JWK & JWKS Generator

Generate RSA, EC, or Ed25519 key pairs and export public JWK, optional private JWK, JWKS, PEM keys, and RFC 7638 SHA-256 thumbprints.

Browser onlyRSA, EC & Ed25519RFC 7638

Key generation settings

Intended use
Signature

JSON Web Keys

Generate key material for JWT, OAuth, and OpenID Connect

JSON Web Keys (JWK) provide a standardized JSON representation of cryptographic keys used by JWT, JWS, JWE, OAuth 2.0, and OpenID Connect applications.

Generate interoperable keys

Create RSA, Elliptic Curve, or Ed25519 key pairs and export them as JWK, JWKS, or PEM formats for use with identity providers, API gateways, and JWT signing services.

Protect private keys

Public JWKs may be published through JWKS endpoints, but private JWKs and PEM private keys should always remain confidential and never be embedded in client-side code.

Guide

About JWK and JWKS Generator

JWK and JWKS formats are used to publish verification keys and exchange key metadata in JWT, OAuth, and OpenID Connect systems.

This generator creates RSA, EC, or Ed25519 key pairs and exports public or private representations.

Only public key material should be published; private keys must remain protected.

Generated formats

Export key material in formats commonly used by JOSE libraries and infrastructure.

  • Public JWK
  • Optional private JWK
  • JWKS document
  • PEM public and private keys
  • RFC 7638 SHA-256 thumbprint

Key identifiers

A kid value helps verifiers select the correct key during key rotation and multi-key deployments.

Publishing a JWKS

Publish only public keys over HTTPS and use cache controls and rotation procedures appropriate for your identity system.

Private-key handling

Do not embed private JWKs or PEM keys in front-end bundles, public repositories, logs, or public JWKS endpoints.

FAQ

Frequently asked questions

Which key type should I generate?

Choose based on algorithm support, interoperability, policy, and deployment requirements.

Can a JWKS contain multiple keys?

Yes. Multiple keys support rotation and different algorithms or purposes.

Should I publish the private JWK?

No. Publish only the public members.

What is kid used for?

It allows a verifier to select a specific key from a JWKS.

Can PEM and JWK represent the same key?

Yes. They are different encodings of the same underlying key material.

Are keys generated locally?

Generation is intended to occur in your browser.

Continue exploring

Useful tools for the next step in the same workflow.