---
title: "RSA Encryption Tool (PEM)"
description: "Generate RSA key pairs as PEM, encrypt a short message with a public key, and decrypt it with the private key. RSA-OAEP in your browser; not OpenPGP."
url: https://findutils.com/security/pgp-encryption-tool/
category: security
---

# RSA Encryption Tool (PEM)

Generate RSA key pairs as PEM, encrypt a short message with a public key, and decrypt it with the private key. RSA-OAEP in your browser; not OpenPGP.

**Use this tool:** [RSA Encryption Tool (PEM)](https://findutils.com/security/pgp-encryption-tool/)

## Programmatic access

- REST id `pgp-encryption-tool`: POST https://api.findutils.com/api/tools/pgp-encryption-tool/execute (reference: https://findutils.com/api/pgp-encryption-tool/)
- MCP tool `pgp_encryption_tool` on https://mcp.findutils.com (reference: https://findutils.com/mcp/pgp-encryption-tool/)

## Why Use RSA Encryption?

Public-key encryption lets someone send you a secret without agreeing on a password first: they encrypt with your public key, and only your private key can decrypt it.

## Tips for Using RSA Encryption

- Keep messages short: RSA-OAEP with a 2048-bit key encrypts at most 190 bytes. For longer text, use a symmetric tool like AES text encryption and share the password separately.
- Back up your private key in a safe place, such as a password manager. Losing it means you cannot decrypt messages encrypted with the matching public key.
- Never paste a private key into a tool that sends data to a server. This page runs in your browser; the REST and MCP API is a separate path that receives what you send it.
- Verify a public key through a second channel before you use it, for example by reading part of it back over a call, to rule out a swapped key.
- This is not PGP. If the other person uses GnuPG or another OpenPGP program, use that program: it cannot read these PEM keys or messages.

## Frequently Asked Questions

### Is this PGP encryption?

No. It uses RSA-OAEP with SHA-256 and PEM keys (BEGIN PUBLIC KEY and BEGIN PRIVATE KEY), not the OpenPGP format that PGP and GnuPG use. GnuPG cannot read its keys or messages, and it cannot read GnuPG's. The page keeps its old address, but it has always been an RSA tool.

### Should I share my private key?

Never share your private key. It's the only way to decrypt messages sent to you. Share only your public key with people who want to send you encrypted messages.

### Is my data processed locally?

On this page, yes. Key generation, encryption and decryption run in your browser with the Web Crypto API, and your keys and messages are not sent to any server. The REST and MCP API is a separate path: a call there sends the text and keys you include to FindUtils over TLS, and they are not stored or logged.

### What key size does it use?

This page generates 2048-bit RSA keys, a size that is widely considered secure today. The API can also generate 3072-bit and 4096-bit keys. A larger key allows a slightly longer message and a wider security margin, but takes longer to generate.

### Can I use these keys with GnuPG or OpenSSL?

With OpenSSL and most programming languages, yes: the keys are standard SPKI and PKCS#8 PEM, and the ciphertext is RSA-OAEP with SHA-256, encoded in Base64. With GnuPG or other PGP programs, no: they use the OpenPGP format, which is different.

### Can I encrypt files with this tool?

No. It encrypts short text only: RSA-OAEP with a 2048-bit key fits at most 190 bytes. For files or longer text, use a tool that combines RSA with a symmetric cipher, such as GnuPG, or encrypt with AES and a shared password.

### How is this different from AES encryption?

RSA is asymmetric: the sender uses your public key and only your private key decrypts, so you never share a password. AES is symmetric: both sides need the same password. RSA can only encrypt a short message directly, which is why PGP and TLS use RSA to protect a random AES key and AES for the data. This tool does not do that; it encrypts the message with RSA alone.

### Is RSA-OAEP still secure?

Yes. RSA-OAEP with 2048-bit or larger keys has no known practical attack today. Large quantum computers would break RSA in the future, which is why post-quantum algorithms are being standardized, but none exists that can do so now.

### What does the BEGIN ENCRYPTED MESSAGE block mean?

The encrypted bytes are encoded as Base64 text and wrapped between BEGIN ENCRYPTED MESSAGE and END ENCRYPTED MESSAGE lines, so you can paste the result into an email or chat without it being corrupted. It is a label this tool uses, not an OpenPGP armor block.

### Can someone decrypt my message if they have only my public key?

No. The public key can only encrypt messages, not decrypt them. Decryption requires the corresponding private key, which only you possess. This is the fundamental security property of asymmetric cryptography.

## Related Tools

- [Text Encryption](https://findutils.com/security/text-encryption/)
- [Secure Note Sharing](https://findutils.com/security/secure-note-sharing/)
- [Password Generator](https://findutils.com/security/password-generator/)
- [Random Key Generator](https://findutils.com/security/random-key-generator/)
- [Hash Comparison Tool](https://findutils.com/security/hash-comparison-tool/)
- [HMAC Generator](https://findutils.com/security/hmac-generator/)
