🗝

RSA / EC Keypair Generator

Generate RSA (2048/4096), elliptic-curve (P-256/P-384) and Ed25519 keypairs with the Web Crypto API, and export them as PEM. Keys are generated and stay entirely in your browser.

Generate an RSA 2048 keypair

Generate a fresh RSA-2048 keypair and export both the public and private keys as PEM blocks.

For the example this picks RSA-2048, but in practice a minimum of 4096 bits (or an elliptic-curve key) is a strong default for most needs.

FAQ

RSA vs ECC vs Ed25519 — which should I choose?

Ed25519 and elliptic-curve (P-256) keys are smaller and faster than RSA at comparable security. Use RSA only when a system requires it; otherwise prefer Ed25519 or ECDSA.

Is it safe to generate keys in a browser?

The keys are created by your browser’s Web Crypto API from operating-system entropy and never leave your device. Just make sure you download or copy them before leaving the page — nothing is stored.

How should I store the private key?

Keep it encrypted at rest (a file encrypted with AES here works), back it up in a safe place, and never paste it into chats, code, or logs. Anyone with the private key can impersonate you.

What are these PEM formats?

The public key is exported as SPKI (“BEGIN PUBLIC KEY”) and the private key as PKCS#8 (“BEGIN PRIVATE KEY”) — standard formats accepted by OpenSSL, TLS servers and most tooling.

Updated 2026-08-10 · Runs in your browser — your data never leaves this page unless the tool explicitly says it makes a network check.