AnkhKit

RSA Key Pair Generator Online (PEM) — Free

Runs 100% in your browser — your files never leave your device.

SSH configs, JWT signing, TLS experiments — sometimes you just need an RSA key pair without installing OpenSSL. Choose a key size, click generate, and copy the SPKI public key and PKCS#8 private key in standard PEM format. Your browser's native WebCrypto does the work; the private key never leaves the tab.

How it works

  1. 1

    Pick a key size

    1024, 2048, or 4096 bits — 2048 is the safe default.

  2. 2

    Generate the pair

    Keygen runs in your browser via WebCrypto; larger keys take a moment.

  3. 3

    Copy both PEM keys

    Public and private keys come out in standard PEM blocks, ready to paste.

About this tool

What the pair is

RSA is asymmetric cryptography: a public key that anyone may hold and use to encrypt messages or verify signatures, and a private key that must never leave your possession. The tool generates both together — they are mathematically linked, and the link is the security.

Key size is the security budget

2048 bits is the current minimum for real use; 4096 buys margin at the cost of slower operations. Larger keys are exponentially harder to factor — the entire security of RSA rests on the difficulty of that factoring, which is why key size matters more than any other setting.

Guard the private half

Publish the public key freely, protect the private key absolutely: anyone holding it can decrypt everything encrypted to you and sign as you. Generate on-device (this tool computes locally — the keys never cross a network) and store the private half encrypted.

Frequently asked questions

Can I encrypt with the private key and decrypt with the public one?

That operation is signing — it proves origin rather than providing secrecy. Encryption flows the other way: public encrypts, private decrypts.

Which key size should I choose?

2048 for compatibility and speed, 4096 when long-term secrecy matters more than performance. Both are considered secure today; 1024 is broken and exists here only for legacy verification.

Are the keys generated on my device?

Yes — key generation runs entirely in your browser from local randomness. The private key is never transmitted, stored, or logged.

More crypto & security