Home / Security & Encoding / SSH Key Generator

SSH Key Generator

Runs in your browser Files stay on your device · 100% private

Generate SSH key pairs in-browser.

About SSH Key Generator

An SSH key pair is a matched set: a public half you place on servers and a private half you keep to yourself. This generator creates that pair using the Web Crypto API built into your browser, so the private key is produced on your own machine and never travels over a network. It supports RSA at 2048 and 4096 bits for older systems, and ECDSA on the NIST P-256 and P-384 curves for shorter keys with the same strength. The public key comes out in the format a server expects in ~/.ssh/authorized_keys, and the private key comes out as a PEM file that OpenSSH reads. An optional passphrase encrypts the private key so a stolen file alone cannot log into anything.

How to Use SSH Key Generator

1

Choose a key type

Pick RSA 2048, RSA 4096, or one of the ECDSA curves. RSA 2048 is the safe default that works everywhere. ECDSA P-256 gives the same practical security with a much shorter key if your server is reasonably modern.

2

Add a comment and passphrase

The comment lands at the end of the public key and is usually an email or device name, which helps you tell keys apart later. A passphrase encrypts the private key file itself, so it needs a password whenever it is used.

3

Generate the pair

Click Generate key pair. Both boxes fill in immediately: the public key on top, the private key below. Nothing is transmitted during this step.

4

Install both halves

Download both files. Append the public key contents to ~/.ssh/authorized_keys on your server and set chmod 600 on that file. Save the private key as ~/.ssh/id_rsa or ~/.ssh/id_ecdsa on your computer with chmod 600 as well.

Why Use SSH Key Generator: Common Use Cases

Setting up a new VPS

Generate a pair before first login, then paste the public key into the cloud provider console or the authorized_keys file so password logins can be turned off entirely.

Giving a teammate server access

Ask them to generate a pair and send you only the public key. You append it to authorized_keys and they can log in without you ever seeing or storing a password.

Rotating keys after a laptop loss

Remove the lost key from authorized_keys, generate a fresh encrypted pair, and install it. Because the old private key was passphrase protected, the window of risk stays small. The new passphrase itself is worth checking with Password Strength.

Automating deployments from CI

Continuous integration runners push code over SSH with their own key pair. Generate a dedicated pair for the runner and grant it access only to the deploy target.

SSH Key Generator Specifications

Input Formats Key type selection, Comment, Optional passphrase
Output Formats OpenSSH public key (authorized_keys line), PKCS#8 PEM private key
File Size Limit No strict limit (dependent on device memory)
Processing Engine 100% Client-side (Runs locally in your browser)
Data Retention Files never leave your device
Batch Processing Single file processing

Tips for SSH Key Generator

  • One key per device is easier to manage than one shared key. If a laptop dies, you remove its single line from authorized_keys and nothing else breaks.

  • Use a passphrase on any key that leaves your machine. An unencrypted private key file is as dangerous as a written password.

  • RSA 4096 takes a few seconds to generate and produces larger signatures. Unless a compliance rule requires it, RSA 2048 or ECDSA P-256 is the practical choice.

  • Test a new key before closing your current session. Open a second terminal and confirm the login works, so you do not lock yourself out.

  • Hardening a server further? Add TOTP two-factor codes on top of keys, so a stolen key alone still cannot log in.

  • Store the public key of every key you own somewhere safe. The public half cannot regenerate the private half, but having it on hand makes audits quick.

Frequently Asked Questions

Are the generated keys safe to use in production?

Yes. The keys come from the Web Crypto API, which uses the same underlying cryptographic primitives as command line tools. The key format is standard, so ssh, scp, git, and every major cloud provider accept them without conversion.

Why not Ed25519?

Ed25519 is a popular modern choice, but browser support for generating it through Web Crypto is still inconsistent across engines. RSA and ECDSA generate reliably everywhere, and both remain fully supported by OpenSSH.

Where does the private key go?

On your own computer, in the .ssh folder of your home directory, with permissions set to 600. The server only ever needs the public half. Never email or paste a private key into a chat.

What does the passphrase actually protect?

It encrypts the private key file using PBKDF2 with a hundred thousand hashing rounds plus AES encryption. Someone who copies the file still cannot use it without guessing the passphrase, which buys you time to rotate keys.

Can I use one key pair for GitHub, GitLab, and my servers?

Technically yes, and the same public key can be registered in several places. Separating them per service or per device keeps the blast radius small when one needs revoking.

How long should a key stay in use?

There is no expiry baked into SSH keys, so rotation is a policy decision. Many teams rotate every year, or immediately after a staff change or a device is retired. Generating a fresh pair here takes seconds.