SSH Key Fingerprint
Compute SHA-256 and MD5 fingerprints from an OpenSSH public key. Shows algorithm and key size.
Compute the SHA-256 and MD5 fingerprint of an SSH public key. Parses algorithm, key size, and comment from OpenSSH format. Read more Show less
What is an SSH key fingerprint?
An SSH key fingerprint is a short, fixed-length hash of an SSH public key. It exists because a public key is too long to compare by eye - the base64 blob is hundreds of characters - and because two keys that look similar can be completely different. The fingerprint reduces the key to a single string that a human can read aloud, compare visually, or verify against a server's published key.
When you first connect to an SSH server, your client shows you the server's fingerprint and asks whether to trust it. When a server's key changes unexpectedly, the client refuses to connect and warns you. Both behaviors depend on the fingerprint being a stable, unforgeable summary of the underlying key.
How to use
Paste a line from your ~/.ssh/id_ed25519.pub, ~/.ssh/id_rsa.pub, or any other .pub file. The tool parses the algorithm token, the base64 blob, and the trailing comment, then shows:
- SHA-256 fingerprint - the modern default, formatted as
SHA256:base64hashwith no padding. - MD5 fingerprint - the legacy format, formatted as
MD5:aa:bb:cc:.... Still what older tooling expects. - Algorithm and key size - parsed from the base64 blob, not trusted from the comment.
- ssh-keygen equivalent - what you would see if you ran
ssh-keygen -lfon the same file.
Supported algorithms
The parser understands the standard OpenSSH key types:
- ssh-ed25519 - EdDSA on Curve25519, 256-bit keys. The modern default.
- ssh-ed448 - EdDSA on Curve448, 456-bit keys.
- ssh-rsa - RSA, key size read from the modulus length (1024, 2048, 3072, 4096, and so on).
- ecdsa-sha2-nistp256, nistp384, nistp521 - ECDSA on NIST curves.
- sk-ssh-ed25519@openssh.com, sk-ecdsa-sha2-nistp256@openssh.com - FIDO/U2F hardware-backed keys.
- ssh-dss - DSA. Deprecated and should not be used for new keys, but still parseable.
The OpenSSH public key format
A public key line has three parts, separated by spaces:
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAI... user@host
Part 1 is the algorithm name. Part 2 is a base64-encoded binary blob containing the algorithm name again (as a length-prefixed string) followed by the key material. Part 3 is an optional comment - often user@host, but it is free text and carries no cryptographic meaning. The comment is what the user chose when they created the key, and it is not part of the fingerprint.
The fingerprint is computed over the entire decoded base64 blob, not over the base64 text and not over the algorithm name separately. Two keys with the same algorithm but different key material produce different fingerprints.
SHA-256 vs MD5 fingerprints
Before OpenSSH 6.8 (2014), the default fingerprint format was MD5, shown as sixteen colon-separated hex byte pairs. Since 6.8, the default is SHA-256, shown as a base64 string prefixed with SHA256:. The SHA-256 form is shorter and both collision-resistant and preimage-resistant, which MD5 is not.
Some older documentation, CI systems, and known_hosts entries still use MD5. This tool shows both so you can compare against either format.
What this tool does not do
It does not generate keys. It does not sign or verify anything. It does not touch your private key. A public key is by definition public - pasting it anywhere is safe - but this tool never asks for, accepts, or processes private key material.
Everything runs in your browser. The key you paste is not sent anywhere.
FAQ
Is my public key safe to paste online?
Yes. A public key is designed to be shared - it appears in authorized_keys files on every server you connect to, and in your GitHub profile settings. There is no secret in a public key.
Is my private key safe to paste?
Never paste a private key into any online tool, including this one. A private key must stay on the machine that generated it, with restrictive file permissions. This tool will reject input that looks like a private key rather than parse it.
Why do I see two fingerprints?
Because SSH still lives in a transition period. Old systems expect MD5, new ones expect SHA-256. Both are computed from the same underlying blob, so they are consistent with each other.
Why does the key size read 256 for my ed25519 key?
Because ed25519 keys are always 256 bits. The algorithm is fixed-size - the only choice a user makes is the comment, not the key length. This is unlike RSA, where you choose 2048, 3072, 4096, or another modulus size.
What is a known_hosts entry?
The file ~/.ssh/known_hosts stores the fingerprints of every server you have connected to. When you reconnect, SSH checks the fingerprint against what is stored. If it does not match, the connection is refused until you explicitly remove the old entry. This is the mechanism that stops man-in-the-middle attacks after the first connection.
What does the @openssh.com suffix on some algorithms mean?
It marks a key type that was added by OpenSSH but never standardized by an RFC. The sk- prefix indicates a security key - a FIDO/U2F hardware token that requires a physical touch to use.
Command line equivalent
# ssh-keygen -lf
ssh-keygen -lf ~/.ssh/id_ed25519.pub
# MD5 fingerprint explicitly
ssh-keygen -lf ~/.ssh/id_ed25519.pub -E md5
# Older OpenSSH (< 6.8) - prints MD5 by default
ssh-keygen -l -f ~/.ssh/id_rsa.pub
# Read the key with Python
python3 -c 'import base64,hashlib,sys; k=open(sys.argv[1]).read().split(); blob=base64.b64decode(k[1]); print("SHA256:"+base64.b64encode(hashlib.sha256(blob).digest()).decode().rstrip("="))' ~/.ssh/id_ed25519.pub