Download Cheat sheet PDF 12 pages · syntax, editors, patterns, Unicode, performance, debugging
Pattern

Regex for SSH public key

OpenSSH format public key — ssh-rsa, ssh-ed25519, etc.

The SSH public key regex is ^(ssh-rsa|ssh-ed25519|ecdsa-sha2-nistp\d+|ssh-dss)\s+[A-Za-z0-9+/]+=*(\s+[^\s]+)?$ — copy it below, or open it in the explainer for a token-by-token breakdown.

The pattern

^(ssh-rsa|ssh-ed25519|ecdsa-sha2-nistp\d+|ssh-dss)\s+[A-Za-z0-9+/]+=*(\s+[^\s]+)?$
Try in explainer → Download cheat sheet ↓

What it matches

  • ssh-rsa AAAAB3NzaC1yc2EAAAA...== user@host
  • ssh-ed25519 AAAAC3NzaC1lZDI1NTE5...= laptop

What it doesn't match

  • ssh-rsa
  • BEGIN OPENSSH PRIVATE KEY
  • rsa AAAA

Notes & gotchas

OpenSSH public key format: algorithm + base64-encoded key + optional comment. Common in ~/.ssh/authorized_keys.

Code in your language

Use the explainer's Code tab to generate ready-to-paste snippets in JavaScript, Python, Java, .NET, Go, Ruby, and PHP for this pattern.

Open in explainer →

Token-by-token breakdown

Every part of the pattern, left to right:

TokenMeaning
^start of string (or line in multiline mode)
(start of a capturing group
ssh-rsaliteral text “ssh-rsa”
|OR — try the alternative
ssh-ed25519literal text “ssh-ed25519”
|OR — try the alternative
ecdsa-sha2-nistpliteral text “ecdsa-sha2-nistp”
\d+one or more: digit (0–9)
|OR — try the alternative
ssh-dssliteral text “ssh-dss”
)end of group
\s+one or more: whitespace
[A-Za-z0-9+/]+one or more: any of: uppercase letters, lowercase letters, digits, “+”, “/”
=*zero or more: the literal “=”
(start of a capturing group
\s+one or more: whitespace
[^\s]+one or more: any character except whitespace
)?end of group, optional (zero or one)
$end of string (or line in multiline mode)

About this pattern

Identifier formats like UUIDs, hashes, and version strings have well-defined structures that regex captures cleanly. The pattern verifies format; checksums and validity against a registry need additional checks.

Quick usage in different languages

This exact pattern — with the correct escaping and idioms for each language:

  • JavaScript: /^(ssh-rsa|ssh-ed25519|ecdsa-sha2-nistp\d+|ssh-dss)\s+[A-Za-z0-9+\/]+=*(\s+[^\s]+)?$/.test(value)
  • Python: re.match(r"^(ssh-rsa|ssh-ed25519|ecdsa-sha2-nistp\d+|ssh-dss)\s+[A-Za-z0-9+/]+=*(\s+[^\s]+)?$", value)
  • Java: Pattern.compile("^(ssh-rsa|ssh-ed25519|ecdsa-sha2-nistp\\d+|ssh-dss)\\s+[A-Za-z0-9+/]+=*(\\s+[^\\s]+)?$").matcher(value).matches()
  • C# / .NET: Regex.IsMatch(value, @"^(ssh-rsa|ssh-ed25519|ecdsa-sha2-nistp\d+|ssh-dss)\s+[A-Za-z0-9+/]+=*(\s+[^\s]+)?$")
  • Go: regexp.MustCompile(`^(ssh-rsa|ssh-ed25519|ecdsa-sha2-nistp\d+|ssh-dss)\s+[A-Za-z0-9+/]+=*(\s+[^\s]+)?$`).MatchString(value)
  • Ruby: /^(ssh-rsa|ssh-ed25519|ecdsa-sha2-nistp\d+|ssh-dss)\s+[A-Za-z0-9+\/]+=*(\s+[^\s]+)?$/.match?(value)
  • PHP: preg_match('~^(ssh-rsa|ssh-ed25519|ecdsa-sha2-nistp\d+|ssh-dss)\s+[A-Za-z0-9+/]+=*(\s+[^\s]+)?$~', $value)

The explainer’s Code tab regenerates these for any pattern you paste, and the downloadable cheat sheet bundles the breakdown, all seven snippets, and the pitfalls below onto one printable page.

Common pitfalls

  • Anchored to the whole string. This pattern uses ^ and $, so it requires the entire input to match. To find it inside a longer text, drop the anchors and use the global (g) flag.
  • ASCII letters only. [a-zA-Z] excludes accented and non-Latin letters (é, ü, ß, ñ, and non-Latin scripts). For international input use Unicode properties like \p{L} with the u flag.
  • Escape it correctly per language. In Java and JavaScript strings each backslash must be doubled (\\d); in Python, Go, and C# use raw/verbatim strings so the backslashes survive.
  • Validate beyond format. Matching the format doesn't guarantee the value is real. Confirm the ssh public key against a source of truth (database, API, or checksum) where it matters.

Standards & sources

This pattern is based on the following authoritative specification(s) and issuing authorities. Formats can change — always confirm against the primary source.

Related patterns

More patterns in the Codes & IDs category:

See also

Browse all 300 patterns in the library, or open this regex in the interactive explainer to see a token-by-token breakdown, test against custom input, and generate code in seven languages.


← Back to all patterns