SSH Public Key & PEM Pair Generator
Choose RSA 2048/4096 or ECDSA P-256/P-384. Export separately labeled PEM and OpenSSH public formats; the private key is unencrypted.
A QUICK WALKTHROUGH
How to use this tool
- Choose the algorithm and size, and optionally enter an ASCII public-key comment up to 80 characters.
- Generate with browser WebCrypto; keep the private-key output private.
- Explicitly copy or download the selected output, or clear it. Cancel discards results without aborting WebCrypto.
Formats and algorithms
RSA uses RSASSA-PKCS1-v1_5 with SHA-256, exponent 65537 and 2048/4096 bits. ECDSA uses P-256/P-384. Exportable WebCrypto keys produce unencrypted PKCS#8 private PEM and SPKI public PEM. The separately encoded OpenSSH public line uses RFC 4251/4253 RSA strings and positive mpints, or RFC 5656 ECDSA curve names and uncompressed points. An ssh-rsa public-key label is a key format, not a promise of a negotiated signature algorithm or server policy. No OpenSSH private file or passphrase protection is produced.
Local limits and cancellation
WebCrypto in a secure browser context is required; unavailable or unsupported algorithms fail without a fallback. One generation runs at a time across tool instances. Input changes, Clear or Cancel discard results but cannot abort the browser’s crypto operation; Generate stays locked until it settles. Each output is limited to 65,536 ASCII characters. The comment permits at most 80 printable ASCII characters and no line breaks. No API calls or persistent storage. Clearing removes displayed references, not a guarantee of memory zeroization.
Unencrypted private material
Private PEM is unencrypted. Copy and download are explicit actions and create copies outside this tool. Anyone with that private key can possess the same key material. This tool does not prove identity, configure a server, test login or certify production suitability.
GOOD TO KNOW
Common questions
Does it make an OpenSSH private key?
No. Only the public authorized_keys line is OpenSSH format. The private key is unencrypted PKCS#8 PEM.
Does Cancel stop WebCrypto?
No. It invalidates the result while the underlying operation may continue. The generation lock releases after settlement.