About the RSA Key Generator
The key pair is generated by your browser's Web Crypto API (crypto.subtle.generateKey), the same native implementation that secures HTTPS connections, using the operating system's random source. The private key never leaves the page: there is no upload and nothing is stored. RSA keys come in 2048, 3072 or 4096 bits with the public exponent 65537; 2048 bits is the current minimum, 3072 bits matches 128-bit security. ECDSA keys on P-256, P-384 or P-521 and Ed25519 keys are much smaller and faster for the same strength.
The private key is exported as PKCS#8 (-----BEGIN PRIVATE KEY-----) and the public key as SubjectPublicKeyInfo (-----BEGIN PUBLIC KEY-----), the unencrypted PEM formats read by OpenSSL, Node.js, Java, Go, Python and most JWT libraries. PEM is the Base64 of the DER structure in lines of 64 characters. The same keys are shown as JWK (RFC 7517), the JSON form used by JWKS endpoints and OAuth / OpenID Connect; the chosen use and hash end up in its alg and key_ops fields.
The fingerprint is the SHA-256 digest of the public key in DER form, so you can compare it with openssl pkey -pubin -in public.pem -outform DER | openssl dgst -sha256. Choose RSASSA-PKCS1-v1_5 for RS256-style JWT signatures and the widest compatibility, RSA-PSS for the newer signature padding (PS256), and RSA-OAEP for encrypting small payloads or wrapping keys. The PEM files are not password-protected: keep the private key out of version control and encrypt it if it must be stored.
How to use it
- Choose RSA, ECDSA or Ed25519.
- For RSA pick the size, the use (signing or encryption) and the hash; for ECDSA pick the curve.
- Click Generate: 4096-bit RSA keys can take a few seconds.
- Copy or download private.pem and public.pem, or the JWK versions.