Tooleux

Encrypt a short message with an RSA public key using OAEP padding.

Runs in your browser. Nothing leaves your device.
Encrypt text with an RSA public key (RSA-OAEP SHA-256) in your browser. Free, offline, runs entirely client-side. Read more Show less

What is RSA encryption?

RSA is a public-key cryptosystem invented by Rivest, Shamir, and Adleman in 1977. It is one of the oldest and most widely deployed asymmetric algorithms. In encryption mode, a sender uses the recipient's public key to encrypt a short message; only the recipient, who holds the matching private key, can decrypt it.

RSA is used in TLS handshakes, S/MIME email, PGP, and many enterprise systems. It is slower than symmetric ciphers, so it is normally used only to encrypt a small symmetric key that then protects the bulk data. This is the hybrid encryption pattern.

How to use

Paste the recipient's public key in PEM format (SPKI, BEGIN PUBLIC KEY), type the plaintext you want to encrypt, and press Encrypt. The output is Base64 ciphertext.

To decrypt, use the RSA Decrypt tool with the matching private key.

Padding: OAEP

This tool uses RSA-OAEP with SHA-256. OAEP is the modern standard and is resistant to the attacks that broke early RSA encryption schemes. Older protocols sometimes use PKCS#1 v1.5, which is not supported here because it is considered insecure.

OAEP requires a hash function. Both ends must use the same one. SHA-256 is the current default.

Size limit

RSA-OAEP can only encrypt a message shorter than the modulus minus the padding overhead. For a 2048-bit key with SHA-256, the maximum message is 190 bytes. For a 4096-bit key, 446 bytes. Larger inputs must be encrypted with a symmetric cipher, with the symmetric key RSA-wrapped. This is what TLS, PGP, and every real system does.

FAQ

Is my private key safe?

This tool never sees the private key in encrypt mode - you only paste the public key, which is not secret. Nothing is uploaded. Everything runs in your browser.

Why is my message too long?

RSA-OAEP has a hard size limit of about 190 bytes for a 2048-bit key. If your message is longer, encrypt it with AES or ChaCha20 first and use RSA only to wrap the symmetric key.

What key size should I use?

2048-bit minimum for anything new. 3072-bit or 4096-bit for long-lived keys and high-value secrets. Generate keys on the RSA Key Generator.

PKCS#1 v1.5 vs OAEP?

OAEP is more secure and is what this tool uses. PKCS#1 v1.5 is vulnerable to padding oracle attacks if the implementation leaks information. If you have to interoperate with a legacy system that uses PKCS#1 v1.5, use a native library.

Can I use this to sign a message?

No. Signing is a different operation with different padding. Use the RSA Sign tool for that.

What format does the public key need to be in?

PKCS#8 SPKI PEM: starts with BEGIN PUBLIC KEY. If your key starts with BEGIN RSA PUBLIC KEY, it is PKCS#1 and needs converting. Run: openssl rsa -pubin -in key.pem -outform PEM -out key-spki.pem

Command line equivalent
# OpenSSL
# Encrypt with a public key
echo -n "hello" | openssl pkeyutl -encrypt -pubin -inkey public.pem -pkeyopt rsa_padding_mode:oaep -pkeyopt rsa_oaep_md:sha256 | base64

# Node with NodeRSA
node -e '
const NodeRSA = require("node-rsa");
const key = new NodeRSA(fs.readFileSync("public.pem"));
console.log(key.encrypt("hello", "base64"));
'

# Python with cryptography
python3 -c '
from cryptography.hazmat.primitives.asymmetric import padding
from cryptography.hazmat.primitives import hashes, serialization
import base64
pub = serialization.load_pem_public_key(open("public.pem","rb").read())
ct = pub.encrypt(b"hello", padding.OAEP(mgf=padding.MGF1(hashes.SHA256()), algorithm=hashes.SHA256(), label=None))
print(base64.b64encode(ct).decode())
'
Loads a test value into the form
Plaintext
Ciphertext