Tools · SSH Key

Generate an Ed25519 SSH key.

Create a modern SSH key pair in OpenSSH format, entirely in your browser. The private key is generated locally and never leaves your device.

Generated locally with @noble/curves Ed25519. No network, no logging, no telemetry.

About Ed25519 keys

Modern · Fast · Compact

The recommended algorithm

Ed25519 is an elliptic-curve signature scheme that’s become the default for SSH: a 128-bit security level, fast verification, and resistance to many implementation pitfalls that plagued older schemes.

Same format as ssh-keygen

Output is the standard OpenSSH private-key envelope and a single authorized_keys line — byte-compatible with ssh-keygen -y and every modern SSH client and Git host.

Part of the Apex suite

Apex Agent brings SSH and GPG key handling on-device, so your keys can live behind biometric approval instead of an unprotected file. SSH keys are how developers prove identity without a password.

SSH Key Generator FAQ

Common questions

Are the keys generated safely in the browser?

Keys are generated locally using the Web Crypto random source and the @noble/curves Ed25519 implementation. Nothing is transmitted — you can verify in your browser’s Network tab. For the highest-assurance scenarios (production server keys), generating on your own machine with `ssh-keygen -t ed25519` is still the gold standard.

Why Ed25519 instead of RSA?

Ed25519 is the modern default: faster, with small 68-character public keys, and a strong 128-bit security level. Unless you must support legacy systems that only accept RSA, Ed25519 is the recommended choice.

Is the private key encrypted with a passphrase?

No — this tool emits an unencrypted OpenSSH private key. After downloading it, add a passphrase locally with `ssh-keygen -p -f id_ed25519`. A passphrase encrypts the key at rest so a stolen file alone can’t be used.

How do I use these keys?

Save the private key to ~/.ssh/id_ed25519 (chmod 600) and add the public key line to ~/.ssh/authorized_keys on the server, or paste it into your Git host’s SSH key settings. The fingerprint shown matches what `ssh-keygen -lf` reports.

Ready for the full vault?

Stop reusing. Start sealing.

Apex Password stores every credential end-to-end encrypted, on your device. The relay never sees plaintext.