SSL & Security
Encryption Key Generator
Generate cryptographic keys
Optionsgenerated locally in your browser using the Web Crypto API — nothing leaves this page
Key Type
Modulus length
Quantity max 5
RSA public/private key pair (RSASSA-PKCS1-v1_5, SHA-256) — widely supported for signing and legacy encryption.
Tool features
4 features
Key Pairs & Secrets
RSA, ECDSA, and Ed25519 pairs plus AES and HMAC secrets
Web Crypto API
Keys come from your browser’s native cryptographic generator
Standard Formats
PKCS#8 / SPKI PEM export with SHA-256 fingerprints
Private by Design
Everything is generated locally — keys never leave the page
What is an encryption key & how it works
Symmetric keys (AES, HMAC) are a single secret used both to encrypt and decrypt, or to sign and verify. Asymmetric key pairs (RSA, ECDSA, Ed25519) split that into a private key you keep and a public key you can share freely.
This generator uses the browser's Web Crypto API, so keys are created on your device from a secure random source and never reach ShowDNS. Key pairs are exported as PEM (PKCS#8 private, SPKI public), the format OpenSSL and most libraries read; symmetric keys come out as raw bytes in hex or Base64.
AES-256
The standard symmetric cipher key; 256 bits of random data.
PKCS#8 / SPKI
Standard PEM encodings for private and public keys.
Ed25519
A modern, fast signature algorithm with small keys.
How to use this tool
1
Choose the algorithm
Pick AES or HMAC for a shared secret, or RSA, ECDSA or Ed25519 for a key pair.
2
Set the size
Choose the key length (AES 128–256, RSA 2048–4096) or the curve (P-256, P-384, P-521).
3
Generate
Keys are created locally in your browser with the Web Crypto API.
4
Store them safely
Copy or download the keys and put private keys straight into a secrets manager.
Related tools
3 tools
Certificate Generator
Generate X.509 certificates for SSL/TLS, CA, and code signing purposes with full customization
CSR Generator
Generate Certificate Signing Request (CSR) for SSL certificates with customizable options
SSH Key Generator
Generate SSH key pairs (RSA, ECDSA, Ed25519) for secure server authentication
Frequently asked questions
5 Q&A
AES-256 for symmetric encryption, RSA-3072 or larger for new RSA keys (2048 is the minimum), and P-256 or Ed25519 for elliptic-curve keys.
Use a key pair when the party verifying or encrypting should not be able to sign or decrypt: signatures, TLS, JWTs verified by third parties. Use a shared secret key when both sides are trusted, such as encrypting your own data or HMAC-signing webhooks.
Not directly: SSH needs keys in OpenSSH format. Use the SSH Key Generator for SSH access keys.
Browser generation is secure, but production keys are best created where they will live, such as a KMS, HSM or the server itself, so the private key never exists anywhere else.