RSA encrypt

Encrypt a short message to someone's RSA public key — OAEP or PKCS#1 v1.5, SHA-256/384/512 — and get base64 ciphertext. Runs in your browser; nothing is uploaded.

Ciphertext (base64)

About this tool

RSA encrypt encrypts a short message to a recipient's RSA public key and returns the result as base64 ciphertext. Only the holder of the matching private key can decrypt it — so you can share the ciphertext over any channel.

Privacy

Everything runs in your browser via WebAssembly — the public key and the message are never uploaded to a server. You can also run it from the gizza CLI or inside a gizza chat.

Notes

FAQ

Why do I get "message too long for this key/padding"?

RSA encrypts only a single block. With a 2048-bit key that's about 190 bytes using OAEP-SHA256 or 245 bytes with PKCS#1 v1.5 — larger OAEP hashes leave even less room. For anything bigger, use hybrid encryption: encrypt a random AES key with RSA and encrypt the actual data with that AES key.

Which key formats and paddings are supported?

Public keys in PEM — either SPKI (-----BEGIN PUBLIC KEY-----) or PKCS#1 (-----BEGIN RSA PUBLIC KEY-----); both are auto-detected. Padding is OAEP (recommended, with a SHA-256/384/512 hash for MGF1) or legacy PKCS#1 v1.5. The hash choice is ignored when you pick PKCS#1 v1.5.

Why is the ciphertext different every time I encrypt the same message?

Both OAEP and PKCS#1 v1.5 are randomized — they mix in fresh random bytes on each run — so identical plaintext produces different base64 output every time. That's expected and is what keeps RSA encryption secure; any correct private key still decrypts it back to the same message.

Is the public key or message sent to a server?

No. Encryption runs entirely in your browser via WebAssembly, so the public key and plaintext never leave your device. To decrypt, use any standard RSA library with the matching private key and the same padding and hash.

Developer & Automation Access

Run it from the terminal

Same engine as this page, headless — via the gizza CLI:

gizza tool rsa-encrypt "The short message to encrypt" 'public_key=-----BEGIN PUBLIC KEY-----
...
-----END PUBLIC KEY-----'

New to the CLI? Get gizza →

Open it by URL

Pre-fill and auto-run this tool with query parameters — the names match the API/CLI:

https://gizza.ai/tools/rsa-encrypt/?message=The%20short%20message%20to%20encrypt&public_key=-----BEGIN%20PUBLIC%20KEY-----%0A...%0A-----END%20PUBLIC%20KEY-----&padding=oaep&hash=sha256

Machine-readable descriptor: tool.json — title + parameters JSON Schema for agents.