Online key-checking tools from Pwnedkeys

  • Home
  • About
  • FAQ
  • API
  • Tools
  • The Revokinator
Login

Pwnedkeys provides a number of online tools to check whether a key is known to have been disclosed. This is in addition to the Pwnedkeys API, which is freely available for automated querying.

None of these tools require you to upload any private key material. If you do upload a private key, that key will be added to the Pwnedkeys dataset.

For everyone

X.509 Certificate or CSR

Upload an X.509 certificate or Certificate Signing Request, and we'll tell you if it's using a key known to have been compromised.

For everyone

SSH authorized_keys

Upload an OpenSSH authorized_keys file, and we'll tell you if any of the public keys in it are known to Pwnedkeys to have been compromised.

For subscribers

Code Hosting Service Users

Verify that the developer of your favourite program isn't using a compromised key to upload code to any of the most popular code hosting services.