Keypairs with solana-keygen
Generate Ed25519 keypairs, recover wallets from seed phrases, and grind vanity addresses with solana-keygen.
Search across all documentation pages
Generate Ed25519 keypairs, recover wallets from seed phrases, and grind vanity addresses with solana-keygen.
Quick-reference recipe card - copy-paste ready.
# New keypair (interactive passphrase optional)
solana-keygen new --outfile ~/.config/solana/id.json
# Recover from 12/24-word seed phrase
solana-keygen recover -o recovered.json
# Vanity prefix (slow - increase --num-threads)
solana-keygen grind --starts-with abc:1 --ignore-caseWhen to reach for this:
solana config set --keypair.mkdir -p ~/.config/solana
solana-keygen new --outfile ~/.config/solana/id.json --no-bip39-passphrase
solana config set --keypair ~/.config/solana/id.json
solana address
# Backup seed phrase when prompted - store offline, never in git
chmod 600 ~/.config/solana/id.jsonWhat this demonstrates:
--no-bip39-passphrase skips an extra encryption layer (dev only).chmod 600 restricts read access to your user account.solana address confirms the public key matches expectations.solana-keygen new can emit a BIP39 seed phrase for recovery.solana address.| Field | Format | Notes |
|---|---|---|
| Secret key | JSON byte array (64 bytes) | Contains seed + public key bytes |
| Passphrase | Optional BIP39 | Encrypts the on-disk file when set |
| Seed phrase | 12 or 24 words | Independent backup path to the same key |
# Verify pubkey without exposing the secret file contents
solana-keygen pubkey ~/.config/solana/id.json
# Prompt for passphrase-protected key during recover
solana-keygen recover prompt:// -o recovered.json*.json key paths to .gitignore and use hardware or CI secrets for production.--num-threads, or accept a shorter match.solana-keygen new overwrites existing paths without a prompt in scripts. Fix: check test -f before generating in automation.| Alternative | Use When | Don't Use When |
|---|---|---|
| Hardware wallet (Ledger) | Mainnet treasury and upgrade authority | Quick localnet iteration |
solana-keygen recover | Restoring from seed phrase | Generating brand-new keys |
| Browser wallet (Phantom) | End-user signing in dApps | Headless CI deploy pipelines |
mucho key helpers | Foundation scaffold workflows | You only need a single dev key |
A JSON array of 64 unsigned bytes representing the Ed25519 secret key. The CLI and Anchor read this format natively.
They encode the same key material when created together. You can recover the JSON from the phrase with solana-keygen recover, but you cannot derive the phrase from the JSON alone if you skipped recording it.
Yes for any key that holds mainnet funds. For throwaway devnet keys, --no-bip39-passphrase is common but never commit those files.
solana-keygen pubkey path/to/keypair.jsonOnly through a secrets manager or encrypted channel - never Slack or email. Prefer separate keys per machine for dev and a single hardware-backed key for production roles.
CPU time grows exponentially with prefix length. A 3-character prefix is quick; 6+ characters may need dedicated hardware or overnight runs.
Run solana-keygen recover prompt:// and enter the phrase when prompted. Use ASK or prompt:// forms documented in solana-keygen recover --help.
Yes via WSL or native builds from the Agave installer. Paths differ - use %USERPROFILE%\.config\solana\ equivalents.
chmod 600 on Unix so only your user can read the secret bytes.
Program deploy keypairs sign deployment transactions; program IDs come from the program keypair's public key. Store program keys with the same care as treasury keys.
Stack versions: This page was written for Agave 4.1.1, Solana CLI 3.0.10, Anchor 0.32.1, anchor-lang 0.32.1, Rust 1.91.1, @solana/kit 7.0.0, Surfpool 0.12.0, and LiteSVM 0.6.x.
Reviewed by Chris St. John·Last updated Jul 16, 2026