SSH Key Fingerprint Checker
Paste an OpenSSH public key (ssh-rsa, ssh-ed25519, ecdsa-sha2-*) and get its SHA-256 and MD5 fingerprints plus key type and bits — entirely in your browser.
This reproduces what ssh-keygen -lf prints. Compare the SHA-256 value against the one shown when you connect to a host to verify you're talking to the right server.
Fingerprint a sample public key
Load a generated ssh-rsa public key and compute its SHA-256 and MD5 fingerprints, type and bit length.
This reproduces what ssh-keygen -lf prints. You can generate your own key here with the Keypair Generator and fingerprint the result.
FAQ
What is a fingerprint?
A short digest of a public key. Fingerprints let you verify a key you’re using belongs to the right server or person, without comparing hundreds of base64 characters.
How do I verify a host?
When you first connect, your SSH client prints a fingerprint. Compare it against what this tool shows for the host’s published key (or what the admin publishes) — if they differ, you may be talking to the wrong server.
SHA-256 or MD5 — which do I use?
Use the SHA-256 fingerprint. It’s the modern standard and more collision-resistant. MD5 is shown for compatibility with legacy systems that still display it.
Why does a mismatch matter?
If the fingerprint doesn’t match the one you expect, the key — or the server — isn’t what you thought, which is a classic symptom of a man-in-the-middle attack. Stop and investigate.