Skip to content
JustTools

PPK to PEM Converter

Turn a PuTTY .ppk key into a PEM or OpenSSH key for ssh, Git, AWS and macOS/Linux — passphrase-protected keys included. Converted entirely in your browser; the key never leaves your device.

Runs in your browser Free · no sign-up

At a glance

  • Reads PuTTY PPK version 2 and 3 files, including passphrase-protected ones (Argon2 for v3, as PuTTY 0.75 and later write them).
  • Converts to PEM (BEGIN RSA / EC / DSA PRIVATE KEY), OpenSSH (BEGIN OPENSSH PRIVATE KEY), PKCS#8 or another PPK version.
  • Supports RSA, ECDSA (P-256, P-384, P-521), Ed25519 and DSA keys.
  • Checks the key file’s MAC, so a wrong passphrase or a damaged file is reported instead of producing a broken key.
  • Can add a new passphrase to the converted key, and shows the SHA256 fingerprint and public key line (for authorized_keys).
  • Tested against keys made by PuTTYgen and checked with OpenSSH’s ssh-keygen and OpenSSL.
  • Runs entirely in your browser — the private key is never uploaded.

Step by step

How to convert a PPK file to PEM

  1. 1

    Open the .ppk file

    Click Open a key file and choose your .ppk, or paste its text.

  2. 2

    Unlock it

    If the key has a passphrase, enter it and click Unlock.

  3. 3

    Choose the format

    Pick PEM (or OpenSSH / PKCS#8) and optionally a new passphrase.

  4. 4

    Download

    Click Convert, then Download. On macOS/Linux run chmod 600 on the file before using it.

Features

Everything you need, nothing you don’t

Without PuTTYgen

Convert on any computer or phone — no need to install PuTTY or use the command line on a Mac or Linux machine.

Passphrases handled

Unlock an encrypted .ppk with its passphrase, and choose whether the new key has one.

Every format

PEM for AWS and older tools, OpenSSH for modern ssh and Git, PKCS#8 for code libraries.

Verify before you use it

Compare the SHA256 fingerprint with the one your server or PuTTYgen shows.

Public key too

Copy the matching public key line for ~/.ssh/authorized_keys or download it as .pub.

Private

Your key is converted in this browser tab and never sent anywhere.

PEM or OpenSSH — which do I need?

Ed25519 keys have no traditional PEM form, so choosing PEM gives the standard PKCS#8 “BEGIN PRIVATE KEY” format instead.

UseChoose
ssh on macOS/Linux, Git, VS Code RemoteOpenSSH (or PEM — both work)
AWS EC2 .pem files, older tools, ParamikoPEM
Java, Node.js, Python cryptography librariesPKCS#8
An older PuTTY or WinSCP that rejects new keysPPK v2

Using the converted key

Save it in ~/.ssh (for example ~/.ssh/id_rsa) and run chmod 600 ~/.ssh/id_rsa — ssh refuses keys that other users can read. Then connect with ssh -i ~/.ssh/id_rsa user@server.

Need it the other way round? Use the PEM to PPK converter.

FAQ

Frequently asked questions

How do I convert a PPK file to PEM?

Open the .ppk file here, enter its passphrase if it has one, choose PEM and click Convert. Download the new key — no PuTTYgen needed.

Does it work with PuTTY’s new PPK version 3 files?

Yes. PPK v3 (PuTTY 0.75 and later), including keys protected with Argon2 passphrases, and older v2 files are both supported.

Is it safe to convert a private key online?

The conversion runs in your browser and the key is never uploaded, so it’s as private as converting on your own computer. Still, use only sites you trust with keys, and delete spare copies afterwards.

What if I forgot the passphrase?

It can’t be recovered — the passphrase is what decrypts the key. You’ll need to create a new key pair and add its public key to your servers.

Why does ssh say “bad permissions” or “unprotected private key”?

The key file is readable by other users. Run chmod 600 on it (or remove other users’ access on Windows), then try again.

Can I convert DSA keys?

Yes, but OpenSSH 9.8 and later no longer accept DSA (ssh-dss) keys. Create a new Ed25519 key for new servers.

Keep going

Browse every tool

Last updated Report a problem or suggest a feature