Ed25519 Key Generator
Generate an Ed25519 key pair, or derive one from a 32-byte seed.
Generate an Ed25519 key pair (RFC 8032). Free, offline, runs in your browser. Read more Show less
What is Ed25519?
Ed25519 is a digital signature scheme using Curve25519 and SHA-512, defined in RFC 8032. It is used by SSH, Signal, Tor, WireGuard, DNS (DNSSEC), and most modern blockchain and decentralized-identity systems.
An Ed25519 key pair has a 32-byte private key (a seed) and a 32-byte public key. Signatures are 64 bytes. This is dramatically smaller than RSA (256+ byte keys, 256+ byte signatures) and smaller than ECDSA P-256 (32-byte keys, 64-byte signatures) while being faster to verify.
How to generate a key pair
Leave the seed empty for a cryptographically random key pair. Or paste a 32-byte seed (hex or Base64) to derive the same pair every time - useful for tests, deterministic wallets, and reproducible builds.
Never reuse a seed across different purposes. If you paste a seed, delete it before sharing your screen.
Key format
The private key is the raw 32-byte seed. The public key is the raw 32-byte curve point. This tool displays them in hex or Base64.
Many tools store Ed25519 keys in PEM format (-----BEGIN PRIVATE KEY-----), which wraps the same bytes in DER/PKCS#8. If you need PEM, encode the 32 bytes with a library such as @peculiar/x509 or openssl pkey.
FAQ
Is Ed25519 the same as EdDSA?
EdDSA is the algorithm family. Ed25519 is the specific instance using Curve25519 and SHA-512. There is also Ed448 (Curve448, SHAKE256), which is not covered here.
Ed25519 vs ECDSA P-256
Both give ~128-bit security. Ed25519 is deterministic (no random nonce, so no nonce-reuse attack), simpler to implement safely, and faster in software. ECDSA P-256 is more widely supported in FIPS environments. If you have a choice, pick Ed25519.
Can I use this to derive a Bitcoin or Ethereum address?
Not directly. Bitcoin uses secp256k1, Ethereum uses secp256k1 with Keccak-256. Ed25519 is used by Solana, Cardano, and Stellar. To derive a Bitcoin address, use a secp256k1 tool.
How do I store the private key?
Treat it like a password. Encrypt it with AES-GCM or ChaCha20-Poly1305 before saving it anywhere. Never commit it to a repository.
Command line equivalent
# OpenSSL 3.x
openssl genpkey -algorithm ED25519 -out private.pem
openssl pkey -in private.pem -pubout -out public.pem
openssl pkey -in private.pem -text -noout
# Node with @noble/ed25519
npm i @noble/ed25519
node --input-type=module -e '
import * as ed from "@noble/ed25519";
const priv = randomBytes(32);
const pub = await ed.getPublicKeyAsync(priv);
console.log("Public: ", Buffer.from(pub).toString("hex"));
console.log("Private:", Buffer.from(priv).toString("hex"));
'
# Python with cryptography
pip install cryptography
python3 -c 'from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey;
k = Ed25519PrivateKey.generate();
print(k.private_bytes_raw().hex()); print(k.public_key().public_bytes_raw().hex())'