All tools

SSH Key Generator

Generate Ed25519 and RSA SSH keys locally

Create Ed25519, ECDSA or RSA key pairs in OpenSSH format in your browser, with fingerprints and an authorized_keys line.

How to use SSH Key Generator

  1. Pick a Key type: Ed25519 (recommended, if your browser supports it), ECDSA P-256/P-384/P-521, or RSA 2048/3072/4096.
  2. Optionally type a Comment (often you@laptop), then press Generate.
  3. Download id_ed25519 and id_ed25519.pub (or id_ecdsa / id_rsa) into ~/.ssh, run chmod 600 on the private key, and add a passphrase with ssh-keygen -p -f ~/.ssh/id_ed25519.
  4. Copy the Public key or the authorized_keys line (with optional restrict, from=, command= and other options) to the server.

How it works

Keys are generated by your browser’s Web Crypto API (crypto.subtle.generateKey): Ed25519, ECDSA on the NIST curves, or RSASSA-PKCS1-v1_5 with exponent 65537. The tool then encodes them itself in SSH wire format (RFC 4251 strings and mpints): the public key line is type base64(blob) comment, and the private key is written in OpenSSH’s openssh-key-v1 format with the none cipher and KDF, two matching random check integers, the comment and 1, 2, 3… padding.

The SHA-256 fingerprint is the unpadded Base64 SHA-256 of the public key blob, as ssh-keygen -l shows it; the MD5 fingerprint is the legacy colon-separated form. PKCS#8 and SPKI PEM copies come straight from Web Crypto’s export, for tools that want standard PEM.

Limits

  • The private key is not encrypted. Add a passphrase afterwards with ssh-keygen -p; this tool doesn’t implement bcrypt-pbkdf encryption.
  • Ed25519 needs a browser whose Web Crypto supports it (recent Chrome, Edge, Firefox and Safari). Otherwise the option is disabled and ECDSA or RSA remain.
  • No DSA, no FIDO/security-key (-sk) types, and no certificates.
  • RSA 4096 can take several seconds to generate on slow devices.

Privacy

Keys are generated in your browser and never uploaded or stored. They exist only in this tab until you download or copy them, and this tool doesn’t create share links. Send to… only offers the public key.

Frequently asked questions

Which key type should I choose?

Ed25519: it is small, fast and the default in modern OpenSSH. Use RSA 3072 or 4096 only for old servers that don’t accept Ed25519 or ECDSA.

Is it safe to generate SSH keys in a browser?

The randomness and key generation come from the same Web Crypto implementation browsers use for TLS, and nothing leaves the page. For high-value keys, generating with ssh-keygen on the machine that uses them is still the gold standard.

How do I add a passphrase to the private key?

Save it to ~/.ssh/id_ed25519, run chmod 600 ~/.ssh/id_ed25519, then ssh-keygen -p -f ~/.ssh/id_ed25519 and enter a new passphrase.

What is the authorized_keys line for?

Append it to ~/.ssh/authorized_keys on the server. Options such as restrict, from="10.0.0.0/8" or command="…" limit what the key can do and where it can be used from.

How do I check the fingerprint matches?

Run ssh-keygen -l -f ~/.ssh/id_ed25519.pub. It prints the same SHA256:… value shown here.

More tools