---
title: chronoctl gen-keypair
description: The gen-keypair command generates an RSA keypair and writes it to the file system.
url: https://docs.influxdata.com/chronograf/v1/tools/chronoctl/gen-keypair/
estimated_tokens: 344
product: Chronograf
version: v1
publisher: InfluxData
canonical: https://docs.influxdata.com/chronograf/v1/tools/chronoctl/gen-keypair/
date: '2023-10-17T11:22:14-06:00'
lastmod: '2023-10-17T11:22:14-06:00'
---

The `gen-keypair` command generates an RSA keypair and writes it to the file system.
Private keys are stored in a file at a specified location.
Private keys are stored in the same location using the same name with the `.pub`extension added.

## Usage

```sh
chronoctl gen-keypair [flags]
```

## Flags

|Flag|        |                             Description                             |Input type|
|----|--------|---------------------------------------------------------------------|----------|
|    |`--bits`|Number of bits to use to generate the RSA keypair *(default is 4096)*| integer  |
|`-h`|`--help`|                         Output command help                         |          |
|    |`--out` |    Keypair file path to write to *(default is `chronograf-rsa`)*    |  string  |

## Examples

The following example generates a 4096 bit RSA keypair and writes the following
files to the local file system:

* `/path/to/chrono-rsa`: Private key
* `/path/to/chrono-rsa.pub`: Public key

```sh
chronoctl gen-keypair --out /path/to/chrono-rsa
```
| Flag |  | Description | Input type |
| --- | --- | --- | --- |
| Flag |  | Description | Input type |
|  | --bits | Number of bits to use to generate the RSA keypair  (default is 4096) | integer |
| -h | --help | Output command help |  |
|  | --out | Keypair file path to write to  (default is  chronograf-rsa ) | string |
