SSH Key Generator — Ed25519

A ready-to-use Ed25519 key pair in OpenSSH format, generated locally.

Copy the result before closing this tab.

Create an Ed25519 public/private key pair in OpenSSH format. The private key is unencrypted. For a production identity, use ssh-keygen locally and protect the key with a passphrase.

Why Ed25519?

Ed25519 offers compact SSH keys without a key-size setting. Use it when your client, server and cryptographic policy support it. An OpenSSH public key includes an algorithm name, an encoded key and an optional comment, so the full line length varies. See the Ed25519 and RSA comparison for compatibility considerations.

Using the generated key

Save the private key to ~/.ssh/id_ed25519 and the public key to ~/.ssh/id_ed25519.pub, then tighten permissions and load it:

chmod 600 ~/.ssh/id_ed25519 && ssh-add ~/.ssh/id_ed25519

Add the public key line to ~/.ssh/authorized_keys on servers, or paste it into GitHub/GitLab. The optional comment is embedded in both halves so you can recognize the key later.

Is generating SSH keys in a browser safe?

The key pair is created by your own browser's crypto.subtle.generateKey() using the browser’s cryptographic implementation, and the private key is displayed without ever being transmitted or stored; you can verify in the network tab that nothing leaves the page. That said, for high-value production keys the gold standard remains generating them yourself with ssh-keygen -t ed25519, so the private key never touches a rendered web page at all. Use it for test environments where you understand those limits.

FAQ

Is it safe to generate an SSH key in a browser?

The key pair is generated with Web Crypto and is not sent to a server. You still need to trust the delivered code and your device. For a long-lived production identity, prefer ssh-keygen on your own machine. Local generation is not an independent security audit.

Ed25519 or RSA?

Use Ed25519 when the client and server support it and your policy allows it. RSA remains useful for compatibility or specific cryptographic policy requirements. See the comparison guide for details.

Where do I put these two keys?

The private key goes in ~/.ssh/id_ed25519 and must be chmod 600 or OpenSSH will refuse it. The public key goes in ~/.ssh/id_ed25519.pub, and its single line is what you paste into GitHub or append to ~/.ssh/authorized_keys on a server. Never paste the private half anywhere.

How generation works

About & privacy

Generated on your device

Web Crypto provides the randomness. Generation works offline after the page has loaded.

No tracking or saved values

No analytics scripts, accounts, cookies or local storage. Values stay in this tab until you copy them.

Browser and device security

A compromised browser or device can expose values. For production private keys, use a trusted local tool.

Other generators

All generators ↗