Nếu đặt, khóa riêng sẽ được mã hóa bằng nó. Quên nó thì khóa không dùng được nữa.
ECC Curve25519 — khuyến nghị: nhanh, hiện đại, khóa nhỏ.
Giữ an toàn khóa riêng của bạn. Nếu mất thì không thể khôi phục. Khóa được tạo hoàn toàn trong trình duyệt và không bao giờ gửi đi đâu — hãy tải xuống nếu không chúng sẽ mất.
(Tài liệu bằng tiếng Anh)
What it does
The PGP Key Generator creates OpenPGP key pairs — a public key you share with anyone who wants to send you encrypted mail or verify your signatures, and a private key you keep secret. It also produces a revocation certificate: a pre-made signature that marks the key as retired if it is ever lost, stolen, or compromised. Key generation runs 100% in your browser (via OpenPGP.js) — your private key is never transmitted, logged, or stored anywhere.
You choose between ECC (Curve25519) — the modern default: fast to generate, small keys, strong security — and the classic RSA in 2048- or 4096-bit sizes for compatibility with older OpenPGP implementations. An optional passphrase encrypts the private key at rest, so a stolen key file alone cannot be used.
How to use it
- Enter your Name and Email — they become the key’s user ID (
Ada Lovelace <ada@example.com>). - Optionally set a Passphrase. It encrypts the private key; forget it and the key is unusable. Use the eye toggle to show it.
- Pick an Algorithm: ECC (recommended), RSA 2048, or RSA 4096 (generation can take a few seconds).
- Press Generate key pair and wait for the spinner to finish.
- Copy or Download your public key (
public-key.asc) — share this one freely. - Copy or Download your private key (
private-key.asc) — store it somewhere safe. - Expand Revocation certificate and download it (
revocation-cert.asc). Print it and store it offline for emergencies.
Examples
An ECC identity key
Input: name Ada Lovelace, email ada@example.com, algorithm ECC, no passphrase.
Output (truncated):
-----BEGIN PGP PUBLIC KEY BLOCK-----
xjMEZ9xKchYJKwYBBAHaRwBA9D4A5FSsD3vE…
=mBdA
-----END PGP PUBLIC KEY BLOCK-----
Fingerprint: 9A4C 82B1 6C9E 03F2 4721 88AB D05F 33E1 7C42 6019
An RSA-4096 key with a passphrase
Input: name Ada Lovelace, email ada@example.com, passphrase correct horse battery staple, algorithm RSA 4096 → a -----BEGIN PGP PRIVATE KEY BLOCK----- that asks for the passphrase when imported into GnuPG.
A revocation certificate
-----BEGIN PGP PUBLIC KEY BLOCK-----
Comment: This is a revocation certificate
…
-----END PGP PUBLIC KEY BLOCK-----
Good to know
- ECC vs RSA: ECC Curve25519 keys are ~300 bytes armored and generate in milliseconds; RSA-4096 keys are several kilobytes and can take tens of seconds in a browser. Both are considered secure; pick RSA only when you must interoperate with very old OpenPGP software.
- Revocation certificate: publish it to a keyserver (or give it to a friend) only when you want to retire the key. Anyone holding it can revoke the key — that is its power and its risk.
- Private: runs 100% client-side. Refreshing the page without downloading discards the key permanently — by design.
- Related tools: PGP Encrypt/Decrypt, SSH Key Generator,
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
Generator, Passphrase Generator.