Known-Hosts Change Comparer

Compare supplied known_hosts snapshots and report added, removed or changed public key pins without contacting hosts.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Compare host pins controls

Up to 500 records / 500,000 characters. RSA, Ed25519 and P-256 records; revoked/CA markers and opaque version 1 hashed names.

Exact host tokens and key types are compared. Names are never resolved and an added key is not evidence of an attack.

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use Known-Hosts Change Comparer

  1. Supply the earlier known_hosts text and later known_hosts text using the supported input described beside the controls.
  2. Review the selected options and the declared scope, then run the known hosts change comparer.
  3. Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.

Example: Known-Hosts Change Comparer

Compare supplied host-key pin snapshots and highlight changed/added/removed keys. This example uses synthetic public data.

You add
Earlier known_hosts text: demo.example ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwdHh8g Later known_hosts text: demo.example ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwdHh8g new.example ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwdHh8g
You get
Added 1, removed 0, changed 0, unchanged 1 host/type records. Unchanged | demo.example | ordinary | ssh-ed25519 | SHA256:mKqU+0K8OhKmA8bBQi9Rz0Q5l7/g160hIP+rJYSTNj4 | SHA256:mKqU+0K8OhKmA8bBQi9Rz0Q5l7/g160hIP+rJYSTNj4 Added | new.example | ordinary | ssh-ed25519 | | SHA256:mKqU+0K8OhKmA8bBQi9Rz0Q5l7/g160hIP+rJYSTNj4

Options

Before and after
Keep all relevant records, including multiple key types and marker lines. A map with only one key per host can hide a meaningful change.
Hashed hosts
Hashed host identifiers are compared as entered. A different hash salt can prevent matching even when it names the same host.

Supported inputs and limits

Offline supported known_hosts records only. No host contact, hostname recovery, attack determination or automatic pin replacement.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

A changed pin needs investigation

A legitimate rotation, a changed endpoint or an unwanted key can all produce a difference. Confirm the expected key through an independent channel before accepting it. Hashed host fields are opaque here: only identical recorded identifiers can be matched, and the tool does not recover their hostnames.

Questions about Known-Hosts Change Comparer

Does a change mean an attack?

No. It identifies a change in the supplied pins and requires independent confirmation.

Can hashed hostnames be recovered?

No. They are compared opaquely without revealing their original names.

Are records updated automatically?

No. The page exports a review report and does not modify SSH files.

Project manager: Tony Hines · Content updated 4 October 2026 · Report a problem