Tooleux

Ed25519 Key Generator

EdDSA (3)

Generate an Ed25519 key pair, or derive one from a 32-byte seed.

Runs in your browser. Nothing leaves your device.
Generate an Ed25519 key pair (RFC 8032). Free, offline, runs in your browser. Read more Show less

What is Ed25519?

Ed25519 is a digital signature scheme using Curve25519 and SHA-512, defined in RFC 8032. It is used by SSH, Signal, Tor, WireGuard, DNS (DNSSEC), and most modern blockchain and decentralized-identity systems.

An Ed25519 key pair has a 32-byte private key (a seed) and a 32-byte public key. Signatures are 64 bytes. This is dramatically smaller than RSA (256+ byte keys, 256+ byte signatures) and smaller than ECDSA P-256 (32-byte keys, 64-byte signatures) while being faster to verify.

How to generate a key pair

Leave the seed empty for a cryptographically random key pair. Or paste a 32-byte seed (hex or Base64) to derive the same pair every time - useful for tests, deterministic wallets, and reproducible builds.

Never reuse a seed across different purposes. If you paste a seed, delete it before sharing your screen.

Key format

The private key is the raw 32-byte seed. The public key is the raw 32-byte curve point. This tool displays them in hex or Base64.

Many tools store Ed25519 keys in PEM format (-----BEGIN PRIVATE KEY-----), which wraps the same bytes in DER/PKCS#8. If you need PEM, encode the 32 bytes with a library such as @peculiar/x509 or openssl pkey.

FAQ

Is Ed25519 the same as EdDSA?

EdDSA is the algorithm family. Ed25519 is the specific instance using Curve25519 and SHA-512. There is also Ed448 (Curve448, SHAKE256), which is not covered here.

Ed25519 vs ECDSA P-256

Both give ~128-bit security. Ed25519 is deterministic (no random nonce, so no nonce-reuse attack), simpler to implement safely, and faster in software. ECDSA P-256 is more widely supported in FIPS environments. If you have a choice, pick Ed25519.

Can I use this to derive a Bitcoin or Ethereum address?

Not directly. Bitcoin uses secp256k1, Ethereum uses secp256k1 with Keccak-256. Ed25519 is used by Solana, Cardano, and Stellar. To derive a Bitcoin address, use a secp256k1 tool.

How do I store the private key?

Treat it like a password. Encrypt it with AES-GCM or ChaCha20-Poly1305 before saving it anywhere. Never commit it to a repository.

Command line equivalent
# OpenSSL 3.x
openssl genpkey -algorithm ED25519 -out private.pem
openssl pkey -in private.pem -pubout -out public.pem
openssl pkey -in private.pem -text -noout

# Node with @noble/ed25519
npm i @noble/ed25519
node --input-type=module -e '
import * as ed from "@noble/ed25519";
const priv = randomBytes(32);
const pub = await ed.getPublicKeyAsync(priv);
console.log("Public: ", Buffer.from(pub).toString("hex"));
console.log("Private:", Buffer.from(priv).toString("hex"));
'

# Python with cryptography
pip install cryptography
python3 -c 'from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey;
k = Ed25519PrivateKey.generate();
print(k.private_bytes_raw().hex()); print(k.public_key().public_bytes_raw().hex())'
Loads a test value into the form
Key pair