SSH key generator
Create an SSH key pair for GitHub, GitLab or your servers - free, private, right in your browser.
Made by Termphin - an SSH client that keeps your session alive when you lock your phone or switch networks. Get Termphin →
Check a public key's fingerprint
What is an SSH key?
An SSH key lets you log in to GitHub, GitLab or a server without typing a password every time. It comes as two files that belong together. The public key is like a lock: you hand it to every service you want to reach. The private key is the only key that opens that lock, so it stays on your computer and you never share it.
Why this one
- in your browser - keys never leave the tab, and the page is not allowed to send anything over the network.
- works everywhere - the same standard OpenSSH files that macOS, Linux and Windows create, checked against them in tests.
- open source - MIT licensed, source on GitHub.
Guides
- Generate an SSH key on macOS - ssh-keygen in Terminal, the Keychain and ~/.ssh/config.
- Generate an SSH key on Linux - ssh-keygen, ssh-agent and permissions on any distribution.
- Generate an SSH key on Windows - The built-in OpenSSH client, PowerShell and the agent service.
- SSH key for GitHub, GitLab and Bitbucket - Add a key to your account and test the connection.
- Add an SSH key to a server - authorized_keys, ssh-copy-id, permissions and troubleshooting.
- Ed25519 vs RSA vs ECDSA - Which key type to pick in 2026, and when RSA still matters.
- SSH key passphrases - Why to set one, ssh-agent, and changing it with ssh-keygen -p.
- SSH key fingerprints - What a fingerprint is and how to check one.
- ssh-keygen command reference - Every common flag, with examples.
- SSH connection keeps dropping - Broken pipe and timeouts: keepalives, tmux, mosh and sessions that survive.
- Use an SSH key on your phone - Generate or move a key safely, import it, and revoke a lost phone.
- Run Claude Code or Codex over SSH - A coding agent on a server you check from your phone.
FAQ
Is it safe to generate an SSH key in a browser?
Yes, when the page never sends the key anywhere. Keys come from the Web Crypto API on your device, and a Content Security Policy forbids this page from opening any network connection. For keys that guard critical systems, run ssh-keygen locally.
Are the keys stored or sent anywhere?
No. They live only in this tab's memory until you close it or press Start over. There are no cookies, no analytics and no backend.
Which key type should I choose?
Ed25519. Use RSA 4096 only for old systems that reject Ed25519, and ECDSA when a policy demands NIST curves. See Ed25519 vs RSA.
Are the keys compatible with OpenSSH?
Yes. The private key uses the OpenSSH format and, with a passphrase, aes256-ctr and bcrypt_pbkdf at 16 rounds, exactly like ssh-keygen. The public key is a standard authorized_keys line.
Should I set a passphrase?
Yes, for any key on a laptop or phone. A stolen file is useless without it, and ssh-agent means you type it once per session. See passphrases.
Does it work offline?
Yes. Once the page has loaded, generation needs no network at all.