RSA Encryption Tool (PEM)
Generate RSA key pairs as PEM, encrypt a short message with a public key, and decrypt it with the private key. RSA-OAEP in your browser; not OpenPGP.
- Free, no sign-up
- REST + MCP
- Updated
- Reviewed by Olgun Ozoktas
Paste the recipient's public key to encrypt your message
How It Works
Generate a key pair: share your public key, keep your private key secret
To send: encrypt with recipient's public key
To receive: decrypt with your private key
How to Encrypt a Message with RSA
-
Generate an RSA Key Pair
Select the Generate Keys mode and click Generate Key Pair. The tool creates a 2048-bit RSA key pair in your browser with the Web Crypto API and shows it as PEM text: a PUBLIC KEY block and a PRIVATE KEY block. Store the private key somewhere safe and share only the public key. -
Exchange Public Keys
Send your public key to the person you want to communicate with and ask them for theirs. Public keys are safe to share. Anyone with your public key can encrypt a message that only your private key can decrypt. -
Encrypt Your Message
Switch to Encrypt mode, paste the recipient's public key, type a short message, and click Encrypt Message. The output is a Base64 block between BEGIN ENCRYPTED MESSAGE and END ENCRYPTED MESSAGE lines that you can send through any text channel. A 2048-bit key encrypts at most 190 bytes of text. -
Decrypt Received Messages
When you receive an encrypted block, switch to Decrypt mode, paste it, provide your private key, and click Decrypt Message. The original text appears. Only the matching private key can decrypt it.
Common Use Cases
Sharing a Short Secret
Learning Public-Key Cryptography
Testing an RSA Integration
Keeping Keys Off Servers
Why Use RSA Encryption?
RSA is a public-key encryption method: you have a public key you can share and a private key you keep secret. A message encrypted with your public key can only be decrypted with your private key. This RSA Encryption Tool generates a key pair, encrypts a short message and decrypts it again, using RSA-OAEP with SHA-256 through your browser's Web Crypto API. Keys are shown as PEM text (SPKI public keys and PKCS#8 private keys), the format OpenSSL and most programming languages read.
It is not PGP. PGP and GnuPG use the OpenPGP format: their keys and messages start with lines like BEGIN PGP PUBLIC KEY BLOCK and BEGIN PGP MESSAGE, and they encrypt a random session key with AES so messages can be any length. This tool encrypts the message directly with RSA, which limits it to a short message (190 bytes with a 2048-bit key) and produces blocks that GnuPG cannot read. For longer text, use AES Text Encryption with a shared password, or a dedicated OpenPGP program.
For related jobs, generate a strong secret with the Password Generator or Random Key Generator, sign a message with the HMAC Generator, or check a file with the Hash Comparison Tool.
How it compares
Online RSA and PGP tools fall into two groups: those that process your keys on a server and those that run in the browser. On a server-side tool you cannot check what happens to a private key you paste. On this page, key generation, encryption and decryption run in your browser with the Web Crypto API, and you can confirm that nothing is uploaded in your browser's network tab.
Desktop programs like GnuPG and Kleopatra implement the full OpenPGP standard: key rings, signatures, revocation and messages of any length. Use them when you need PGP or need to exchange messages with someone who uses PGP. This tool is smaller: RSA-OAEP key generation, encryption and decryption of a short message, in PEM, with no install.
Tips for Using RSA Encryption
- Keep messages short: RSA-OAEP with a 2048-bit key encrypts at most 190 bytes. For longer text, use a symmetric tool like AES text encryption and share the password separately.
- Back up your private key in a safe place, such as a password manager. Losing it means you cannot decrypt messages encrypted with the matching public key.
- Never paste a private key into a tool that sends data to a server. This page runs in your browser; the REST and MCP API is a separate path that receives what you send it.
- Verify a public key through a second channel before you use it, for example by reading part of it back over a call, to rule out a swapped key.
- This is not PGP. If the other person uses GnuPG or another OpenPGP program, use that program: it cannot read these PEM keys or messages.