SSL & Security

Encryption Key Generator

Key Generation

Generate cryptographic keys

Pick a key type, strength, and quantity, then generate key pairs or secrets instantly.
Optionsgenerated locally in your browser using the Web Crypto API — nothing leaves this page
Key Type
Modulus length
Quantity max 5
RSA public/private key pair (RSASSA-PKCS1-v1_5, SHA-256) — widely supported for signing and legacy encryption.

Tool features

Browser-native cryptographic key generation with standard export formats
4 features

Key Pairs & Secrets

RSA, ECDSA, and Ed25519 pairs plus AES and HMAC secrets

Web Crypto API

Keys come from your browser’s native cryptographic generator

Standard Formats

PKCS#8 / SPKI PEM export with SHA-256 fingerprints

Private by Design

Everything is generated locally — keys never leave the page

What is an encryption key & how it works

Symmetric secrets and public/private key pairs

Symmetric keys (AES, HMAC) are a single secret used both to encrypt and decrypt, or to sign and verify. Asymmetric key pairs (RSA, ECDSA, Ed25519) split that into a private key you keep and a public key you can share freely.

This generator uses the browser's Web Crypto API, so keys are created on your device from a secure random source and never reach ShowDNS. Key pairs are exported as PEM (PKCS#8 private, SPKI public), the format OpenSSL and most libraries read; symmetric keys come out as raw bytes in hex or Base64.

AES-256
The standard symmetric cipher key; 256 bits of random data.
PKCS#8 / SPKI
Standard PEM encodings for private and public keys.
Ed25519
A modern, fast signature algorithm with small keys.

How to use this tool

Generate an encryption key in four steps
1
Choose the algorithm
Pick AES or HMAC for a shared secret, or RSA, ECDSA or Ed25519 for a key pair.
2
Set the size
Choose the key length (AES 128–256, RSA 2048–4096) or the curve (P-256, P-384, P-521).
3
Generate
Keys are created locally in your browser with the Web Crypto API.
4
Store them safely
Copy or download the keys and put private keys straight into a secrets manager.

Frequently asked questions

Common questions about encryption keys
5 Q&A

Yes. They come from the Web Crypto API (crypto.subtle.generateKey) in your browser, which uses the operating system’s secure random generator. Nothing is sent to our servers.

AES-256 for symmetric encryption, RSA-3072 or larger for new RSA keys (2048 is the minimum), and P-256 or Ed25519 for elliptic-curve keys.

Use a key pair when the party verifying or encrypting should not be able to sign or decrypt: signatures, TLS, JWTs verified by third parties. Use a shared secret key when both sides are trusted, such as encrypting your own data or HMAC-signing webhooks.

Not directly: SSH needs keys in OpenSSH format. Use the SSH Key Generator for SSH access keys.

Browser generation is secure, but production keys are best created where they will live, such as a KMS, HSM or the server itself, so the private key never exists anywhere else.