SSH Key Generator

Get the exact commands to create a key on your own computer, put it on your server and switch password logins off. The key is made on your machine: no private key ever passes through a website, including this one.

  • Free
  • No Sign-Up
  • Runs in Your Browser
Key Type
Your Computer

Recommended for almost everything: short, fast and secure. Supported by OpenSSH 6.5 (2014) and later. Set a passphrase when asked.

1. Create the Key (on Your Computer)

ssh-keygen -t ed25519 -a 100 -C "you@laptop" -f ~/.ssh/id_ed25519

2. Copy It to the Server

ssh-copy-id -i ~/.ssh/id_ed25519.pub root@your-server

3. Optional: ~/.ssh/config

Host your-server
    User root
    IdentityFile ~/.ssh/id_ed25519
    IdentitiesOnly yes

4. Switch Off Password Logins

# On the server, after a key login works in a second window:
sudo tee /etc/ssh/sshd_config.d/10-keys-only.conf >/dev/null <<'EOF'
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin prohibit-password
EOF
sudo sshd -t && sudo systemctl reload ssh || sudo systemctl reload sshd

How to Use

How to use the SSH Key Generator

  1. 01

    Choose a key type

    Ed25519 for almost everything; RSA 4096 for very old systems.

  2. 02

    Fill in the details

    Your server's address and user, and a name for the key.

  3. 03

    Run the commands

    On your own computer, then on the server to lock it down.

VPS & Linux

About the SSH Key Generator

Why this page does not make the key for you

A private key is a password that never expires. Any website that generates one and shows it to you has, at least for a moment, had a copy. ssh-keygen is already installed on Linux, macOS and Windows 10 and later, and makes the key where it will be used.

Which key type

Ed25519 keys are short, fast and secure, and every SSH server from the last ten years accepts them. Use RSA with 4096 bits only for older systems that do not. ECDSA works but has no advantage over Ed25519. For the strongest protection, use a hardware key (ed25519-sk) such as a YubiKey: the private key cannot be copied off it at all.

Always set a passphrase. With an SSH agent you type it once per session, and a stolen key file is useless without it.

What it can't tell you

  • Nothing is generated or stored here: the page only writes commands for you to run.

Frequently asked questions

Is Ed25519 better than RSA?
For SSH, yes: Ed25519 keys are smaller and faster with equal or better security than RSA 4096. Use RSA only where Ed25519 is not supported.
Where are SSH keys stored?
In ~/.ssh/ on your computer: the private key (id_ed25519) and the public key (id_ed25519.pub). Only the .pub file is ever copied to servers.
How do I disable password login over SSH?
Set PasswordAuthentication no in /etc/ssh/sshd_config (or a file in /etc/ssh/sshd_config.d/), then reload ssh. Test a key login in a second window first.

Run VMs for other people?

Frabs stops spam, scans and floods leaving your customers' VMs, before the abuse report lands.