Free Online RSA Key Pair Generator with PEM, JWK and Fingerprints
Generate an RSA key pair in your browser with Web Crypto, at 2048, 3072 or 4096 bit. The public key comes out as PEM, as JWK and as an OpenSSH line, the private key as PKCS8 PEM, and both the OpenSSL and the ssh-keygen style SHA-256 fingerprints are worked out for you.
Free Forever Nothing Uploaded Generated In The Tab Private Key Hidden
Share this tool
Advertisement Slot (Top Banner)Google AdSense Unit • Responsive Banner
RSA Key Pair Generator Everything happens in this tab. Nothing you paste is sent anywhere.
Your key pair
Choose a size and press Generate. Nothing is sent anywhere, and nothing is kept
after you close the tab.
SHA-256 of the public key in DER, the openssl figure
SHA-256 of the SSH wire format, the ssh-keygen figure
Export
Key
Export
Buy Us A Coffee
Enjoying WizTools123? Help keep our server infrastructure
100% free and open for everyone.
One key, two correct answers, and neither tool is wrong.
Ask openssl for the fingerprint of a public key and you get a string of hex. Ask
ssh-keygen about the same key and you get something that starts SHA256: and
looks like base64. People reasonably conclude that one of the two is broken. Both are
right, and the reason is that a fingerprint is a hash of a particular encoding, not of
the key itself.
The openssl figure hashes the DER. A public key written as PEM is base64 around
a DER structure called SubjectPublicKeyInfo, which wraps the algorithm identifier and
the key material together. Hashing those DER bytes with SHA-256 and printing the
result as hex is what you get from piping a key through
openssl pkey -pubin -outform DER into a digest.
The ssh-keygen figure hashes the SSH wire format. SSH does not use DER. It uses
its own packing: the string ssh-rsa, then the exponent, then the modulus,
each preceded by a four byte big endian length. That is the blob inside an
authorized_keys line, and SHA-256 of it, printed as base64 with the
padding removed, is the SHA256: value.
Which one you need depends on who is asking. A server telling you the host key
fingerprint, or a ssh-add -l listing, means the SSH one. A certificate
authority, a code signing process or a colleague comparing PEM files usually means the
DER one. Both are shown here so that whichever you are handed, you can match it
without converting anything.
Older tools print an MD5 fingerprint with colons. If what you have been given
looks like sixteen pairs of hex separated by colons and no SHA256: prefix,
it is the old MD5 format that OpenSSH used before version 6.8. This page does not
produce that, deliberately: comparing keys by MD5 is not something worth making easier.
How to Generate an RSA Key Pair
A few steps, and nothing is uploaded.
1
Pick a size and what the key is forUse 2048 bit unless you have been told otherwise, and choose signing or encryption. The choice is recorded in the key, so a key generated for encryption cannot be used to sign.
2
Press Generate and wait a momentA 4096 bit key can take several seconds, because the browser is hunting for large primes. The page tells you how long it took, which is a useful sanity check that real work happened.
3
Read the fingerprintsBoth SHA-256 fingerprints appear: the one openssl gives for the DER, and the one ssh-keygen gives for the SSH wire format. Compare whichever matches the tool that is asking.
4
Choose an export and copy itPublic key as PEM, as JWK or as a single OpenSSH line, private key as PKCS8 PEM or JWK. The private exports stay blanked until you press Show, so the key does not appear in a screen share by accident.
What to Know About These Keys
Including when not to use a key a web page made.
A key a web page generated is a test key, and should be treated as one. The arithmetic is Web Crypto, the same code that runs HTTPS in your browser, so the key itself is sound. What is not sound is the journey: it existed in a tab, next to extensions and whatever else the machine is running, and it passed through a clipboard. For a fixture, a demo or a staging environment that is fine. For a key that protects something real, generate it where it will live, with ssh-keygen or openssl, and never paste a private key into a browser.
This page cannot give you a PKCS1 PEM, the kind that begins BEGIN RSA PRIVATE KEY. Web Crypto exports exactly two binary formats, PKCS8 for private keys and SPKI for public keys, and it has no PKCS1 encoder. Nearly everything modern reads PKCS8, and the two are one openssl command apart if you are stuck with something old. The page shows PKCS8 rather than pretending to offer a choice it does not have.
