# @microsoft/dev-tunnels-ssh-keys

> SSH key import/export library for Dev Tunnels

Latest version **3.12.42** (published 2026-08-24) · MIT license · 0 weekly downloads

## Install

```sh
npm install @microsoft/dev-tunnels-ssh-keys
pnpm add @microsoft/dev-tunnels-ssh-keys
yarn add @microsoft/dev-tunnels-ssh-keys
bun add @microsoft/dev-tunnels-ssh-keys
```

## Health

**Score 60/100 (C)** — status: active.

Positive: has types; no vulnerabilities; recently updated; high maintenance score.

Warnings: low downloads; no esm support.

## Facts

| | |
|---|---|
| Version | 3.12.42 |
| Published | 2026-08-24 |
| First published | 2022-09-29 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | CommonJS |
| Dependencies | 1 |
| Unpacked size | 177.2 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 162 |
| Author | Microsoft |
| Maintainers | microsoft1es, microsoft-oss-releases, debekoe-msft, devtunnels |
| Keywords | SSH |

## Links

- npm: https://www.npmjs.com/package/@microsoft/dev-tunnels-ssh-keys
- Repository: https://github.com/microsoft/dev-tunnels-ssh
- Homepage: https://github.com/microsoft/dev-tunnels-ssh#readme
- Issues: https://github.com/microsoft/dev-tunnels-ssh/issues
- npm.io page: https://npm.io/package/@microsoft/dev-tunnels-ssh-keys

## Dependencies (1)

- [@microsoft/dev-tunnels-ssh](https://npm.io/package/@microsoft/dev-tunnels-ssh.md) ~3.12

## Recent versions

- 3.12.42 (latest) — 2026-08-24
- 3.12.40 — 2026-07-29
- 3.12.36 — 2026-06-11
- 3.12.29 — 2026-05-01
- 3.12.22 — 2026-03-31
- 3.12.12 — 2025-08-20
- 3.12.5 — 2024-09-26
- 3.11.38 — 2024-04-10
- 3.11.36 — 2023-12-20
- 3.11.35 — 2023-12-15
- 3.11.34 — 2023-12-14
- 3.11.33 — 2023-10-27
- 3.11.31 — 2023-10-05
- 3.11.26 — 2023-08-29
- 3.11.25 — 2023-08-28
- … 29 more at https://npm.io/package/@microsoft/dev-tunnels-ssh-keys/versions

## README

# Dev Tunnels SSH Keys Library
Enables importing and exporting SSH public and private keys in various formats.
Password-protection of private keys is also supported when importing and
exporting some formats.

## Supported Key Algorithms
 - RSA (2048, 4096)
 - ECDSA (P-256, P-384, P-521)

## Supported Key Formats

 - **SSH public key** - Single line starting with a key algorithm name
   such as `ssh-rsa`, followed by base64-encoded key bytes, and an optional
   comment. Files in this format typically end with `.pub`.

 - **PKCS#1 public or private RSA key** - PEM-encoded keys in this format begin
   with one of the following:  
   `-----BEGIN RSA PUBLIC KEY-----`  
   `-----BEGIN RSA PRIVATE KEY-----`  

 - **SEC1 private EC key** - PEM-encoded keys in this format begin with:  
   `-----BEGIN EC PRIVATE KEY-----`  

 - **PKCS#8 public or private key** - PEM-encoded keys in this format begin
   with one of the following:  
   `-----BEGIN PUBLIC KEY-----`  
   `-----BEGIN PRIVATE KEY-----`  
   `-----BEGIN ENCRYPTED PRIVATE KEY-----`

 - **JSON Web Key (JWK)** - Key paramters are formatted as JSON.

Private keys in PKCS#1, SEC1, or PKCS#8 format may be passphrase-protected,
meaning the private key is encrypted using an encryption key derived from a
passphrase. (The encryption used by the PKCS#1/SEC1 formats is weak and no
longer recommended.)

For the key formats that are typically PEM-encoded, the equivalent binary (DER)
format is also supported.

## Example
Use `importKey*`, `exportPublicKey*`, and `exportPrivateKey*` functions provided
by the library to import or export keys. When importing, the key format can be
auto-detected in most cases.

```TypeScript
// Import my password-protected RSA private key from a file.
const privateKey: KeyPair = importPrivateKeyFile('.ssh/id_rsa', myPassword);

// Use the private key for client public key authentication.
const session: SshClientSession = ...
const credentials: SshClientCredentials = { username, publicKeys: [ privateKey ] };
const result: boolean = await session.authenticate(credentials);
```

When exporting, you can specify the format, and optionally supply a password
for encrypting the key. The default format is **PKCS#8** because it has broad
support and strong encryption when using password protection.

---
_Source: https://npm.io/package/@microsoft/dev-tunnels-ssh-keys · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
