Developer tool / 23
RSA & ECDSA Key Pair Generator
Generate RSA (2048/4096-bit) or ECDSA public and private key pairs in PEM format using browser Web Crypto API.
RSA & ECDSA Key Pair Generator: TOEA uses the browser's Web Crypto API to generate cryptographically secure key pairs and exports SPKI public keys and PKCS#8 private keys formatted in standard PEM headers. Runs 100% locally in your browser with zero server file uploads.
- Category
- Developer tools
- Runs
- In your browser
- Cost
- Free · no sign-up
- Availability
- Ready to use
Which key type to pick
The keys are made for signing: the RSA options produce the kind of key JWT calls RS256, and ECDSA P-256 and P-384 match ES256 and ES384. A P-256 key is far smaller than an RSA key and roughly as strong as RSA at 3072 bits, so choose it when the system that will use the key supports it. RSA 2048 is still the most widely accepted choice; 4096 buys margin at the cost of slower signing.
PEM formats and where they fit
The public key is SPKI (BEGIN PUBLIC KEY) and the private key is PKCS#8 (BEGIN PRIVATE KEY), which OpenSSL, Node, Java, and most JWT libraries read directly. Older software that wants BEGIN RSA PRIVATE KEY can be given one with openssl rsa -in key.pem -traditional.
These are not SSH keys: authorized_keys expects the ssh-rsa or ssh-ed25519 format, which ssh-keygen creates on your own machine. The private key here is also unencrypted; to store it with a passphrase, run openssl pkey -in key.pem -aes256 -out key-encrypted.pem.
How to use it
- Choose key algorithm (RSA 2048/4096, ECDSA P-256/P-384).
- Click Generate Key Pair.
- Copy or download the public and private PEM keys.
Privacy & limitations
Keys are generated 100% locally in your browser memory and are never transmitted over the network.
Related tools
Frequently asked questions
Are generated private keys safe?
Yes, keys are generated using Web Crypto API inside your browser and never touch any server.
Free tool · runs in your browser · no account required