A self-signed certificate is an X.509 certificate that is signed with its own private key instead of a trusted Certificate Authority (CA). It provides the same encryption as a CA-issued certificate, but browsers and operating systems won't trust it automatically, so it's best suited for local development, internal tools, and testing rather than public-facing production traffic.
This generator creates a 2048-bit (or larger) RSA key pair and a matching certificate directly in your browser — nothing is uploaded or stored on a server. Fill in the subject fields (Common Name, Organization, etc.), pick a key size, validity period and hash algorithm, then generate. The Common Name is also used as the certificate's Subject Alternative Name (DNS), which modern browsers require for TLS to work.
Once generated, download the private key, public key and certificate together as a Zip or a JSON file, or copy each one individually. Keep the private key secret — anyone who has it can impersonate the certificate.
Is a self-signed certificate safe for production?
No — browsers and clients won't trust it automatically, so it's best for local development, internal tools, or testing TLS configuration, not for public-facing production traffic.
Does the private key ever leave my browser?
No — the key pair and certificate are generated entirely client-side; nothing is uploaded or transmitted.
What key size and validity should I pick?
RSA 2048-bit is a reasonable default for development use; pick a short validity period (days to a few months) so expired test certificates don't accidentally linger.