Network · Security
SSH key fingerprint calculator.
Paste an OpenSSH public key and get the same SHA256 and MD5 fingerprints that ssh-keygen -l prints, plus the key type and bit length.
The rule: the fingerprint is a hash of the decoded key blob. SHA256 is the base64 of SHA-256(blob) with the trailing = removed, shown as SHA256:.... The legacy MD5 form is the colon-separated hex of MD5(blob).
Inputs
Public keys only
Paste the contents of a .pub file or an authorized_keys line. Never paste a private key into any web page, including this one.
Result
Paste a public key and press Calculate.
How an SSH key fingerprint is made
An OpenSSH public key line has three fields: the key type, the base64 of the key blob, and an optional comment. RFC 4253 section 6.6 defines the blob as a length-prefixed algorithm name followed by algorithm-specific fields.
- Base64-decode the second field to get the blob.
- Read the length-prefixed algorithm name at the start; it must match the key type on the line.
- SHA256 fingerprint: hash the whole blob with SHA-256, base64-encode the 32 bytes, drop the trailing
=, and prefixSHA256:. - MD5 fingerprint (legacy): hash the blob with MD5 and write the 16 bytes as colon-separated hex, prefixed
MD5:. - Bit length: the modulus size for RSA, the curve size for ECDSA (256, 384 or 521), and 256 for Ed25519.
To compare with your own machine, run ssh-keygen -l -f key.pub for SHA256 or ssh-keygen -l -E md5 -f key.pub for MD5. Sources: RFC 4253 section 6.6 for the blob format and the OpenSSH ssh-keygen manual for the fingerprint forms, which agree with the output of the reference implementation.
Format and fingerprint only — not a trust check
This tool parses the key format and computes hashes entirely in your browser. It cannot tell you whether a key is authorised on any server or belongs to any person. Nothing you paste is transmitted, stored, or logged. Do not paste private keys.