A worked example, rendered from real sample data. Sign in to run the tool on your own input.
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILkvbh4xUoa/9NyGEesBRyUTOaAyYMo8/QbXR0m3Hs5J deploy@build-server═══ Key ═══
Detected format: OpenSSH authorized_keys
Type: ED25519 (ssh-ed25519)
Size: 256 bits
Comment: deploy@build-server
Blob: 51 bytes
═══ Fingerprints ═══
SHA256: SHA256:4+xezGYJ4WOiaUHezau9HEt1Y5+SqJWFeUi3pIr3ka8
MD5: MD5:41:98:a7:a5:ea:25:09:e9:8a:fc:1e:0b:bb:10:d1:f7
ℹ SHA256 is what OpenSSH 6.8 and later print. MD5 still shows up in AWS, GitHub and Jenkins consoles.
═══ OpenSSH (authorized_keys, .pub) ═══
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILkvbh4xUoa/9NyGEesBRyUTOaAyYMo8/QbXR0m3Hs5J deploy@build-server
ℹ What sshd reads and what every hosting provider asks for.
═══ RFC 4716 (SSH2, Tectia, older PuTTY) ═══
---- BEGIN SSH2 PUBLIC KEY ----
Comment: "deploy@build-server"
AAAAC3NzaC1lZDI1NTE5AAAAILkvbh4xUoa/9NyGEesBRyUTOaAyYMo8/QbXR0m3Hs5J
---- END SSH2 PUBLIC KEY ----
ℹ ssh-keygen -e -f key.pub produces this.
═══ PEM SubjectPublicKeyInfo (PKCS#8) ═══
-----BEGIN PUBLIC KEY-----
MCowBQYDK2VwAyEAuS9uHjFShr/03IYR6wFHJRM5oDJgyjz9BtdHSbcezkk=
-----END PUBLIC KEY-----
ℹ What openssl, Java and most TLS libraries expect.
═══ JWK ═══
{
"crv": "Ed25519",
"x": "uS9uHjFShr_03IYR6wFHJRM5oDJgyjz9BtdHSbcezkk",
"kty": "OKP"
}
ℹ For JOSE libraries and JWKS documents.
═══ Findings ═══
✓ Modern key type, adequate size, and a usable comment.
═══ Do the same locally ═══
ssh-keygen -l -f key.pub # fingerprint
ssh-keygen -e -m RFC4716 -f key.pub # to RFC 4716
ssh-keygen -e -m PKCS8 -f key.pub # to PEM
ssh-keygen -i -m PKCS8 -f key.pem # back to OpenSSH
Convert an SSH public key between OpenSSH, RFC 4716, PEM and JWK, with both fingerprints. Part of the DevTools Surf developer suite. Browse more tools in the Security / Crypto collection.