key pair
a key pair is the matched set of one public key you share and one private key you never share - the whole basis of pgp identity.
public-key cryptography splits one logical key into two halves generated together. the public key can be posted anywhere - it lets people encrypt messages to you and verify your signatures. the private key is the only thing that can decrypt those messages and create those signatures, so its secrecy is your entire identity.
the asymmetry is one-directional by design: deriving the private half from the public half would take longer than the age of the universe with known math. that is what lets you publish a key on a market profile without enabling anyone to read your mail.
operational rules follow directly. protect the private key with a strong passphrase (that is what s2k stretching is for), keep a backup somewhere safe since lost keys cannot be recovered, and treat a private key that has ever touched a sketchy machine or been pasted into a website as burned - generate a fresh pair and republish the fingerprint.
generate keys locally, always. our key generator runs entirely in javascript in your browser precisely so the private half is created and stays on your machine - a key generator on someone else's server is a key you do not really own.