Toolprivacy

RSA Key Pair Generator

Generate RSA key pairs for encryption and decryption. Free RSA key generator with PEM export format.

Works Offline100% Free

Processed 100% locally in your browserPrivate & Safe

RSA Key Pair Generator runs entirely on your device using Web API standards. No data is ever uploaded to UtilixVerse servers.

Your Input
➔
Browser
➔
Result
No Server UploadsNo Account RequiredWorks OfflineZero Data Logging

Key Options

Key size (modulus)
Hash algorithm
Export format

PEM is human-readable text; DER is the raw binary encoding (openssl rsa -inform DER).

Click Generate to create a new RSA key pair locally.

Free RSA Key Pair Generator — Public & Private Keys in PEM

Welcome to the UtilixVerse RSA Key Pair Generator — a free, browser-based tool that creates RSA-OAEP public/private key pairs in standard PEM format. Choose 2048, 3072, or 4096 bits and a SHA-256 or SHA-512 hash, then copy or download the public key (SPKI) and private key (PKCS#8). Keys are generated 100% locally with the Web Crypto API — free, private, and offline.

How Public-Key Cryptography Works

The generator produces a matched pair: a public key you can hand out to anyone and a private key only you hold. A message encrypted with your public key can only be decrypted with your private key — which means anyone can safely send you secrets without ever knowing your private key. This is the foundation of TLS, SSH, PGP, and virtually all modern secure communication.

Interoperable Output

Keys are exported in the universal PEM format using standard DER encodings (PUBLIC KEY / PRIVATE KEY). They work directly with OpenSSL, Node.js, Python, Go, and countless other libraries — no conversion needed. The keys are generated with RSA-OAEP padding for encryption and decryption.

Who Uses This Tool

Developers bootstrapping encryption in their apps, DevOps engineers generating keys for services and CI, security researchers testing cryptographic flows, and students learning how asymmetric encryption works. No install, no sign-up, and your keys never leave your browser.

Frequently Asked Questions About RSA Key Generation

What is RSA and how does a key pair work?

RSA is a public-key cryptosystem based on the practical difficulty of factoring large numbers. A key pair consists of a public key, which you share with anyone, and a mathematically linked private key, which you keep secret. Data encrypted with the public key can only be decrypted with the private key, and vice versa. The keys are generated together locally in your browser; this tool exports them in standard PEM format (SPKI for the public key, PKCS#8 for the private key).

Which key size should I choose?

2048-bit keys are the current baseline and are accepted almost everywhere, but the U.S. National Institute of Standards and Technology (NIST) recommends moving to 3072-bit or larger for data meant to stay confidential beyond 2030. This tool offers 2048, 3072, and 4096 bits. Larger keys are slower to generate and use, so pick 3072 or 4096 for long-term secrets and 2048 for everyday use.

How are the keys generated?

Entirely in your browser with the Web Crypto API. The browser generates a cryptographically secure RSA-OAEP key pair using the operating system's secure random source. The private key never exists anywhere except your device — it is exported on request as a PEM file, but no copy is ever sent to a server or stored by this site.

How do I use these keys to encrypt something?

The public key can be shared with anyone who wants to send you a secret. Many tools accept PEM public keys directly — for example OpenSSL with "openssl pkeyutl -encrypt -pubin", SSH/PGP-style tools, or libraries like Node.js crypto. The private key must be kept on your device and used to decrypt. Keep them together with a note about which is which, and protect the private key file.

What are the differences between RSA-OAEP and other RSA schemes?

RSA can be used for encryption (RSA-OAEP) or digital signatures (RSA-PSS). This tool generates keys usable for encryption/decryption with OAEP padding, which is the modern, provably secure padding scheme. RSA-OAEP keys use a hash (SHA-256 or SHA-512) for the OAEP label. The PEM output is fully standard, so it interoperates with OpenSSL, Python, Node.js, and most other crypto toolkits.

Is the private key encrypted with a password?

No — the browser's Web Crypto API can only export keys in unencrypted PKCS#8 form, so the private key file is not password-protected. If you need encryption at rest, protect the PEM file yourself (for example, with a password-protected archive or a hardware key), or combine this tool with this site's Local File Encryption tool before storing or sending it.

Is this RSA generator free and private?

Yes — completely free, no registration, and 100% private. Keys are generated locally in your browser using the Web Crypto API and are never transmitted anywhere. The tool works offline after the page loads.

Keep UtilixVerse Free

One-time contribution for hosting & new tools

Donate

Missing a Tool? Request It

Suggest new utilities or report bugs

Request Tool