SSH Public Key Inspector
Paste an OpenSSH public key line to read its type, size and SHA256 fingerprint.
Paste a public key line on the left.
How it works
An OpenSSH public key line is <type> <base64> [comment]. The base64 decodes to SSH's own
wire format — a sequence of length-prefixed fields, the algorithm name repeated inside the blob itself. This reads
that wire format directly rather than trusting the leading type word, since the two can disagree.
It is safe to paste a public key here — that is what a public key is for. This tool never asks for, accepts, or processes a private key.
Fingerprint format
The fingerprint shown is SHA256 only, in the ssh-keygen -lf default format. The legacy MD5 colon-hex
fingerprint some older tooling still prints is not generated — WebCrypto has no MD5 implementation, the same
limitation the Certificate Fingerprint Calculator documents.
Example
An Ed25519 key always reports 256 bits — the format uses a fixed-size 32-byte key by design, unlike RSA where the bit length varies by how the key was generated.
Frequently asked questions
Is it safe to paste my SSH public key here?
Yes — an SSH public key is designed to be shared; it is what you put in authorized_keys or a Git host's account settings. This tool would refuse to be useful for anything requiring the private key, since it never asks for one.
Why does the algorithm name come from inside the base64, not the leading word on the line?
Because the two can disagree — a key line can claim ssh-rsa as its leading word while the base64 blob decodes to something else entirely. Reading the wire format directly, the same way ssh-keygen and a real SSH client do, is the only way to get a trustworthy answer.
Why is my Ed25519 key always 256 bits?
Ed25519 uses a fixed-size 32-byte (256-bit) key by design — there is no variable key-size choice the way there is with RSA. That fixed size is part of why it is fast to inspect and simple to fingerprint.
Related tools
X.509 Certificate Decoder
Paste a PEM certificate to read its subject, issuer, validity, key and extensions.
LocalCertificate Fingerprint Calculator
Paste a PEM certificate, get its SHA-1 and SHA-256 fingerprint.
LocalHash Identifier
Narrow an unlabelled hash down to the algorithms that could have produced it.
LocalCSR Decoder
Paste a PKCS#10 CSR to read its requested subject, key and Subject Alternative Names.
LocalPassword Entropy Checker
A charset-and-length entropy estimate, with the math and its limits shown, not a bare score.
LocalSecret Pattern Detector
Scan pasted text or code for the shape of a leaked API key, token or private key.
Local