Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To view a public SSH key, print its .pub file with cat ~/.ssh/id_ed25519.pub. If that file is missing but you have the matching private key, derive the public key with ssh-keygen -y -f ~/.ssh/id_ed25519. Do not display or share the private key itself. If you mean keys installed on the server, inspect the relevant account’s authorized_keys file instead.

First, identify which SSH key information you need

“SSH key content” can mean several different things. Your client identity key is usually a key pair: a private key that must remain confidential and a public key that can be copied to a server. A fingerprint is a short identifier for a key, not the full public-key text. A VPS or VDS also has a server-side list of public keys authorized to log in to a particular account.

  • Need the public-key text? Display the matching .pub file, or derive the public key from its private-key file.
  • Need to identify or compare a key? Display its fingerprint.
  • Need to see which keys a server account accepts? Inspect that account’s authorized_keys file.
  • Need the private-key text? Avoid displaying or sharing it. It is sensitive authentication material.

Find the key for the right user and machine

Run the commands as the operating-system user whose SSH identity you want to inspect. The ~/.ssh path refers to that user’s home directory; it may not be the same account you use in a VPS control panel or in another shell session.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

List the directory contents:

ls -la ~/.ssh

Common OpenSSH identity names include id_ed25519 and id_rsa. A public-key file commonly has the same name with .pub appended, such as id_ed25519.pub. Names are conventions, not proof: keys can use custom filenames or locations. OpenSSH describes identity-file naming and handling in its ssh(1) manual and ssh_config(5) manual.

If you generated the key on your laptop and installed its public key on the VPS, look in the laptop user’s ~/.ssh directory for the client identity. The VPS normally contains the installed public key, not the corresponding client private key.

Print a saved public key

Use cat on the public-key file, substituting its actual path if it has a different name:

cat ~/.ssh/id_ed25519.pub

This prints the public key as a line of text. Copy that line only when you intend to install or compare the public key. OpenSSH states that public-key contents need not be kept secret in its ssh-keygen(1) manual.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Derive the public key if the .pub file is missing

If you have the matching private key but no public-key file, OpenSSH can derive and print the public key:

Rank #3
HP MicroServer Gen10 Plus Mini Tower Server, Intel Xeon E-2224 3.4GHz, 32GB RAM, 16TB Storage, RAID, Windows Server 2019
  • HP MicroServer Gen10 Plus Tower Server for Business with Microsoft Windows Server 2019 OS!
  • Intel Xeon E-2224 Quad-Core 3.4GHz 8MB CPU, Up To 4.6GHz Turbo
  • 32GB (2 x 16GB) DDR4 PC4-21300 2666MHz Unbuffered Memory
  • 16TB (4 x 4TB) 7.2K 6Gb/s SATA 3.5" HDDs in RAID
  • Hard drives and memory upgrades included separately NOT installed, installation required.
ssh-keygen -y -f ~/.ssh/id_ed25519

Replace the example path with the private-key path that matches your key. The -y option reads a private OpenSSH-format key and writes its public key to standard output. If the private key is encrypted, ssh-keygen may prompt for its passphrase. This operation prints the public key; it does not make the private key safe to disclose.

Show a fingerprint instead of the full key

For an identity check, use the fingerprint command on the public-key file:

ssh-keygen -l -f ~/.ssh/id_ed25519.pub

The -l option displays a fingerprint. It is an identifier for comparing keys, not the full public-key line. If you only need to verify identity, there is no reason to display or circulate the private key.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect public keys authorized on the VPS or VDS

To see public keys installed for a remote account, connect as the relevant account and inspect its default authorized-keys file:

cat ~/.ssh/authorized_keys

This file contains public-key entries accepted for that account; it is separate from the client-side identity key and does not contain the corresponding private key. OpenSSH documents ~/.ssh/authorized_keys and ~/.ssh/authorized_keys2 as defaults when AuthorizedKeysFile is not explicitly configured. An administrator may configure another location, so the server’s sshd configuration can override the default. See the sshd(8) manual.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep private-key files protected

Do not paste, publish, or email private-key contents. OpenSSH warns that identity files contain sensitive data and should be readable by their owner but not accessible by others. Its SSH client ignores a private-key file if others can access it. Use the applicable file permissions and account ownership to restrict access, as described in the ssh(1) manual.

Troubleshoot common problems

  • The file is not found: Confirm you are logged in as the user who owns the key, check the directory with ls -la ~/.ssh, and account for a custom key filename or location.
  • There is no .pub file: If the matching private key is available and readable, use ssh-keygen -y -f with its path to derive the public key.
  • ssh-keygen -y reports an error: Check that the path points to a readable private key in a supported format. If the key is encrypted, provide its passphrase when prompted.
  • You are looking on the VPS but cannot find the client private key: The client identity may be on the workstation used to connect. The server-side authorized_keys file stores public-key entries, not the client’s private key.
  • You cannot find the server’s authorized keys in the default location: The server administrator may have set a different AuthorizedKeysFile path in the SSH daemon configuration.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.