Security · Developer tools

PGP key fingerprint calculator.

Paste an armored PGP public key and get the same fingerprint and key ID that gpg --fingerprint prints, plus the algorithm, creation time and user IDs.

The rule: a v4 fingerprint is SHA-1 over 0x99, the 2-byte length, then the primary key packet body; the key ID is its last 64 bits. A v6 fingerprint is SHA2-256 over 0x9B, the 4-byte length, then the packet body; its key ID is the first 64 bits.

Source: RFC 4880 section 12.2, RFC 9580 section 5.5.4Verified 30 September 2026

Advertisement

Inputs

Public keys only

Paste the output of gpg --armor --export. Never paste a private key block into any web page, including this one.

The whole block, from the BEGIN line to the END line.

Result

Paste a public key block and press Calculate.

How a PGP key fingerprint is made

An ASCII-armored block is base64 of a stream of OpenPGP packets, optionally followed by a CRC-24 line that starts with =. The first Public-Key packet (tag 6) is the primary key, and the fingerprint is a hash of that packet alone. Subkeys and signatures do not change it.

  1. Strip the armor headers, base64-decode the body, and check the optional CRC-24 (initial value 0xB704CE, generator 0x864CFB).
  2. Walk the packet headers (old or new format) to find the first Public-Key packet, and read the User ID packets that follow it.
  3. Version 4 key: hash the byte 0x99, the 2-byte big-endian packet length and the packet body with SHA-1. The 160-bit result is the fingerprint and its low 64 bits are the key ID.
  4. Version 6 key: hash the byte 0x9B, the 4-byte big-endian packet length and the packet body with SHA2-256. The 256-bit result is the fingerprint and its high 64 bits are the key ID.
  5. The packet body also holds the version, the creation time (seconds since 1970-01-01 UTC) and the public-key algorithm id, which this tool shows by name.

To compare with your own machine, run gpg --fingerprint --keyid-format long [email protected]; it groups a v4 fingerprint as ten blocks of four hex digits. Version 3 keys (MD5 fingerprint) are deprecated and not supported. The v4 method is checked against GnuPG output for Ed25519 and RSA keys, and the v6 method against the sample certificate in RFC 9580 Appendix A.3. Sources: RFC 4880 section 12.2 and RFC 9580 section 5.5.4; armor checksum in RFC 9580 section 6.1.

Format and fingerprint only — not a trust check

This tool parses the key packet and computes hashes entirely in your browser. It cannot tell you whether a key belongs to the person it names, is signed by anyone, or has been revoked or expired. Compare the fingerprint with one you got from the owner over a separate channel. Nothing you paste is transmitted, stored, or logged. Do not paste private keys.

Advertisement
Advertisement
Listening…