SSH

SSH Key Fingerprint Checker

Paste an OpenSSH public key (ssh-rsa, ssh-ed25519, ecdsa-sha2-*) and get its SHA-256 and MD5 fingerprints plus key type and bits — entirely in your browser.

This reproduces what ssh-keygen -lf prints. Compare the SHA-256 value against the one shown when you connect to a host to verify you're talking to the right server.

Fingerprint a sample public key

Load a generated ssh-rsa public key and compute its SHA-256 and MD5 fingerprints, type and bit length.

This reproduces what ssh-keygen -lf prints. You can generate your own key here with the Keypair Generator and fingerprint the result.

FAQ

What is a fingerprint?

A short digest of a public key. Fingerprints let you verify a key you’re using belongs to the right server or person, without comparing hundreds of base64 characters.

How do I verify a host?

When you first connect, your SSH client prints a fingerprint. Compare it against what this tool shows for the host’s published key (or what the admin publishes) — if they differ, you may be talking to the wrong server.

SHA-256 or MD5 — which do I use?

Use the SHA-256 fingerprint. It’s the modern standard and more collision-resistant. MD5 is shown for compatibility with legacy systems that still display it.

Why does a mismatch matter?

If the fingerprint doesn’t match the one you expect, the key — or the server — isn’t what you thought, which is a classic symptom of a man-in-the-middle attack. Stop and investigate.

Updated 2026-08-10 · Runs in your browser — your data never leaves this page unless the tool explicitly says it makes a network check.