CipherLayer
Home / Tools / RSA-OAEP

RSA-OAEP Encryptor

Real RSA keypair generation and encryption (OAEP-SHA256) in your browser. Key fingerprint, modulus and exponent displayed in hex. PEM export ready to paste into OpenSSL or a JWT library.

2048 / 3072 / 4096 OAEP-SHA256 PEM export Fingerprint Keygen timing
RSA is slow. Use it for keys, not data. RSA can only encrypt messages up to ~190 bytes (for 2048-bit OAEP-SHA256). For anything larger, generate a random AES key, encrypt your data with AES-GCM, then encrypt the AES key with RSA. This tool shows the max-plaintext calculator.

Inputs

4096-bit keygen takes several seconds. The browser will block during this — be patient.

Output

// Output will appear here This is real RSA. Keygen is slow. Encryption is slower than AES by orders of magnitude — that's the price of asymmetric crypto.
Last operation
—
Time
—
Key size
—

Why this tool, and why this version

Most "RSA online" tools lie. They either hardcode a single test key, or they encrypt with textbook RSA (no padding), which is catastrophically broken — given a few ciphertexts and the public key, an attacker can recover any plaintext. Real RSA uses OAEP padding, which adds randomness to each encryption.

How OAEP works. OAEP — Optimal Asymmetric Encryption Padding — uses two hash functions and a random seed to transform the plaintext before modular exponentiation. The result: the same plaintext encrypted twice produces two different ciphertexts. This blocks the chosen-ciphertext attacks that break textbook RSA. OAEP-SHA256 is the modern standard.

Why keygen is slow. RSA key generation requires finding two large random primes p and q, then computing n = p × q and d = e⁻¹ mod φ(n). For 4096-bit RSA, each prime is ~2048 bits — there are roughly 2^2014 candidate primes per second on modern hardware, but you still need to test thousands. Expect 5–30 seconds for 4096-bit keys. 2048-bit takes ~1 second.

What this tool exposes. After generation, you see the modulus n in hex, the public exponent e (= 65537 by default), the private exponent d in hex, and the SHA-256 fingerprint of the DER-encoded public key. The fingerprint lets you verify a key out-of-band ("are you really sending me Alice's key?") without revealing the key itself.

Who this is for

Engineers debugging JWT or JWE

You need to encrypt a small payload (a JWT signing key, an API key) with RSA-OAEP. This tool produces PEM you can paste into Node.js or Python. No server. No accidental upload of your secret.

Cryptography students learning asymmetric encryption

Generating a key and seeing the modulus makes RSA concrete. The fingerprint display shows how SSH and TLS verify keys by hash. The max-plaintext calc shows why hybrid encryption exists.

Security researchers exploring RSA behavior

You want to know exactly what timing looks like, what exponents are produced, what the output format looks like. This tool exposes every parameter. Run with the console open.

Frequently asked questions

Why is RSA so slow? ▶
RSA encryption is one modular exponentiation: c = m^e mod n. With e = 65537, that's 17 modular multiplications of 2048-bit numbers. Each multiplication is many CPU cycles. AES on 16 bytes takes ~10 nanoseconds; RSA on the same number of plaintext bytes takes ~100 microseconds — 10,000× slower. AES uses hardware; RSA cannot. For bulk data, use RSA only to encrypt a symmetric key, then AES for the payload.
Can I encrypt a large file with RSA? ▶
No. RSA can only encrypt messages up to the key size minus padding overhead. For 2048-bit RSA-OAEP-SHA256, that's 190 bytes. For 4096-bit, 446 bytes. Anything larger would fail. The standard pattern is hybrid encryption: generate a random AES-256 key, encrypt your data with AES-GCM using that key, then RSA-OAEP-encrypt the AES key. Send both. This is what JWE does, what CMS does, and what PGP does.
What's OAEP? ▶
Optimal Asymmetric Encryption Padding. Invented by Bellare and Rogaway in 1994, standardized in PKCS#1 v2 and RFC 8017. Before OAEP, RSA was used with "textbook" padding (just prepend 0x00 0x02 || random || 0x00 || message) which is broken. OAEP uses two Feistel rounds with two hash functions to produce a randomized encoding of the plaintext, and includes a hash of any label (often empty). The result is IND-CCA2 secure — provably the strongest practical notion.
What's the difference between RSA and AES? ▶
AES is a symmetric cipher: same key encrypts and decrypts, very fast, no key distribution problem within a closed system. RSA is asymmetric: a public key encrypts, a private key decrypts, mathematically slow, but solves the key distribution problem — anyone can encrypt to you without sharing a secret first. Production systems use both: RSA to exchange an AES key, AES for the bulk data. This is called hybrid encryption.
Is 2048-bit RSA still safe? ▶
As of 2024, 2048-bit RSA is the minimum for new systems. NIST and BSI expect it to remain secure through 2030. Beyond that, 3072 or 4096 is recommended. RSA-1024 has been considered broken for over a decade. For high-value long-lived secrets (root CA keys, code-signing keys that must remain valid for years), use 4096-bit or move to elliptic-curve algorithms (ECDSA, Ed25519) which give equivalent security at much smaller key sizes.
Why is the public exponent always 65537? ▶
65537 = 2^16 + 1. It's a Fermat prime. Using e = 65537 makes public-key operations as fast as possible (17 multiplications instead of, say, 1000 for a random e). The reason it's safe: the security of RSA depends on the difficulty of computing d from e and n. As long as e is coprime to φ(n) (which 65537 always is for reasonable primes), the result is a valid private exponent. Using e = 3 is faster but breaks RSA in practice against certain attacks — so 65537 is the standard.

Limitations you should know