Generate RSA public/private key pairs for encryption
RSA Key Pair Generator
Generate RSA public/private key pairs for encryption
Recommended for most applications
4096-bit keys take noticeably longer to generate in a browser — that's expected
2048-bit RSA generates in under a second for most browsers. 4096-bit can take 5 to 15 seconds because RSA key generation involves finding large prime numbers, which is computationally expensive. The page isn't frozen; it's working. For almost all practical purposes in 2025, 2048-bit is the correct choice — it's the current NIST recommendation, it's what most TLS certificates use, and it's what SSH defaults to. The advantage of 4096-bit is a larger security margin if you expect the key to be used for decades or if you're operating in a context with very long-term confidentiality requirements. The performance cost matters most in signing operations, where 4096-bit RSA is about 4× slower than 2048-bit. For key exchange where you're wrapping a short AES key, the practical difference is negligible.
The private key never leaves your browser during generation
RSA key generation uses the Web Crypto API entirely client-side. The private key appears in the output box and you download or copy it from there; no server receives it at any point. That's the right behavior — a private key that touches a third-party server during generation is not fully private. If you're generating keys for real use, download both immediately and store the private key in a place only you control: encrypted at rest, backed up in a second offline location. Never paste a private key into a web form again after this point, not even on this site. The PEM format makes it obvious what you're looking at — the private key block starts with -----BEGIN RSA PRIVATE KEY----- or -----BEGIN PRIVATE KEY----- depending on whether you chose PKCS#1 or PKCS#8 format.
