Skip to content

Security

RSA Encryption Tool (PEM)

RSA Encryption Tool (PEM)

Generate RSA key pairs as PEM, encrypt a short message with a public key, and decrypt it with the private key. RSA-OAEP in your browser; not OpenPGP.

Use via API
  • Free, no sign-up
  • REST + MCP
  • Updated
  • Reviewed by Olgun Ozoktas

Paste the recipient's public key to encrypt your message

How It Works

Generate a key pair: share your public key, keep your private key secret

To send: encrypt with recipient's public key

To receive: decrypt with your private key

How to Encrypt a Message with RSA

  1. Generate an RSA Key Pair

    Select the Generate Keys mode and click Generate Key Pair. The tool creates a 2048-bit RSA key pair in your browser with the Web Crypto API and shows it as PEM text: a PUBLIC KEY block and a PRIVATE KEY block. Store the private key somewhere safe and share only the public key.
  2. Exchange Public Keys

    Send your public key to the person you want to communicate with and ask them for theirs. Public keys are safe to share. Anyone with your public key can encrypt a message that only your private key can decrypt.
  3. Encrypt Your Message

    Switch to Encrypt mode, paste the recipient's public key, type a short message, and click Encrypt Message. The output is a Base64 block between BEGIN ENCRYPTED MESSAGE and END ENCRYPTED MESSAGE lines that you can send through any text channel. A 2048-bit key encrypts at most 190 bytes of text.
  4. Decrypt Received Messages

    When you receive an encrypted block, switch to Decrypt mode, paste it, provide your private key, and click Decrypt Message. The original text appears. Only the matching private key can decrypt it.

Common Use Cases

Sharing a Short Secret

Send a password, API token or recovery code to a colleague over chat or email without it sitting there in plain text. They share their public key, you encrypt, and only their private key can read it.

Learning Public-Key Cryptography

See RSA-OAEP work end to end: generate a key pair, encrypt with the public key, decrypt with the private key, and watch a wrong key fail. The PEM blocks are the same format OpenSSL and the Web Crypto API use.

Testing an RSA Integration

Produce SPKI and PKCS#8 PEM keys and RSA-OAEP (SHA-256) ciphertext to check code that uses the Web Crypto API or OpenSSL with the same padding.

Keeping Keys Off Servers

Key generation, encryption and decryption on this page run in your browser, so a private key you paste here is not uploaded.

Why Use RSA Encryption?

Public-key encryption lets someone send you a secret without agreeing on a password first: they encrypt with your public key, and only your private key can decrypt it.

RSA is a public-key encryption method: you have a public key you can share and a private key you keep secret. A message encrypted with your public key can only be decrypted with your private key. This RSA Encryption Tool generates a key pair, encrypts a short message and decrypts it again, using RSA-OAEP with SHA-256 through your browser's Web Crypto API. Keys are shown as PEM text (SPKI public keys and PKCS#8 private keys), the format OpenSSL and most programming languages read.

It is not PGP. PGP and GnuPG use the OpenPGP format: their keys and messages start with lines like BEGIN PGP PUBLIC KEY BLOCK and BEGIN PGP MESSAGE, and they encrypt a random session key with AES so messages can be any length. This tool encrypts the message directly with RSA, which limits it to a short message (190 bytes with a 2048-bit key) and produces blocks that GnuPG cannot read. For longer text, use AES Text Encryption with a shared password, or a dedicated OpenPGP program.

For related jobs, generate a strong secret with the Password Generator or Random Key Generator, sign a message with the HMAC Generator, or check a file with the Hash Comparison Tool.

How it compares

Online RSA and PGP tools fall into two groups: those that process your keys on a server and those that run in the browser. On a server-side tool you cannot check what happens to a private key you paste. On this page, key generation, encryption and decryption run in your browser with the Web Crypto API, and you can confirm that nothing is uploaded in your browser's network tab.

Desktop programs like GnuPG and Kleopatra implement the full OpenPGP standard: key rings, signatures, revocation and messages of any length. Use them when you need PGP or need to exchange messages with someone who uses PGP. This tool is smaller: RSA-OAEP key generation, encryption and decryption of a short message, in PEM, with no install.

Tips for Using RSA Encryption

  • Keep messages short: RSA-OAEP with a 2048-bit key encrypts at most 190 bytes. For longer text, use a symmetric tool like AES text encryption and share the password separately.
  • Back up your private key in a safe place, such as a password manager. Losing it means you cannot decrypt messages encrypted with the matching public key.
  • Never paste a private key into a tool that sends data to a server. This page runs in your browser; the REST and MCP API is a separate path that receives what you send it.
  • Verify a public key through a second channel before you use it, for example by reading part of it back over a call, to rule out a swapped key.
  • This is not PGP. If the other person uses GnuPG or another OpenPGP program, use that program: it cannot read these PEM keys or messages.

Frequently Asked Questions

Is this PGP encryption?

No. It uses RSA-OAEP with SHA-256 and PEM keys (BEGIN PUBLIC KEY and BEGIN PRIVATE KEY), not the OpenPGP format that PGP and GnuPG use. GnuPG cannot read its keys or messages, and it cannot read GnuPG's. The page keeps its old address, but it has always been an RSA tool.

Should I share my private key?

Never share your private key. It's the only way to decrypt messages sent to you. Share only your public key with people who want to send you encrypted messages.

Is my data processed locally?

On this page, yes. Key generation, encryption and decryption run in your browser with the Web Crypto API, and your keys and messages are not sent to any server. The REST and MCP API is a separate path: a call there sends the text and keys you include to FindUtils over TLS, and they are not stored or logged.

What key size does it use?

This page generates 2048-bit RSA keys, a size that is widely considered secure today. The API can also generate 3072-bit and 4096-bit keys. A larger key allows a slightly longer message and a wider security margin, but takes longer to generate.

Can I use these keys with GnuPG or OpenSSL?

With OpenSSL and most programming languages, yes: the keys are standard SPKI and PKCS#8 PEM, and the ciphertext is RSA-OAEP with SHA-256, encoded in Base64. With GnuPG or other PGP programs, no: they use the OpenPGP format, which is different.

Can I encrypt files with this tool?

No. It encrypts short text only: RSA-OAEP with a 2048-bit key fits at most 190 bytes. For files or longer text, use a tool that combines RSA with a symmetric cipher, such as GnuPG, or encrypt with AES and a shared password.

How is this different from AES encryption?

RSA is asymmetric: the sender uses your public key and only your private key decrypts, so you never share a password. AES is symmetric: both sides need the same password. RSA can only encrypt a short message directly, which is why PGP and TLS use RSA to protect a random AES key and AES for the data. This tool does not do that; it encrypts the message with RSA alone.

Is RSA-OAEP still secure?

Yes. RSA-OAEP with 2048-bit or larger keys has no known practical attack today. Large quantum computers would break RSA in the future, which is why post-quantum algorithms are being standardized, but none exists that can do so now.

What does the BEGIN ENCRYPTED MESSAGE block mean?

The encrypted bytes are encoded as Base64 text and wrapped between BEGIN ENCRYPTED MESSAGE and END ENCRYPTED MESSAGE lines, so you can paste the result into an email or chat without it being corrupted. It is a label this tool uses, not an OpenPGP armor block.

Can someone decrypt my message if they have only my public key?

No. The public key can only encrypt messages, not decrypt them. Decryption requires the corresponding private key, which only you possess. This is the fundamental security property of asymmetric cryptography.

Rate This Tool

0/1000

Get Weekly Tools

Suggest a Tool