RSA Encrypt / Sign
CryptoRSA-OAEP encryption and RSASSA-PKCS1-v1_5 signing with Web Crypto. Generate a key pair or paste a PEM key.
On this page
What is RSA?#
RSA is asymmetric cryptography: it works with a matched pair of keys instead of one shared secret. A public key can be handed out to anyone — its only job is to lock data and check signatures. A private key stays with you and is the only thing that can unlock data encrypted to the public key, or produce a signature anyone can verify. That split is what lets two parties who have never shared a secret still exchange confidential messages and prove authenticity.
This page covers the four operations RSA is normally used for, all through the browser’s native Web Crypto engine:
- Encrypt / Decrypt use RSA-OAEP with SHA-256 — the modern, authenticated-padding scheme. A short message encrypted with the public key can only be read back with the private key.
- Sign / Verify use RSASSA-PKCS1-v1_5 with SHA-256 — the most widely interoperable signing scheme, the one most JWTs and X.509 chains still use.
- Key generation produces 2048-, 3072-, or 4096-bit pairs with a public exponent of 65537, exported as standard PEM (SubjectPublicKeyInfo for the public key, PKCS#8 for the private key).
RSA is deliberately limited to short payloads. With RSA-2048 and SHA-256, the largest message you can encrypt is about 190 bytes; for anything bigger, use the symmetric tool and protect its key with RSA instead.
How to use it#
- Generate a pair. Pick a key size (2048 / 3072 / 4096) and click Generate. Two read-only boxes fill in: the public key and the private key, both in PEM. Copy each somewhere safe — the private key is what you must never share.
- Choose a mode: Encrypt, Decrypt, Sign, or Verify.
- Put the right key in the Key field for the mode:
- Encrypt → paste the public key.
- Decrypt → paste the private key.
- Sign → paste the private key.
- Verify → paste the public key.
- Type the message. For verify, also paste the signature (base64) into the signature field.
- Run it. The status line reports the result — for verify it states explicitly whether the signature is valid or invalid.
Key features#
- Two algorithms, one key pair. The same PEM works for OAEP encryption and PKCS#1 signing, because Web Crypto takes the algorithm at import time.
- Standard PEM output. Public keys are SPKI, private keys are PKCS#8 — the formats every language and platform read natively.
- 65537 public exponent. The universally chosen value; small enough to be fast, large enough to avoid known weaknesses.
- Interoperable signatures. RSASSA-PKCS1-v1_5 is the format real-world JWTs, code-signing, and certificate chains expect.
- Zero upload. Key generation, encryption, and signing all run locally in your browser; the private key never touches a server.
Worked example#
Click Generate with 2048 selected. The public-key box fills with a PEM block of this shape:
-----BEGIN PUBLIC KEY-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyY7v...(lines of base64)
-----END PUBLIC KEY-----
The private-key box fills with a longer -----BEGIN PRIVATE KEY----- block. Now switch to Encrypt, paste the public key into the Key field, type handshake: 0x4F2A as the message, and run it. The output is a single base64 blob about 344 characters long — exactly 256 bytes of RSA-2048 ciphertext, base64-encoded.
Switch to Decrypt, paste the private key into the Key field, drop that blob into the message field, and run it: the original handshake: 0x4F2A comes back. For signing, the same flow with Sign produces a 344-character base64 signature that Verify will confirm as valid against the public key — and report as invalid if you change a single character of the message first.
FAQ#
Why can RSA only encrypt short messages?#
RSA operates on numbers modulo the key size. With RSA-2048 you have a 256-byte block, and OAEP padding consumes 2 * hashLen + 2 bytes of it (98 for SHA-256), leaving 190 bytes for the message itself. This is by design — RSA is for keys and signatures, not bulk data. The standard pattern is “hybrid”: encrypt the bulk data with AES (use the symmetric tool), then encrypt only the AES key with RSA.
2048, 3072, or 4096 bits?#
2048 is the current baseline and is still considered adequate for most uses. 3072 roughly matches a 128-bit symmetric strength; 4096 is the conservative choice for keys you want to last a decade or more. Each step up costs real time on key generation and every operation, with diminishing security returns.
What is the difference between encrypting and signing?#
Encryption is about secrecy: the public key locks, the private key unlocks. Signing is about authenticity: the private key creates the signature, the public key checks it. They use the same key pair but different algorithms (OAEP versus PKCS#1) and answer different questions — “can anyone read this?” versus “did the holder of this key really produce this?”.
Is my private key sent anywhere when I generate or use it?#
No. Generation, encryption, decryption, signing, and verification are all performed in-page by Web Crypto. The PEM blocks exist only in your browser tab; nothing is transmitted. If you are handling a production private key, generate it in an environment you control rather than pasting it into a web page at all.