Neatbo.

Inspect saved SSH host records without connecting

Search a supplied known_hosts copy, understand plain and hashed matches, and preserve markers and original lines in complete local reports.

Start with a copy and an explicit query

Select one saved UTF-8 known_hosts file or paste its contents. A selected file takes precedence over pasted text, so remove it before changing input mode. Enter the bare host and an integer port separately; no path, URL, username or SSH command is needed. The browser does not enumerate your home directory or read another local file.

The host is a literal query. Plain patterns ignore letter case, while salted hashes use the exact query bytes. A nondefault port becomes [host]:port, including brackets around IPv6. Different aliases or compressed IPv6 spellings can therefore require separate searches; the workspace does not resolve addresses or invent aliases.

Read matching rules before reading fingerprints

A comma-separated positive pattern is sufficient only when no matching negated pattern excludes the row. The wildcard record *.example,!blocked.example applies to demo.example but excludes blocked.example. All matching rows remain visible; the first match does not discard later revoked or CA records.

Interpret saved record forms
Record formLocal lookup meaningLimit
demo.example,192.0.2.10Either explicit alias can matchNo DNS equivalence inferred
*.example,!blocked.examplePositive wildcard with an exclusionMatching negation wins
|1|salt|digestExact supplied query passes salted HMAC-SHA1No unknown-name recovery
@revoked / @cert-authorityMarker preserved on an applicable rowNo remote trust verdict

Check a reproducible example

The starter contains three records using one synthetic Ed25519 public key: an alias row, a wildcard row and a revoked row. Searching demo.example on port 22 produces three applicable records and one revoked marker. Searching blocked.example produces none in this starter, because the wildcard exclusion applies.

The parsed public-key SHA256 fingerprint identifies the key bytes. It is the same for all three starter rows, although their host patterns and markers differ. A matching fingerprint alone cannot establish the source of a saved record or the key currently offered by a server.

Expected synthetic public-key fingerprint
SHA256:ZkAslGjFiUHdGf/WUL8rQvkib4PTvQatUV0OUQSncCA

Keep unsupported keys and unmatched keys distinct

Matching ssh-rsa and ssh-ed25519 keys are structurally decoded before fingerprinting. A damaged matching blob or another matching key type rejects the complete result, rather than producing an invented fingerprint. Unmatched key blobs remain in JSON with an explicit unvalidated status; scanning for one host does not certify every record in the file.

Physical lines include blank lines and comments, so line numbers still refer to the supplied copy. rawLine retains the original record spelling and spacing. Marker meanings, positive matches and negated matches are preserved separately from the summarized table.

Save a complete report and recover from errors

The table previews up to200 matching rows on 100-row pages. The downloaded JSON contains every record and match; CSV contains every matching original line and fingerprint. The on-page JSON is a bounded preview, so use downloads for a large handoff and compare the total count with the receiving application.

Inputs are bounded to1MiB,10,000 physical lines,8,192 bytes per line and32 patterns per row. Pattern comparisons and combined output bytes are also bounded. A limit or invalid matching key fails atomically. Correct the indicated input, rerun, and inspect the new report before acting on information from an older copy.

  • Keep the source known_hosts copy with the report.
  • Check the exact hostname spelling and nondefault port.
  • Read every revoked or CA marker; do not turn presence into a trust approval.
  • Compare the parsed fingerprint with separately trusted key evidence.
  • Treat zero matches as a lookup result, with no permission or security conclusion.

References

Tools in this category

Expand a tool to see its steps, options and supported formats, then open its workspace.

Find matching SSH known-host recordsSearch a local known_hosts file for a supplied host and port, with match explanations and supported public-key fingerprints.

Paste or select your saved OpenSSH known_hosts records, then supply the exact host and port you want to inspect. Find every applicable plain, wildcard or salted-hash record, including revoked and certificate-authority markers. The report explains why a row matches; it does not connect to that host or make a trust decision.

Steps

  1. Paste the records or select one local known_hosts file, then enter the host and port.
  2. Search and review every match, its physical line, marker and explanation. A matching revoked record remains visible.
  3. Download the full JSON/CSV, compare the supported public-key fingerprint with separately trusted evidence, and keep the original file.

Available options

Host to inspect (without port)
demo.example

Use the exact supplied spelling. Nondefault ports are searched as [host]:port.

SSH port
22
Protect formula-like CSV cells
On by default

Capabilities and limits

  • One UTF-8 file or pasted text, up to 1 MiB, 10,000 physical lines and 8,192 UTF-8 bytes per line. Blank and whole-line # comments are ignored. A selected file takes precedence; clear it to use pasted text. UTF-8 BOM and CRLF are accepted, other control characters are rejected.
  • Supply a bare ASCII hostname, IPv4 spelling or IPv6 address, with a separate integer port 1–65535. Port 22 uses the supplied host; other ports use [host]:port. Plain comma-separated patterns support * and ? and matching ! negation, case-insensitively, with at most 32 patterns per line and 5,000,000 pattern comparisons.
  • OpenSSH |1| salted HMAC-SHA1 host hashes require canonical padded Base64 and 20-byte salt/digest. They are compared against the exact supplied query case. Unknown hashes are not reversed, alternative hash versions and markers are unsupported.
  • Only matching ssh-ed25519 and ssh-rsa public-key blobs are structurally parsed and given SHA256 fingerprints. Any matching unsupported or malformed key rejects the result. Unmatched key bytes remain explicitly unvalidated; no private-key, signature, certificate-chain or remote-host validation occurs.
  • All original record lines and match explanations are retained in the complete JSON. CSV contains every matching line and fingerprint, with formula-like cells protected by default. The table previews 200 matching rows on 100-row pages; on-page text is a bounded report preview. Combined downloads are capped at 10 MiB atomically.
Open Find matching SSH known-host records →