Neatbo.

SSH public-key fingerprint

Calculate a SHA256 fingerprint from an OpenSSH RSA or Ed25519 public-key blob and validate its wire structure.

Browser-local processingInputFile / TextOutputFile / TextUp to 1 MiB per file · File limit: 1
  1. 1Add input
  2. 2Adjust settings
  3. 3Get your result

Tool input and files are processed in this browser without being uploaded.

Your input

Inputs are kept temporarily in this tab when switching tools. Refreshing or closing clears them; large results may need to be regenerated.

⌘ / Ctrl + Enter to run
SSH public-key source
0 characters · 0 bytes
Options

Complete the required options first. You can keep the defaults for the rest.

Paste the complete SHA256: value from a trusted service. Blank skips the comparison.

Preparing the tool…

Before you start

Calculate the full SHA256 fingerprint of one OpenSSH RSA or Ed25519 public key. Paste a .pub key, then optionally compare it with a trusted SHA256 fingerprint displayed elsewhere.

How to use this tool

  1. Paste one OpenSSH public key beginning with ssh-ed25519 or ssh-rsa, or choose a .pub file.
  2. Optionally enter the complete SHA256: fingerprint shown by a trusted service.
  3. Inspect the full calculated fingerprint and exact match result; a matching comment alone proves nothing.

Supported inputs and limits

One OpenSSH RSA or Ed25519 public key per run. Private keys, SSH certificates, other algorithms and multiline key lists are rejected. Comments are excluded from the fingerprint.

The optional expected value must be a complete, unpadded SHA256: fingerprint from a trusted source. This page cannot verify GitHub account ownership or SSH access.

Public-key input stays in the browser. A pasted key or one UTF-8 .pub/.txt file is limited to 1 MiB. Outputs do not overwrite original files.

Worked example

Example input

ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAABAgMEBQYHCAkKCwwNDg8QERITFBUWFxgZGhscHR4f demo
Example options
{"expected": ""}

Example output

{
  "type": "ssh-ed25519",
  "fingerprint": "SHA256:ZkAslGjFiUHdGf/WUL8rQvkib4PTvQatUV0OUQSncCA",
  "expectedChecked": false,
  "expectedMatched": null
}

When something does not work

Use one complete OpenSSH .pub line. Verify the key type, base64 data, and full expected SHA256: value; do not paste a private key or a key list.

Frequently asked questions

Which SSH public-key types are supported?

One OpenSSH ssh-ed25519 or ssh-rsa public key. The key blob is parsed before its SHA256 fingerprint is calculated; private keys and certificates are not accepted.

What should the example produce?

The sample fingerprint is SHA256:ZkAslGjFiUHdGf/WUL8rQvkib4PTvQatUV0OUQSncCA. Changing only its comment does not change the fingerprint.

Which cases are outside its scope?

This page cannot retrieve a key from GitHub, verify who owns it, or test an SSH connection. Compare with the complete SHA256 value from a trusted channel.

Documentation & further reading

Related tools