The recommended algorithm
Ed25519 is an elliptic-curve signature scheme that’s become the default for SSH: a 128-bit security level, fast verification, and resistance to many implementation pitfalls that plagued older schemes.
Tools · SSH Key
Create a modern SSH key pair in OpenSSH format, entirely in your browser. The private key is generated locally and never leaves your device.
Generated locally with @noble/curves Ed25519. No network, no logging, no telemetry.
Ed25519 is an elliptic-curve signature scheme that’s become the default for SSH: a 128-bit security level, fast verification, and resistance to many implementation pitfalls that plagued older schemes.
Output is the standard OpenSSH private-key envelope and a single
authorized_keys line — byte-compatible with
ssh-keygen -y and every modern SSH client and Git host.
Apex Agent brings SSH and GPG key handling on-device, so your keys can live behind biometric approval instead of an unprotected file. SSH keys are how developers prove identity without a password.
Keys are generated locally using the Web Crypto random source and the @noble/curves Ed25519 implementation. Nothing is transmitted — you can verify in your browser’s Network tab. For the highest-assurance scenarios (production server keys), generating on your own machine with `ssh-keygen -t ed25519` is still the gold standard.
Ed25519 is the modern default: faster, with small 68-character public keys, and a strong 128-bit security level. Unless you must support legacy systems that only accept RSA, Ed25519 is the recommended choice.
No — this tool emits an unencrypted OpenSSH private key. After downloading it, add a passphrase locally with `ssh-keygen -p -f id_ed25519`. A passphrase encrypts the key at rest so a stolen file alone can’t be used.
Save the private key to ~/.ssh/id_ed25519 (chmod 600) and add the public key line to ~/.ssh/authorized_keys on the server, or paste it into your Git host’s SSH key settings. The fingerprint shown matches what `ssh-keygen -lf` reports.
Ready for the full vault?
Apex Password stores every credential end-to-end encrypted, on your device. The relay never sees plaintext.