Code tool

SSH Public Key Fingerprint

Compute SHA256 or legacy MD5 fingerprints from an OpenSSH public key’s decoded binary blob, locally in your browser.

In-browser processingNo account requiredPrivacy details ↗

Public keys only. Input and output stay in current page memory; no upload or saved history. Never paste a private key.

Accepts an optional comma-separated authorized_keys options prefix and trailing comment. Quoted spaces, commas and escaped double quotes are parsed; option policies are not validated. Options and comments are excluded from hashing. Limit: 100,000 text characters and 64 KiB decoded blob.

Checks cover encoding and structure, not mathematical key validity, signatures, ownership or trust. Compare fingerprints through a separately trusted channel. MD5 is offered only for legacy public-key fingerprints.

A QUICK WALKTHROUGH

How to use this tool

  1. Paste one supported OpenSSH public key line, optionally with authorized_keys options and a comment.
  2. Choose SHA256 or legacy MD5 and generate the fingerprint.
  3. Copy the fingerprint and compare it with a trusted independent source.

One OpenSSH public key line

Accepts an optional comma-separated authorized_keys options prefix and trailing comment. Quoted spaces, commas and escaped double quotes are parsed; option policies are not validated. Options and comments are excluded from hashing. Limit: 100,000 text characters and 64 KiB decoded blob. Public keys only. Input and output stay in current page memory; no upload or saved history. Never paste a private key.

Fingerprint format

SHA256 hashes the decoded key blob with WebCrypto and uses unpadded base64. MD5 hashes the same bytes and uses lowercase colon-separated hex, with its MD5: prefix. SHA256 requires WebCrypto in a secure browser context. MD5 mode remains available.

Key algorithm

Only ssh-rsa, ecdsa-sha2-nistp256 and ssh-ed25519 public key lines. RSA positive mpints, P-256 curve and compressed/uncompressed point field shapes, and a 32-byte Ed25519 field are checked. Certificates, PPK, PEM and private keys are unsupported. Checks cover encoding and structure, not mathematical key validity, signatures, ownership or trust. Compare fingerprints through a separately trusted channel. MD5 is offered only for legacy public-key fingerprints.

GOOD TO KNOW

Common questions

Which key types and formats are accepted?

Only ssh-rsa, ecdsa-sha2-nistp256 and ssh-ed25519 public key lines. RSA positive mpints, P-256 curve and compressed/uncompressed point field shapes, and a 32-byte Ed25519 field are checked. Certificates, PPK, PEM and private keys are unsupported.

What do the two outputs mean?

SHA256 hashes the decoded key blob with WebCrypto and uses unpadded base64. MD5 hashes the same bytes and uses lowercase colon-separated hex, with its MD5: prefix.

Does this verify that a key is safe or trusted?

No. Structural parsing and a matching fingerprint do not establish key mathematics, a signature, identity or trust. This tool does not connect to SSH servers.