Security

SSH Key Fingerprint Calculator

Compute the SHA-256 and MD5 fingerprints of an SSH public key, read its type and size, and verify it matches what a server or a colleague told you before you trust it.

Last reviewed by the Radiatus Cloud team

Fingerprints appear here.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

The fingerprint is what you actually verify

The first time you connect to an SSH host, the client shows a fingerprint and asks whether to trust it. Almost everyone types yes without checking, which means the trust-on-first-use model provides no protection on that first connection. Comparing the presented fingerprint against one obtained through a different channel, a provisioning system, a console, a colleague, is the step that makes the model work, and computing the fingerprint from the key file is how you produce the value to compare against.

SHA-256 replaced MD5 in 2015

OpenSSH 6.8 changed the default fingerprint format from a colon separated MD5 hex string to a base64 SHA-256 value prefixed with SHA256:. Older documentation, wikis and provisioning scripts still carry MD5 fingerprints, which is why both formats remain in circulation and why a comparison sometimes appears to fail when the two values are simply in different formats. MD5 is adequate for a casual comparison and should not be relied on where collision resistance matters.

Key type tells you more than the fingerprint

An ssh-rsa key with a 1024 bit modulus is well below current guidance and is rejected outright by newer OpenSSH defaults. ssh-dss, the DSA type, was disabled by default in 2015 and removed entirely in OpenSSH 10 in 2025. Ed25519 keys are short, fast and the current recommendation. Reading the type and size out of an authorized_keys file is often more useful than the fingerprint, because it identifies keys that need replacing.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

Why do I see two different fingerprint formats?

OpenSSH 6.8 in 2015 changed the default from MD5 to SHA-256. Older records and scripts still carry MD5 values in colon separated hex, while current clients display base64 SHA-256 prefixed with SHA256:. This tool computes both so you can compare against either.

How do I get the same value from the command line?

ssh-keygen -lf key.pub prints the SHA-256 fingerprint, and adding -E md5 prints the MD5 form. For a remote host, ssh-keyscan host | ssh-keygen -lf - shows the host key fingerprints.

What should I do when a host key changes?

Stop and find out why. A legitimate change follows a rebuild, a reinstall or a key rotation, and the new fingerprint should be obtainable from the provisioning system or the console. Deleting the known_hosts entry without verifying is exactly the behaviour an interception attack relies on.

Which key type should I generate?

Ed25519 for new keys: short, fast and with no parameter choices to get wrong. RSA 3072 or 4096 where Ed25519 is not supported by an older server or appliance. DSA has been removed from OpenSSH entirely and ECDSA is acceptable but less favoured.

Is my key safe to paste here?

A public key is not a secret; it is published in authorized_keys and presented on every connection. The computation runs entirely in your browser regardless. Never paste a private key into any web page, including this one.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste an SSH public key to compute its fingerprints and read its type and strength.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.