Ed25519 is a digital signature algorithm that uses the twisted Edwards curve edwards25519 and SHA-512, with 32-byte public keys and 64-byte signatures. It is the Edwards-curve Digital Signature Algorithm (EdDSA) variant defined in RFC 8032, and it targets about 128 bits of security. A signature depends only on the key and the message, so signing the same input twice gives identical bytes.
The private key is 32 random bytes, called the seed. The signer hashes the seed with SHA-512 and splits the 64-byte result. The first half, with some bits cleared and set, becomes a secret scalar, and the second half becomes a prefix. The public key is that scalar times the base point, packed into 32 bytes.
To sign, the algorithm hashes the prefix together with the message to get a nonce r, so no random number generator is needed at signing time. The signature has two 32-byte halves, R and S. R is the nonce point and S combines the nonce, the key and a hash of R, the public key and the message.
RFC 8032 lists three variants. Plain Ed25519 signs the whole message. Ed25519ph signs a SHA-512 hash of it, and Ed25519ctx adds a context string. Plain Ed25519 is the one TLS, SSH and most libraries expose.
The script below signs an empty message with the first test key in RFC 8032, and both the public key and the signature match that RFC.
from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey
from cryptography.hazmat.primitives import serialization as s
sk=Ed25519PrivateKey.from_private_bytes(bytes.fromhex("9d61b19deffd5a60ba844af492ec2cc44449c5697b326919703bac031cae7f60"))
pub=sk.public_key().public_bytes(s.Encoding.Raw,s.PublicFormat.Raw)
sig=sk.sign(b"")
print("public:", pub.hex(), len(pub))
print("sig :", sig.hex(), len(sig))
print("again identical:", sk.sign(b"")==sig)
public: d75a980182b10ab7d54bfed3c964073a0ee172f3daa62325af021a68f707511a 32
sig : e5564300c360ac729086e2cc806e828a84877f1eb8e5d974d873e065224901555fb8821590a33bacc61e39701cf9b46bd25bf5f0595bbe24655141438e7a100b 64
again identical: True
An Ed25519 private key is 32 bytes, the public key is 32 bytes and the signature is 64 bytes. Contrast that with RSA-2048, whose signature is 256 bytes, and with P-256 ECDSA, whose raw signature is also 64 bytes but varies from 70 to 72 bytes in DER. Some APIs return a 64-byte private key, which is the 32-byte seed followed by the public key, so check which form a library means.
Ed25519 differs from ECDSA mainly in how the nonce is made and in how verification behaves. ECDSA needs a good random k for every signature, while Ed25519 derives it from the key and message. RFC 8032 notes that EdDSA formulas are complete, so verification needs no separate point validation, and signatures resist the hash collisions that hurt pure hash-then-sign schemes. Verification also rejects any S that is not smaller than the group order, which stops signature malleability (RFC 8032, section 8.4).
TLS 1.3 assigns Ed25519 the signature scheme code 0x0807 (RFC 8446), and RFC 8709 defines it for SSH.