>_devtools

RSA, EC & Ed25519 Key Pair Generator

Generate RSA (2048-4096), EC (P-256, P-384, P-521), and Ed25519 key pairs in your browser, exported as PEM (PKCS#8, PKCS#1, SEC1, SPKI) and JWK.

What this does

Generates an asymmetric key pair with your browser's WebCrypto implementation and shows it as PEM and JWK. The random numbers come from the browser's cryptographically secure generator, the same one behind HTTPS, and nothing is sent anywhere.

Choosing a key type

  • EC P-256 is a good default: small keys, fast, supported by TLS, JWT (ES256), and SSH tooling.
  • RSA 2048 or 3072 is the compatibility choice (RS256, PS256, older TLS and signing stacks). 4096 bits is slower to generate and use with little practical gain over 3072.
  • Ed25519 gives compact, fast signatures (EdDSA). Support in browsers and libraries is broad but not universal; if generation fails, your browser does not offer it yet.
  • For RSA choose the algorithm family up front: PKCS#1 v1.5 signatures (RS256/384/512), PSS signatures (PS256/384/512), or OAEP encryption. It decides the alg written to the JWK.

Formats you get

The private key is PKCS#8 (BEGIN PRIVATE KEY), which works for every key type, and can be switched to PKCS#1 for RSA (BEGIN RSA PRIVATE KEY) or SEC1 for EC (BEGIN EC PRIVATE KEY). The public key is SPKI (BEGIN PUBLIC KEY), or PKCS#1 for RSA. The JWK view adds use, alg, and a kid equal to the RFC 7638 thumbprint, and offers a ready-to-publish public JWKS.

Handling the private key

The key exists only in this tab. Reloading or leaving the page discards it, and it is never saved, logged, or placed in the URL. Anything you generate on a web page is only as trustworthy as the page and the browser it runs in, so for long-lived production keys prefer a KMS, an HSM, oropenssl on a machine you control. Test the result with thesign and verify tool or inspect it in thePEM parser.