Key Pair Generator - RSA, ECDSA & Ed25519 Keys in PEM and OpenSSH Format
Key Pair Generator
Public and private keys generated in your browser
Modern Algorithms
Ed25519 for small, fast keys, ECDSA for wide compatibility, RSA for legacy systems.
SSH-Ready
Get the one-line public key for authorized_keys or GitHub, with the same fingerprint ssh-keygen shows.
Standard PEM
SPKI and PKCS#8 PEM files work with OpenSSL, JWT libraries and most languages.
Generated Locally
Keys come from the browser's secure random generator and are never uploaded or stored.
Choosing and Using a Key
Ed25519 is the best default today: short keys, fast signatures and no tricky parameters. ECDSA P-256 is supported almost everywhere, including older TLS and cloud systems. RSA remains common for older software; use at least 3072 bits for keys meant to last. The public key can be shared freely; the private key must stay secret, so store it with restrictive permissions (chmod 600) and preferably encrypt it with a passphrase.
The private key is exported as unencrypted PKCS#8 PEM. OpenSSL, most libraries and OpenSSH read it directly; to add a passphrase run ssh-keygen -p -f private_key.pem or openssl pkcs8 -topk8 -v2 aes-256-cbc. For servers holding long-lived production secrets, generating keys on the machine that uses them with ssh-keygen or openssl is still the most conservative choice.
Key Takeaways
- Ed25519 first: Choose RSA only for systems that need it.
- Protect the private key: Never share it; add a passphrase after saving.
- Check fingerprints: Compare SHA256 fingerprints when adding keys to servers.