Tools
Guides

RSA Encrypt / Sign

Crypto

RSA-OAEP encryption and RSASSA-PKCS1-v1_5 signing with Web Crypto. Generate a key pair or paste a PEM key.

100% client-side No backend
Message
Signature
Key (PEM)
Output
Public key (PEM)
Private key (PEM)
On this page

What is RSA?#

RSA is asymmetric cryptography: it works with a matched pair of keys instead of one shared secret. A public key can be handed out to anyone — its only job is to lock data and check signatures. A private key stays with you and is the only thing that can unlock data encrypted to the public key, or produce a signature anyone can verify. That split is what lets two parties who have never shared a secret still exchange confidential messages and prove authenticity.

This page covers the four operations RSA is normally used for, all through the browser’s native Web Crypto engine:

  • Encrypt / Decrypt use RSA-OAEP with SHA-256 — the modern, authenticated-padding scheme. A short message encrypted with the public key can only be read back with the private key.
  • Sign / Verify use RSASSA-PKCS1-v1_5 with SHA-256 — the most widely interoperable signing scheme, the one most JWTs and X.509 chains still use.
  • Key generation produces 2048-, 3072-, or 4096-bit pairs with a public exponent of 65537, exported as standard PEM (SubjectPublicKeyInfo for the public key, PKCS#8 for the private key).

RSA is deliberately limited to short payloads. With RSA-2048 and SHA-256, the largest message you can encrypt is about 190 bytes; for anything bigger, use the symmetric tool and protect its key with RSA instead.

How to use it#

  1. Generate a pair. Pick a key size (2048 / 3072 / 4096) and click Generate. Two read-only boxes fill in: the public key and the private key, both in PEM. Copy each somewhere safe — the private key is what you must never share.
  2. Choose a mode: Encrypt, Decrypt, Sign, or Verify.
  3. Put the right key in the Key field for the mode:
    • Encrypt → paste the public key.
    • Decrypt → paste the private key.
    • Sign → paste the private key.
    • Verify → paste the public key.
  4. Type the message. For verify, also paste the signature (base64) into the signature field.
  5. Run it. The status line reports the result — for verify it states explicitly whether the signature is valid or invalid.

Key features#

  • Two algorithms, one key pair. The same PEM works for OAEP encryption and PKCS#1 signing, because Web Crypto takes the algorithm at import time.
  • Standard PEM output. Public keys are SPKI, private keys are PKCS#8 — the formats every language and platform read natively.
  • 65537 public exponent. The universally chosen value; small enough to be fast, large enough to avoid known weaknesses.
  • Interoperable signatures. RSASSA-PKCS1-v1_5 is the format real-world JWTs, code-signing, and certificate chains expect.
  • Zero upload. Key generation, encryption, and signing all run locally in your browser; the private key never touches a server.

Worked example#

Click Generate with 2048 selected. The public-key box fills with a PEM block of this shape:

-----BEGIN PUBLIC KEY-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyY7v...(lines of base64)
-----END PUBLIC KEY-----

The private-key box fills with a longer -----BEGIN PRIVATE KEY----- block. Now switch to Encrypt, paste the public key into the Key field, type handshake: 0x4F2A as the message, and run it. The output is a single base64 blob about 344 characters long — exactly 256 bytes of RSA-2048 ciphertext, base64-encoded.

Switch to Decrypt, paste the private key into the Key field, drop that blob into the message field, and run it: the original handshake: 0x4F2A comes back. For signing, the same flow with Sign produces a 344-character base64 signature that Verify will confirm as valid against the public key — and report as invalid if you change a single character of the message first.

FAQ#

Why can RSA only encrypt short messages?#

RSA operates on numbers modulo the key size. With RSA-2048 you have a 256-byte block, and OAEP padding consumes 2 * hashLen + 2 bytes of it (98 for SHA-256), leaving 190 bytes for the message itself. This is by design — RSA is for keys and signatures, not bulk data. The standard pattern is “hybrid”: encrypt the bulk data with AES (use the symmetric tool), then encrypt only the AES key with RSA.

2048, 3072, or 4096 bits?#

2048 is the current baseline and is still considered adequate for most uses. 3072 roughly matches a 128-bit symmetric strength; 4096 is the conservative choice for keys you want to last a decade or more. Each step up costs real time on key generation and every operation, with diminishing security returns.

What is the difference between encrypting and signing?#

Encryption is about secrecy: the public key locks, the private key unlocks. Signing is about authenticity: the private key creates the signature, the public key checks it. They use the same key pair but different algorithms (OAEP versus PKCS#1) and answer different questions — “can anyone read this?” versus “did the holder of this key really produce this?”.

Is my private key sent anywhere when I generate or use it?#

No. Generation, encryption, decryption, signing, and verification are all performed in-page by Web Crypto. The PEM blocks exist only in your browser tab; nothing is transmitted. If you are handling a production private key, generate it in an environment you control rather than pasting it into a web page at all.