Neatbo.

Find matching SSH known-host records

Search a local known_hosts file for a supplied host and port, with match explanations and supported public-key fingerprints.

Browser-local processingInputOpenSSH known_hosts + host/portOutputMatch JSON / CSVUp to 1 MiB per file · File limit: 1
  1. 1Add input
  2. 2Adjust settings
  3. 3Get your result

Tool input and files are processed in this browser without being uploaded.

Your input

Inputs are kept temporarily in this tab when switching tools. Refreshing or closing clears them; large results may need to be regenerated.

⌘ / Ctrl + Enter to run

or drag and drop it here

Files stay on this device. Your originals stay unchanged.

.txt · .known_hosts

Up to 1 MiB per file · File limit: 1

    0 characters · 0 bytes
    Options

    Complete the required options first. You can keep the defaults for the rest.

    Use the exact supplied spelling. Nondefault ports are searched as [host]:port.

    Preparing the tool…

    Before you start

    Paste or select your saved OpenSSH known_hosts records, then supply the exact host and port you want to inspect. Find every applicable plain, wildcard or salted-hash record, including revoked and certificate-authority markers. The report explains why a row matches; it does not connect to that host or make a trust decision.

    How to use this tool

    1. Paste the records or select one local known_hosts file, then enter the host and port.
    2. Search and review every match, its physical line, marker and explanation. A matching revoked record remains visible.
    3. Download the full JSON/CSV, compare the supported public-key fingerprint with separately trusted evidence, and keep the original file.

    Supported inputs and limits

    One UTF-8 file or pasted text, up to 1 MiB, 10,000 physical lines and 8,192 UTF-8 bytes per line. Blank and whole-line # comments are ignored. A selected file takes precedence; clear it to use pasted text. UTF-8 BOM and CRLF are accepted, other control characters are rejected.

    Supply a bare ASCII hostname, IPv4 spelling or IPv6 address, with a separate integer port 1–65535. Port 22 uses the supplied host; other ports use [host]:port. Plain comma-separated patterns support * and ? and matching ! negation, case-insensitively, with at most 32 patterns per line and 5,000,000 pattern comparisons.

    OpenSSH |1| salted HMAC-SHA1 host hashes require canonical padded Base64 and 20-byte salt/digest. They are compared against the exact supplied query case. Unknown hashes are not reversed, alternative hash versions and markers are unsupported.

    Only matching ssh-ed25519 and ssh-rsa public-key blobs are structurally parsed and given SHA256 fingerprints. Any matching unsupported or malformed key rejects the result. Unmatched key bytes remain explicitly unvalidated; no private-key, signature, certificate-chain or remote-host validation occurs.

    All original record lines and match explanations are retained in the complete JSON. CSV contains every matching line and fingerprint, with formula-like cells protected by default. The table previews 200 matching rows on 100-row pages; on-page text is a bounded report preview. Combined downloads are capped at 10 MiB atomically.

    Worked example

    Example input

    demo.example,192.0.2.10 ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAABAgMEBQYHCAkKCwwNDg8QERITFBUWFxgZGhscHR4f plain
    *.example,!blocked.example ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAABAgMEBQYHCAkKCwwNDg8QERITFBUWFxgZGhscHR4f wildcard
    @revoked demo.example ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAABAgMEBQYHCAkKCwwNDg8QERITFBUWFxgZGhscHR4f revoked
    
    Example options
    {"hostname":"demo.example","port":22}

    Example output

    3 saved records, 3 applicable rows, 1 revoked marker; parsed public key SHA256:ZkAslGjFiUHdGf/WUL8rQvkib4PTvQatUV0OUQSncCA. No network or trust decision.

    When something does not work

    Correct the first invalid physical line, unsupported marker or matching key, then run again. For no matches, check the supplied spelling and nondefault port; do not interpret an empty result as permission to trust the host.

    Frequently asked questions

    Can this reveal an unknown hashed hostname?

    No. It tests only the name and port you supply against the stored salt and HMAC. No dictionary search, DNS lookup or SSH connection runs.

    Does a matching CA or fingerprint mean the host is trusted?

    No. @cert-authority and @revoked are reported as saved record markers. The fingerprint identifies parsed public-key bytes; its provenance, certificate signatures and current host key remain unverified.

    Why can changing letter case affect a hash match?

    Plain OpenSSH host patterns match without letter case. A stored salted hash is checked against the exact supplied query bytes, so enter the spelling you intend to search; the tool does not invent canonical variants.

    Documentation & further reading

    Related tools