for testing JWT signing, encryption and signature code.

About this tool

What does the Public-Key Generator do?

Public-key (asymmetric) cryptography uses a pair of keys: a public key that you can share, and a private key that you keep secret. The private key signs or decrypts; the public key verifies or encrypts. This tool creates such key pairs with the browser's Web Crypto API and shows both keys in PEM or JWK format, ready to copy or download.

How to use

  1. Choose an Algorithm. A key pair is generated immediately.
  2. Adjust the options for that algorithm: Public exponent, Hash and Modulus length (bits) for RSA, or Named curve for ECDSA/ECDH. A new key pair is generated whenever these change.
  3. Choose the Format (PEM or JWK). Switching format converts the current key pair instead of creating a new one.
  4. Copy or download the Public key and Private key with the buttons in each editor (publickey.pem / privatekey.pem, or .json for JWK).
  5. Click Regenerate to create another key pair with the same settings.

Supported algorithms

AlgorithmPurposeOptions
RSASSA-PKCS1-v1_5Signatures (JWT RS256/384/512)Modulus length, exponent 3 or 65537, SHA-256/384/512
RSA-PSSSignatures (JWT PS256/384/512)Same as above
RSA-OAEPEncryptionSame as above
ECDSASignatures (JWT ES256/384/512)P-256, P-384, P-521
ECDHKey agreementP-256, P-384, P-521
Ed25519SignaturesNone (requires a recent browser)

Features

  • Six Web Crypto algorithms for signing, encryption and key agreement
  • RSA modulus length from 512 to 16384 bits in multiples of 8 (2048 is the default; 2048 or more is recommended)
  • PEM output: private key as PKCS#8 (BEGIN PRIVATE KEY), public key as SPKI (BEGIN PUBLIC KEY)
  • JWK output (the browser includes key_ops, and alg for RSA keys)
  • Format conversion between PEM and JWK for the current key pair
  • The keys work directly in the JWT tool for signing (private key) and verifying (public key)

Choosing an algorithm

For signatures, ECDSA P-256 or Ed25519 give small keys and fast operations; RSA 2048 or larger offers the widest compatibility. Use RSA-OAEP when you need to encrypt small pieces of data with a public key, and ECDH to derive a shared secret between two parties. The Hash option for RSA is part of the key's intended algorithm (it appears in the JWK alg), not part of the key material itself.

FAQ

Are the keys generated on a server?

No. Keys are generated in your browser and not transmitted. However, the last generated key pair is saved in this browser's storage so it is still shown next time. For production keys, generate them on a trusted machine and click Regenerate afterwards if you share the device.

Can I get an OpenSSH key (ssh-rsa / ssh-ed25519)?

No. The output is PEM (PKCS#8 / SPKI) or JWK. Convert it with ssh-keygen -i -m PKCS8 -f publickey.pem if you need the OpenSSH public key format.

Why does RSA generation take a moment?

RSA keys require finding large random primes. 2048-bit keys are usually quick, but 8192 bits and above can take several seconds, and the browser may refuse very large sizes.

Ed25519 shows an error. Why?

Ed25519 support in Web Crypto is relatively new. Update your browser or use ECDSA instead.