JWK & JWKS Generator
Generate RSA, EC, or Ed25519 key pairs and export public JWK, optional private JWK, JWKS, PEM keys, and RFC 7638 SHA-256 thumbprints.
Key generation settings
JSON Web Keys
Generate key material for JWT, OAuth, and OpenID Connect
JSON Web Keys (JWK) provide a standardized JSON representation of cryptographic keys used by JWT, JWS, JWE, OAuth 2.0, and OpenID Connect applications.
Generate interoperable keys
Create RSA, Elliptic Curve, or Ed25519 key pairs and export them as JWK, JWKS, or PEM formats for use with identity providers, API gateways, and JWT signing services.
Protect private keys
Public JWKs may be published through JWKS endpoints, but private JWKs and PEM private keys should always remain confidential and never be embedded in client-side code.
Guide
About JWK and JWKS Generator
JWK and JWKS formats are used to publish verification keys and exchange key metadata in JWT, OAuth, and OpenID Connect systems.
This generator creates RSA, EC, or Ed25519 key pairs and exports public or private representations.
Only public key material should be published; private keys must remain protected.
Generated formats
Export key material in formats commonly used by JOSE libraries and infrastructure.
- Public JWK
- Optional private JWK
- JWKS document
- PEM public and private keys
- RFC 7638 SHA-256 thumbprint
Key identifiers
A kid value helps verifiers select the correct key during key rotation and multi-key deployments.
Publishing a JWKS
Publish only public keys over HTTPS and use cache controls and rotation procedures appropriate for your identity system.
Private-key handling
Do not embed private JWKs or PEM keys in front-end bundles, public repositories, logs, or public JWKS endpoints.
FAQ
Frequently asked questions
Which key type should I generate?
Choose based on algorithm support, interoperability, policy, and deployment requirements.
Can a JWKS contain multiple keys?
Yes. Multiple keys support rotation and different algorithms or purposes.
Should I publish the private JWK?
No. Publish only the public members.
What is kid used for?
It allows a verifier to select a specific key from a JWKS.
Can PEM and JWK represent the same key?
Yes. They are different encodings of the same underlying key material.
Are keys generated locally?
Generation is intended to occur in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
JWK & JWKS Inspector
Inspect JSON Web Keys, review JWKS collections, and generate RFC 7638 thumbprints.
PKI & Certificates
JWT Signature Verifier
Verify HMAC JWT signatures and important claims locally.
Authentication
JWT Inspector
Inspect JWT claims, expiration, lifetime, and common structural security issues.
Security Tools
Public & Private Key Analyzer
Identify PEM and OpenSSH key algorithms, formats, sizes, curves, and fingerprints locally.
PKI & Certificates
X.509 Certificate Decoder
Decode certificate identity, validity, algorithms, key details, and fingerprints locally.
PKI & Certificates
CSR Decoder
Decode PKCS#10 certificate signing requests and review requested identities, keys, and extensions.
PKI & Certificates