Skip to main content
Version: 1.28 (Current)

RSA Encrypt

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens

Encrypts one or more short values with an RSA public key and saves each result in a token. Only the matching private key can decrypt them, with RSA Decrypt.

RSA is asymmetric: the public key encrypts and the private key decrypts. You can share the public key freely. The action uses PKCS#1 v1.5 padding, encodes the text as UTF-8, and returns a base64 string.

Typical Use Cases​

  • Encrypt a short secret, such as a PIN or an AES key, so only the holder of the private key can read it
  • Encrypt a value for a partner system that gave you its public key
  • Let an app encrypt data that only a separate, protected process can decrypt

Don't use it to​

  • Encrypt long text. RSA only handles short values, see Maximum length. Use AES Encrypt instead.
  • Store passwords. Passwords should be hashed, not encrypted.
  • Sign data or prove who sent it. This action only encrypts.

Which to use​

You need toUse
Let others encrypt data that only you can decryptRSA Encrypt with the public key, RSA Decrypt with the private key
Encrypt long text or many values quicklyAES Encrypt
Encrypt and decrypt inside your own app with one shared secretAES Encrypt and AES Decrypt
Encrypt a value in the format the connector store usesConnector Encrypt
Action NameDescription
RSA DecryptDecrypts values encrypted by this action, using the private key.
Generate RSA KeysCreates a key pair in PEM format. See Key format before you use it with this action.
AES EncryptEncrypts values of any length with a shared key.
AES DecryptDecrypts AES-encrypted values.
Get ConnectorReads connector properties into tokens, for example to load a key.

Input Parameter Reference​

ParameterDescriptionSupports TokensDefaultRequired
Public KeyThe RSA public key in .NET XML format, starting with <RSAKeyValue>. PEM keys (-----BEGIN PUBLIC KEY-----) aren't accepted. Use the key generator linked in the parameter's help text to create a key pair in the right format.Yesempty stringYes
FieldsA list of values to encrypt. In Data to Encrypt, enter the value, usually a token such as [Pin]. In Store in Token, enter the name of the token that gets the encrypted result, such as PinEncrypted. Square brackets around the name are removed.Yes, in Data to EncryptemptyYes

Output Parameters Reference​

TokenDescription
[<Store in Token>]One token for each row in Fields, holding the encrypted value as a base64 string. An empty input gives an empty string.

Key format​

The key must be XML, like this shape (values shortened):

<RSAKeyValue><Modulus>...</Modulus><Exponent>AQAB</Exponent></RSAKeyValue>

The key generator linked in the Public Key help text creates a public and private key in this format. Where it asks for a key size, it accepts 1024 to 16384 bits in steps of 1024. Use 2048 or more.

The Generate RSA Keys action creates PEM keys instead, which this action can't read. If a partner sends a PEM key, convert it to XML with an external tool first.

Maximum length​

RSA can only encrypt a value shorter than the key. With PKCS#1 v1.5 padding, the limit is the key size in bytes minus 11, counted after UTF-8 encoding:

Key sizeMaximum value length
1024 bits117 bytes
2048 bits245 bytes
4096 bits501 bytes

Letters like é or ü take two bytes, and many symbols take more. If a value is too long, the action fails. To encrypt longer data, encrypt it with AES Encrypt and use RSA only for the AES key.

Considerations​

  • Old padding. The action uses PKCS#1 v1.5 padding, not the newer OAEP. It's widely supported, but it's weaker. If decryption errors are shown to outsiders, an attacker can sometimes use them to work out encrypted values. The other side must also use PKCS#1 v1.5 to decrypt.
  • The result changes each time. Encrypting the same value twice gives different results. That's normal, and both decrypt to the same text.
  • Errors stop the action. An invalid key or a value that's too long makes the action fail. Use the On Error actions of Execute Actions to handle it.
  • Empty key does nothing. If the key is empty, for example because a token didn't resolve, no tokens are set.
  • Use a strong key. 1024-bit keys are no longer considered safe. Use 2048 bits or more.
  • Only the private key matters for secrecy. The public key can be in the action. Keep the private key away from anywhere this action runs if the app only needs to encrypt.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

1. Encrypt a PIN with a partner's public key​

This action encrypts [Pin] with the public key in the [PartnerPublicKey] token and saves the result in [PinEncrypted].

{
"Title": "RSA Encrypt",
"ActionType": "RSAEncrypt",
"Description": "Encrypt the PIN for the partner",
"Condition": "[Pin] != \"\"",
"Parameters": {
"Key": "[PartnerPublicKey]",
"Fields": {
"[Pin]": "PinEncrypted"
}
}
}

Revised 09/27/2026