RSA Encrypt
Audience:
Low-code EngineersSkill Prerequisites:
Actions,Tokens
Encrypts one or more short values with an RSA public key and saves each result in a token. Only the matching private key can decrypt them, with RSA Decrypt.
RSA is asymmetric: the public key encrypts and the private key decrypts. You can share the public key freely. The action uses PKCS#1 v1.5 padding, encodes the text as UTF-8, and returns a base64 string.
Typical Use Cases
- Encrypt a short secret, such as a PIN or an AES key, so only the holder of the private key can read it
- Encrypt a value for a partner system that gave you its public key
- Let an app encrypt data that only a separate, protected process can decrypt
Don't use it to
- Encrypt long text. RSA only handles short values, see
Maximum length. Use AES Encrypt instead. - Store passwords. Passwords should be hashed, not encrypted.
- Sign data or prove who sent it. This action only encrypts.
Which to use
| You need to | Use |
|---|---|
| Let others encrypt data that only you can decrypt | RSA Encrypt with the public key, RSA Decrypt with the private key |
| Encrypt long text or many values quickly | AES Encrypt |
| Encrypt and decrypt inside your own app with one shared secret | AES Encrypt and AES Decrypt |
| Encrypt a value in the format the connector store uses | Connector Encrypt |
Related Actions
| Action Name | Description |
|---|---|
| RSA Decrypt | Decrypts values encrypted by this action, using the private key. |
| Generate RSA Keys | Creates a key pair in PEM format. See Key format before you use it with this action. |
| AES Encrypt | Encrypts values of any length with a shared key. |
| AES Decrypt | Decrypts AES-encrypted values. |
| Get Connector | Reads connector properties into tokens, for example to load a key. |
Input Parameter Reference
| Parameter | Description | Supports Tokens | Default | Required |
|---|---|---|---|---|
| Public Key | The RSA public key in .NET XML format, starting with <RSAKeyValue>. PEM keys (-----BEGIN PUBLIC KEY-----) aren't accepted. Use the key generator linked in the parameter's help text to create a key pair in the right format. | Yes | empty string | Yes |
| Fields | A list of values to encrypt. In Data to Encrypt, enter the value, usually a token such as [Pin]. In Store in Token, enter the name of the token that gets the encrypted result, such as PinEncrypted. Square brackets around the name are removed. | Yes, in Data to Encrypt | empty | Yes |
Output Parameters Reference
| Token | Description |
|---|---|
[<Store in Token>] | One token for each row in Fields, holding the encrypted value as a base64 string. An empty input gives an empty string. |
Key format
The key must be XML, like this shape (values shortened):
<RSAKeyValue><Modulus>...</Modulus><Exponent>AQAB</Exponent></RSAKeyValue>
The key generator linked in the Public Key help text creates a public and private key in this format. Where it asks for a key size, it accepts 1024 to 16384 bits in steps of 1024. Use 2048 or more.
The Generate RSA Keys action creates PEM keys instead, which this action can't read. If a partner sends a PEM key, convert it to XML with an external tool first.
Maximum length
RSA can only encrypt a value shorter than the key. With PKCS#1 v1.5 padding, the limit is the key size in bytes minus 11, counted after UTF-8 encoding:
| Key size | Maximum value length |
|---|---|
| 1024 bits | 117 bytes |
| 2048 bits | 245 bytes |
| 4096 bits | 501 bytes |
Letters like é or ü take two bytes, and many symbols take more. If a value is too long, the action fails. To encrypt longer data, encrypt it with AES Encrypt and use RSA only for the AES key.
Considerations
- Old padding. The action uses PKCS#1 v1.5 padding, not the newer OAEP. It's widely supported, but it's weaker. If decryption errors are shown to outsiders, an attacker can sometimes use them to work out encrypted values. The other side must also use PKCS#1 v1.5 to decrypt.
- The result changes each time. Encrypting the same value twice gives different results. That's normal, and both decrypt to the same text.
- Errors stop the action. An invalid key or a value that's too long makes the action fail. Use the
On Erroractions of Execute Actions to handle it. - Empty key does nothing. If the key is empty, for example because a token didn't resolve, no tokens are set.
- Use a strong key. 1024-bit keys are no longer considered safe. Use 2048 bits or more.
- Only the private key matters for secrecy. The public key can be in the action. Keep the private key away from anywhere this action runs if the app only needs to encrypt.
Examples
To understand how to use the below examples, please see Running Examples.
1. Encrypt a PIN with a partner's public key
This action encrypts [Pin] with the public key in the [PartnerPublicKey] token and saves the result in [PinEncrypted].
{
"Title": "RSA Encrypt",
"ActionType": "RSAEncrypt",
"Description": "Encrypt the PIN for the partner",
"Condition": "[Pin] != \"\"",
"Parameters": {
"Key": "[PartnerPublicKey]",
"Fields": {
"[Pin]": "PinEncrypted"
}
}
}
Revised 09/27/2026