Skip to content

prod.keys is a plain-text keyset file. Understanding its structure is useful because most “invalid key” and “cannot recognise keyset” problems are structural rather than cryptographic. This guide describes the file at that level. It contains no values.

Filename

The file is conventionally named prod.keys. The name matters more than it looks: many tools look for that exact filename, so a file saved as prod keys.txt or Prod.Keys may exist and still be ignored. If a tool reports that no keyset was found, check the name before the contents.

File type

It is a text file, not a binary blob. That is why encoding and line endings matter, and why a file opened in the wrong editor can be silently altered. It should be transferred in a way that does not change bytes — not retyped, not copy-pasted through a word processor.

Keyset structure

Structurally the file is a list of named entries. Each entry has a name that identifies its category or purpose, and a value. Entries are grouped by the revision or generation they belong to, which is what makes it a keyset rather than a flat list of unrelated strings.

Key names

Key names are descriptive identifiers: they say what an entry is for, not what it is. Reading the names is how you understand which categories a keyset contains. The key categories guide explains what the main groups of names refer to at a conceptual level.

Hexadecimal representation

Values are written in hexadecimal text. Two consequences follow. First, the file is human-readable in form, which is why handling errors are so easy to make. Second, a single altered character changes the value entirely — there is no checksum to warn you that an edit was wrong, which is why editing a keyset by hand is a bad idea.

Comments and whitespace

Some keysets carry comment lines. Whether a tool ignores them depends on the tool, so a file that parses in one application may be rejected by another. Whitespace causes the same class of problem: a trailing space after a value, a tab instead of a space, or a blank line in the wrong place can break a parser that is stricter than expected.

Case sensitivity

Names and values are generally case-sensitive as written. A value entered in upper case where lower case is expected is a different value. If a single entry is rejected while the rest of the file loads, case and whitespace are the first two things to check.

Revision tags and categories

The revision a set of entries belongs to is part of the file’s meaning, not decoration. A keyset can be perfectly formatted and still unusable because the revision it carries does not match what the content expects. That is a different failure from a formatting error, and it is covered by unsupported revision.

No key values appear on this page. This site describes the file’s structure and never reproduces its contents. If you need a keyset, generate it from hardware you are authorised to use, and treat the result as sensitive material.

Checking structure without exposing values

A format validator can confirm that a file is well-formed — correct names, consistent formatting, expected structure — without displaying or transmitting the values. That is the right first step when a tool rejects a keyset. See format validators and parsers.