RSA Encryption, Decryption, Signing & Verification Online — Key Pair Generation
RSA-OAEP public-key encryption / private-key decryption / key pair generation / digital signatures
About RSA Encryption & Decryption
RSA is an asymmetric encryption algorithm based on the difficulty of factoring large primes. Encryption and decryption use different keys: encrypt with the public key, decrypt with the private key, with no shared secret needed. This tool generates 1024/2048/4096-bit key pairs locally in the browser, using standard -----BEGIN PUBLIC KEY----- public keys and -----BEGIN PRIVATE KEY----- (PKCS#8) private keys, with SHA-256 and SHA-1 hash padding.
About Digital Signatures
A digital signature uses the private key to sign data, and the receiver uses the public key to verify it, ensuring the data was not tampered with and comes from a trusted source. This tool uses the RSASSA-PKCS1-v1_5 signature algorithm with SHA-256, SHA-384 and SHA-512 hashes. Signatures are common in software distribution verification, API request signing and JWT issuance.
Key Format Notes
This tool supports standard PEM public keys (SPKI format, starting with -----BEGIN PUBLIC KEY-----) and standard PKCS#8 private keys (starting with -----BEGIN PRIVATE KEY-----). If your key starts with -----BEGIN RSA PUBLIC KEY----- or -----BEGIN RSA PRIVATE KEY-----, it is PKCS#1 format and must be converted to the standard format first. OpenSSH public keys (ssh-rsa ...) can also be converted to standard PEM for import.
FAQ
Yes. The plaintext size for RSA-OAEP depends on the key size: a 2048-bit key with SHA-256 padding encrypts about 190 bytes (roughly 63 Chinese characters), and a 4096-bit key about 446 bytes. So RSA is not suited to encrypting long text directly. In practice, RSA encrypts an AES key and AES encrypts the data (hybrid encryption). To encrypt long text, use theAES symmetric encryption tool.
The public key can be shared — give it to anyone to encrypt data or verify signatures. The private key must stay secret and is held only by you for decryption and signing. If the private key leaks, an attacker can decrypt all messages and forge signatures. Download the generated private key as a .pem file and store it safely.
No. Since 2014 NIST has no longer recommended 1024-bit RSA, recommending at least 2048 bits. A 1024-bit key can theoretically be factored with reasonable computing resources. Use 4096 bits for high-security scenarios.
Encryption/decryption targets confidentiality — encrypting with the public key so only the private-key holder can decrypt. Signing/verification targets integrity and authentication — signing with the private key to prove the data comes from you and was not tampered with. The former protects the content, the latter its trustworthiness. The two features use separate key pairs.