you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 1 min ago 255 onions tracked
home / tools / pgp key generator

pgp key generator

create your personal pgp key pair in three steps. with javascript on, everything happens inside your browser - once this page has loaded you can even go offline before generating. with javascript off, the key is created on our server instead - in memory only, never stored.

you end up with two things: a public key you give to everyone, and a private key nobody else may ever see.

privacy

two ways to run this. locally in your browser (javascript on) is the most private option - your key material never leaves your device. server-side without js: the same button submits this form and our server generates the key in memory for that single request, then discards it - nothing is logged or stored.

1

who is the key for?

this is just a label people will see next to your key.

at least one of the two is required so the key has an identity attached.

2

lock it with a passphrase

if anyone ever gets hold of your private key file, this passphrase is the only thing stopping them from using it.

a passphrase protects the private key file: without it, anyone who gets the file can use your key. with one, you need the passphrase every time you sign or decrypt. four or five random words beat any password.

advanced: key type

the no-javascript path always generates rsa-4096 - curve25519 needs javascript.

3

generate

takes a second on curve25519, up to a minute on rsa-4096.

where should this run?

faq

is this actually safe?
with javascript on, the generation happens with openpgp.js in your machine's browser tab - your passphrase and private key never leave the browser, no upload exists in the code. with javascript off, the form posts to our server and the key is generated there in memory for that single request, then discarded - nothing is logged or stored. that fallback only makes rsa-4096 keys.
which key type should i pick?
curve25519 unless something specifically demands rsa. it is faster to generate, produces smaller keys and messages, and is the modern default across the ecosystem. without javascript you get rsa-4096 regardless.
the "suggest one" passphrase - can i trust it?
it is built from random words using your browser's crypto random generator, on your machine, and never transmitted. feel free to roll your own instead - length and unpredictability are what matter.
i lost my private key / passphrase. can you recover it?
nobody can. that is the entire point of public-key cryptography. back both up before you need them.