The OpenSSH line here is a public key only, and there is no OpenSSH private key format. The ssh-rsa line is built by hand from the modulus and the exponent, so you can paste it into authorized_keys. The matching private key is offered as PKCS8 PEM, which recent OpenSSH will read, but the modern openssh-key-v1 private format is not something this page produces.
Nothing is remembered, and there is no way to get a key back once the tab is closed. There is no history and no saved setup on this page, deliberately: a private key in browser storage is exactly the thing that gets found later by something else. Copy what you need while it is on screen, because closing the tab is the whole of the cleanup.
Key Features & Capabilities
What this tool does, and what it deliberately does not.
Three sizes2048, 3072 and 4096 bit, generated by Web Crypto with a public exponent of 65537.
PEM and JWKSPKI PEM and PKCS8 PEM, wrapped at 64 columns, plus the JWK form of each key.
An OpenSSH lineA complete ssh-rsa line, built from the wire format, ready for authorized_keys.
Both fingerprintsThe openssl DER figure in hex and the ssh-keygen figure in base64, side by side.
Private key hiddenPrivate exports stay blanked until you press Show, so nothing leaks into a screen share.
Nothing rememberedNo history and no saved setups. A private key never reaches browser storage.
About RSA Keys in a Browser
An RSA key pair is two numbers that share a modulus: one that anybody may hold and one that nobody else may. Generating a pair is not a formatting exercise, it is a search for two large primes, which is why a 4096 bit key takes noticeably longer than a 2048 bit one and why the time taken is printed on this page. The search happens in Web Crypto, the browser own cryptographic implementation, which is the same code path that negotiates the HTTPS connection you are reading this over.
The awkward part of a key pair is never the key, it is the encodings. The same public key is a DER structure inside a PEM envelope, a JSON object with two base64url numbers in it, and a length prefixed binary blob in an authorized_keys line, and each of those has its own fingerprint. This page produces all three from one generated key and shows both SHA-256 fingerprints, because the usual reason someone reaches for a tool like this is that two programs are disagreeing about what the same key is called.
The OpenSSH line is built here by hand rather than by a library, because the format is three pieces: the string ssh-rsa, the public exponent and the modulus, each written with a four byte big endian length in front of it, with a leading zero byte added wherever the top bit would otherwise read as a negative number. That is the whole specification, it needs no dependency, and writing it out is a better use of twenty lines than shipping a megabyte of someone else code.
What the page will not do is pretend that a key made in a tab is a key for production. Web Crypto gives you sound arithmetic, not a sound custody chain, and a private key that has been in a clipboard has been somewhere you cannot audit. Use this for fixtures, for a staging server, for testing a signature path or for comparing a fingerprint. For the key that guards something that matters, use ssh-keygen or openssl on the machine where the key belongs.
Frequently Asked Questions
Sizes, formats, fingerprints and what a browser can export.
2048 bit, unless something has told you otherwise. It is still the common default and is considered sound for general use. 3072 bit is the usual step up when a policy asks for more, and 4096 bit costs noticeably more time to generate and to use for little practical gain. If you need small and fast, the real answer is an elliptic curve key rather than a bigger RSA one.
Because a fingerprint is a hash of an encoding, and openssl and ssh-keygen hash different encodings of the same key. openssl hashes the DER bytes of the public key and prints hex, while ssh-keygen hashes the SSH wire format and prints base64 after SHA256:. Both are shown here so you can match whichever one you have been given.
Not from here. That is PKCS1, and Web Crypto only exports PKCS8 for private keys, which begins BEGIN PRIVATE KEY. Almost everything current reads PKCS8, and if you genuinely need the older form, one openssl command converts it. The page shows what it can actually produce rather than offering a format it would have to fake.
Because Web Crypto ties a key to its purpose when it is created, so a key generated for RSA-OAEP cannot be used to sign and a key generated for signing cannot decrypt. The hash is bound in the same way. Inside the exported PEM the key material is the same either way, but matching the use here keeps the key usable on the page that will consume it.
No. The key pair is generated by your browser, the PEM wrapping and the SSH line are built in the page, and the fingerprints are hashed locally, with no request made. There is also no history and no saved setup here, so nothing is written to browser storage either.
Every Other Security Tool
10 more tools in this set. All free, all in your browser.