What Is an RSA Key Pair, and What Is It Used For?
RSA is the most widely used algorithm in the asymmetric (public-key) encryption family. Unlike symmetric encryption (one secret key that both encrypts and decrypts), RSA generates two separate keys that are mathematically linked but serve different roles: the <strong>public key</strong> (can be freely shared with anyone, used to encrypt data or verify a signature) and the <strong>private key</strong> (must stay only with you, used to decrypt data or create a signature). Computing the private key back from the public key isn't feasible in a reasonable amount of time with today's computers — this relies on the difficulty of factoring very large numbers into their prime factors.
What does key length (bits) mean? The bit length determines the size of the prime numbers underlying the key, and therefore how hard the key is to break (factor). 2048 bits is still widely accepted as the minimum secure length today and generates quickly; 3072 bits is for longer-term security needs; 4096 bits provides the highest security but is noticeably slower to generate (and for every encryption/signing operation).
The generated keys are presented in a text-based format called <strong>PEM</strong> — base64-encoded and wrapped with header/footer lines (<code>-----BEGIN …-----</code>/<code>-----END …-----</code>) — the standard format used for SSH, TLS certificates, email signing (S/MIME), JWT signing, and key exchange in many APIs. The public key is encoded as <strong>SPKI</strong> (SubjectPublicKeyInfo), the private key as <strong>PKCS8</strong> — both are standard formats that common libraries (OpenSSL, Node.js crypto, Python cryptography, etc.) can read directly.
This tool generates keys using the browser's built-in Web Crypto API (<code>crypto.subtle.generateKey</code>) — no key is ever sent to a server, saved, or logged; the keys on screen are permanently lost when you refresh the page. That's why you need to copy and save the private key somewhere secure (a password manager, an encrypted file) right after generating it.
Try This Next
Finished here? These might be your next step.
Frequently Asked Questions
-----BEGIN …-----/-----END …----- lines, making it copy-paste friendly for humans. SPKI (SubjectPublicKeyInfo) defines the standard structure (ASN.1/DER) of the binary data inside a public key, and PKCS8 does the same for a private key — this tool produces both wrapped in PEM; nearly every library (OpenSSL, Node.js, Python, etc.) can read these two structures directly.crypto.subtle.generateKey) — nothing is ever sent over the network, stored on a server, or logged. If you close or refresh the page, the keys shown on screen are permanently lost — so make sure to save the private key somewhere secure right after generating it.Last updated: