Skip to content
JustTools

PEM to PPK Converter

Turn an id_rsa, AWS .pem or other OpenSSH/PEM private key into a PuTTY .ppk for PuTTY, WinSCP and FileZilla — passphrase-protected keys included. Converted in your browser; nothing is uploaded.

Runs in your browser Free · no sign-up

At a glance

  • Reads OpenSSH keys (BEGIN OPENSSH PRIVATE KEY), traditional PEM (BEGIN RSA / EC / DSA PRIVATE KEY) and PKCS#8, encrypted or not.
  • Unlocks passphrase-protected keys: OpenSSH’s bcrypt + AES, and PEM/PKCS#8 encrypted with AES or 3DES (as older OpenSSL and PuTTYgen exports are).
  • Writes PPK v3 (PuTTY 0.75+, WinSCP 5.19+) or PPK v2 for older PuTTY versions, with an optional passphrase.
  • Supports RSA, ECDSA (P-256, P-384, P-521), Ed25519 and DSA keys, and keeps the key comment.
  • Shows the key type, size and SHA256 fingerprint, and the public key line for authorized_keys.
  • Output is tested against PuTTY’s format and read back by an independent PPK reader.
  • Runs entirely in your browser — the private key is never uploaded.

Step by step

How to convert a PEM file to PPK

  1. 1

    Open the key

    Click Open a key file and choose your .pem or id_rsa file, or paste the key text.

  2. 2

    Unlock it

    If the key has a passphrase, enter it and click Unlock.

  3. 3

    Choose PPK

    Pick PPK v3 (or PPK v2 for older PuTTY), set the comment and optionally a passphrase.

  4. 4

    Download

    Click Convert and Download the .ppk file.

Features

Everything you need, nothing you don’t

AWS keys in PuTTY

Downloaded an EC2 key pair as .pem? Convert it to .ppk to connect with PuTTY or WinSCP on Windows.

No PuTTYgen needed

Works in any browser, on any computer — handy on a work laptop where you can’t install software.

Old and new PuTTY

Choose PPK v3 for current PuTTY, or v2 for older PuTTY, WinSCP and tools that don’t read v3 yet.

Keep it protected

Add a passphrase to the .ppk so the key is encrypted on disk.

Check the fingerprint

The SHA256 fingerprint matches what ssh-keygen and PuTTYgen show, so you can confirm it’s the right key.

Private

Your key is converted in this browser tab and never sent anywhere.

Using the .ppk file

PuTTY: Connection → SSH → Auth → Credentials → “Private key file for authentication”, then save the session.

WinSCP: Login → Advanced → SSH → Authentication → Private key file. FileZilla: Settings → Connection → SFTP → Add key file.

Going the other way? Use the PPK to PEM converter.

PPK v3 or v2?

PPK v3PPK v2
Works withPuTTY 0.75 and later, WinSCP 5.19+, current FileZillaAll PuTTY versions and older tools
Passphrase protectionArgon2 (much harder to crack)Older SHA-1 based scheme
Choose whenYour tools are up to dateA tool says the key format is unsupported

FAQ

Frequently asked questions

How do I convert a PEM file to PPK?

Open the .pem file here, enter its passphrase if it has one, choose PPK v3 and click Convert. Then download the .ppk — no PuTTYgen needed.

Can I convert an AWS EC2 .pem key to .ppk?

Yes. AWS key pairs download as PEM files; convert them to .ppk here and load them in PuTTY or WinSCP. Connect as the instance’s user, such as ec2-user or ubuntu.

Does it support new OpenSSH keys (BEGIN OPENSSH PRIVATE KEY)?

Yes, including passphrase-protected ones. Unlocking takes a second or two because OpenSSH deliberately makes passphrase checks slow.

PuTTY says “unsupported key format” — what now?

Your PuTTY is probably older than 0.75. Convert again choosing PPK v2, or update PuTTY.

Is it safe to convert a private key online?

The conversion happens in your browser and the key is never uploaded. Use only tools you trust with private keys, and delete spare copies afterwards.

Which key types are supported?

RSA, ECDSA (P-256, P-384, P-521), Ed25519 and DSA. Ed448 and security-key (sk-) keys aren’t supported by PuTTY’s format here.

Keep going

Browse every tool

Last updated Report a problem or suggest a feature