What is the PPK file format?
A .ppk file is a PuTTY Private Key file - a text-based SSH private key container in PuTTY's proprietary format, created by the PuTTYgen key generation tool and used by PuTTY, WinSCP, FileZilla, and compatible SSH clients.
The file stores an SSH key pair (both public and private key components) in a structured multi-line text layout. The first line identifies the format version and key algorithm, for example:
PuTTY-User-Key-File-3: ssh-ed25519
This is followed by header fields for encryption type and comment, then Base64-encoded blocks for the public key, the optionally encrypted private key, and a MAC for integrity verification.
Three format versions exist:
- PPK v1 - obsolete legacy format
- PPK v2 - used by PuTTY prior to 0.75; passphrase protection uses a SHA-1-based KDF and AES-256-CBC; integrity verified with HMAC-SHA-1
- PPK v3 - introduced with PuTTY 0.75 (January 2021); replaces SHA-1 KDF with Argon2id, making passphrase brute-force significantly harder; uses HMAC-SHA-256
PuTTYgen can upgrade a v2 key to v3 in-place. To use a .ppk key with standard OpenSSH tools (ssh, scp, sftp), it must first be exported to PEM or OpenSSH new format via PuTTYgen; the two formats are not directly interchangeable.
PPK files are typically 1-4 KB regardless of key algorithm (RSA, DSA, ECDSA, Ed25519).
Security & safety
RISK: HIGHPPK files contain private key material - equivalent to a password for all servers where the corresponding public key is authorized. A PPK without a passphrase gives immediate SSH access if obtained by an attacker. Always protect with a strong passphrase. Use PPK v3 format (PuTTY 0.75+) for stronger Argon2id passphrase protection. Never store unencrypted PPK files on shared drives or include in source code repositories. Sites offering to "open" or "view" PPK files online are dangerous - uploading a private key to a third-party website is equivalent to giving away a password.
Format details
in a nutshellPrograms that open PPK files
Technical details
deep spec| Encoding | Text (ASCII/UTF-8 headers; Base64-encoded binary key data within) |
| File signature | First line is literally PuTTY-User-Key-File-N: algorithm (N = 2 or 3); identifies version and key algorithm |
| Format versions | v1 (obsolete); v2 (PuTTY <0.75, HMAC-SHA-1, SHA-1-based KDF); v3 (PuTTY 0.75+, Argon2id KDF, HMAC-SHA-256) |
| Key algorithms | ssh-rsa, ssh-dss (DSA), ecdsa-sha2-nistp256/384/521, ssh-ed25519, ssh-ed448 |
| Passphrase encryption | AES-256-CBC; v2 uses SHA-1-based KDF; v3 uses Argon2id (memory-hard KDF) - substantially stronger against brute-force |
| Integrity check | HMAC-SHA-1 (v2) or HMAC-SHA-256 (v3) computed over public key, private key, algorithm name, and comment |
| Structure | Multi-line key/value headers + Base64 blocks: public key lines, private key lines, Private-MAC; v3 adds Argon2 KDF parameter lines when encrypted |
| Typical size | 1 KB - 4 KB regardless of key algorithm |
| Interoperability | Not directly usable with OpenSSH tools; must be exported to PEM or OpenSSH new format via PuTTYgen |
| Contains | Both public and private key components in a single file |
| Security note | PPK v2 with SHA-1 HMAC is considered weaker; upgrading to v3 via PuTTYgen is recommended for keys still in v2 format |
| Released | Early 2000s (PuTTY 0.4x era); PPK v3 introduced with PuTTY 0.75 (2021) |
| Latest version | PPK version 3 (PuTTY 0.75+, 2021) |
| Specification | tartarus.org |
PPK conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about PPK files.