Tool
RSA Key Generator
Generate RSA public/private key pairs in PEM format for RS256 JWT signing.
Last updated July 1, 2026
Runs entirely in your browser — no data sent to servers. Privacy policy
Prove it runs locally
- Open DevTools → Network tab
- Click Generate
- Confirm zero outbound requests for the secret
Generation uses crypto.getRandomValues() in your browser. Privacy policy
Advertisement
How to Use This Tool
Select key size: 2048-bit for standard production use, 4096-bit for high-security or long-lived keys.
Click Generate to create an RSA key pair using the Web Crypto API in your browser.
Copy the public key PEM for verifiers and JWKS endpoints. Store the private key in a secrets manager — never commit it.
Use the private key with your JWT library to sign RS256 tokens.
Continue learning
ToolsJWT Encoder — Sign JWTs with HS256 (use RS256 in code with RSA keys).JWT Validator — Verify HS256 tokens during development.JWKS Viewer — Turn public PEMs into a JWKS document for verifiers.
GuidesChoose HS256 or RS256 for Your API — Decide between HS256 shared secrets and RS256 public/private keys for your API. Quick decision steps plus links to full side-by-side algorithm comparisons.Sign Your First RS256 JWT — Generate an RSA key pair in your browser, sign an RS256 JWT, and verify it with the public key — a practical RS256 quickstart for APIs.Node.jsPythonGoJavaRuby
ArticlesRSA Key Pairs for JWT Signing (RS256) — Generate and use RSA key pairs for RS256 JWT signing.JWKS in Production — Turn RSA public keys into a production JWKS URI safely.HS256 vs RS256 Comparison — When asymmetric RSA signing beats shared secrets.