Key Pair Generator - RSA, ECDSA & Ed25519 Keys in PEM and OpenSSH Format

AdSense Placeholder
Slot: header_tool

Key Pair Generator

Public and private keys generated in your browser

Fingerprint:

AdSense Placeholder
Slot: tool_mid_article

Modern Algorithms

Ed25519 for small, fast keys, ECDSA for wide compatibility, RSA for legacy systems.

SSH-Ready

Get the one-line public key for authorized_keys or GitHub, with the same fingerprint ssh-keygen shows.

Standard PEM

SPKI and PKCS#8 PEM files work with OpenSSL, JWT libraries and most languages.

Generated Locally

Keys come from the browser's secure random generator and are never uploaded or stored.

Choosing and Using a Key

Ed25519 is the best default today: short keys, fast signatures and no tricky parameters. ECDSA P-256 is supported almost everywhere, including older TLS and cloud systems. RSA remains common for older software; use at least 3072 bits for keys meant to last. The public key can be shared freely; the private key must stay secret, so store it with restrictive permissions (chmod 600) and preferably encrypt it with a passphrase.

The private key is exported as unencrypted PKCS#8 PEM. OpenSSL, most libraries and OpenSSH read it directly; to add a passphrase run ssh-keygen -p -f private_key.pem or openssl pkcs8 -topk8 -v2 aes-256-cbc. For servers holding long-lived production secrets, generating keys on the machine that uses them with ssh-keygen or openssl is still the most conservative choice.

Key Takeaways

  • Ed25519 first: Choose RSA only for systems that need it.
  • Protect the private key: Never share it; add a passphrase after saving.
  • Check fingerprints: Compare SHA256 fingerprints when adding keys to servers.
AdSense Placeholder
Slot: footer_leaderboard