What you need to do before Suyu can decrypt game files
Suyu, the Nintendo Switch emulator, requires encryption keys to read and run Switch games on your computer. These keys decrypt the game files so the emulator can understand them. Without them, Suyu cannot launch most games — it will either refuse to start them or show an error message.
The keys themselves are not included with Suyu. You obtain them from your own Switch console, and then you place them in a specific file that Suyu reads when it starts. The process takes about ten minutes and involves creating a text file with a particular name in a particular location.
This guide covers where to get the keys, where to put them, and how to verify that Suyu recognizes them. It assumes you have already downloaded and installed Suyu itself.
Key Takeaways
- Encryption keys come from your own Switch console using a tool like Lockpick_RCM, not from the internet or Suyu itself.
- The keys go into a plain text file named prod.keys or dev.keys, placed in Suyu's config folder.
- On Windows, the config folder is usually C:\Users\[YourUsername]\AppData\Roaming\suyu\keys.
- On macOS and Linux, the keys folder is inside ~/.local/share/suyu/keys or ~/.config/suyu/keys depending on your setup.
- After placing the keys file, restart Suyu and try launching a game to confirm the keys are working.
Extracting keys from your Switch console
The only legitimate way to get encryption keys is to extract them from a Switch console you own. The most common tool for this is Lockpick_RCM, which runs on the Switch itself and outputs the keys to a text file.
To use Lockpick_RCM, you need to put your Switch into Recovery Mode (RCM) and send the tool to it using a computer and a USB cable. This requires either a modded Switch or a way to trigger RCM on an unmodified console — the method depends on your hardware revision. Once Lockpick_RCM runs, it generates a file containing all the keys your console uses.
If you do not have the ability to run Lockpick_RCM, you cannot obtain the keys through legitimate means. Do not download keys from the internet — they are copyrighted material, and distributing or downloading them violates Nintendo's terms of service and may violate copyright law in your country.
Finding Suyu's config folder on Windows
On Windows, Suyu stores its configuration files in the AppData folder, which is hidden by default. The full path is C:\Users\[YourUsername]\AppData\Roaming\suyu\keys, where [YourUsername] is your Windows login name.
The easiest way to navigate there is to open File Explorer, press Ctrl + L to highlight the address bar, paste the path above, and press Enter. Windows will take you directly to the folder. If the keys folder does not exist, create it by right-clicking in the empty space, selecting New, then Folder, and naming it keys.
Alternatively, you can open Suyu, go to File menu, select Open Suyu Folder, then navigate to the keys subfolder from there.
Finding Suyu's config folder on macOS and Linux
On macOS and Linux, Suyu stores keys in a hidden folder in your home directory. The path is usually ~/.local/share/suyu/keys on Linux or ~/.config/suyu/keys on macOS, though some setups use different locations.
To navigate there, open your file manager and use the keyboard shortcut to show hidden files — Ctrl + H on Linux, or Cmd + Shift + . on macOS. Then navigate to the path above. If the keys folder does not exist, open a terminal and run mkdir -p ~/.local/share/suyu/keys on Linux or mkdir -p ~/.config/suyu/keys on macOS.
You can also check Suyu's preferences to see the exact location it is using. Open Suyu, go to Emulation menu, select Configure, then look for the file paths section to confirm where your keys folder should be.
Creating and placing the keys file
Once you have extracted the keys from your Switch, you will have a text file containing the key data. Open a plain text editor — Notepad on Windows, TextEdit on macOS (set to plain text mode), or any text editor on Linux — and paste the key data into it.
Save this file as prod.keys (or dev.keys if you extracted development keys) in the keys folder you found above. The filename must be exactly prod.keys — no spaces, no different capitalization, no .txt extension. If your text editor adds .txt automatically, rename the file after saving to remove it.
Do not create multiple key files or put keys in the wrong folder. Suyu looks for prod.keys in the specific location above, and it will not find keys placed anywhere else.
Verifying that Suyu recognizes your keys
After placing the prod.keys file in the correct folder, close Suyu completely and reopen it. Then try launching a game from your library. If the keys are correct and in the right location, the game will start normally.
If Suyu shows an error message like "Failed to load game" or "Decryption failed", the keys file is either missing, in the wrong location, or contains corrupted data. Double-check the file path and the filename. Make sure there are no extra spaces or characters in the filename, and make sure the file is in plain text format, not a Word document or other format.
If you are still having trouble, open Suyu's log file to see what error it encountered. The log is usually in the same config folder as your keys. Look for messages that mention "keys" or "decryption" — they will tell you whether Suyu found the file and what went wrong if it did not.
Frequently Asked Questions
Can I use the same keys file on multiple computers?
Yes. The keys you extract from your Switch are tied to that console, not to a specific computer. You can copy the prod.keys file to the keys folder on any computer where you have Suyu installed, and it will work the same way.
What is the difference between prod.keys and dev.keys?
Production keys (prod.keys) decrypt retail games and the standard Switch firmware. Development keys (dev.keys) are used only for development consoles and are not needed for normal emulation. Use prod.keys unless you have a specific reason to use development keys.
Do I need to extract keys every time I update Suyu?
No. Once you have extracted the keys from your Switch and placed them in Suyu's keys folder, you do not need to extract them again. The keys do not change unless Nintendo updates the Switch firmware, and even then, you only need to extract them once after the update.
What happens if my keys file is corrupted or incomplete?
Suyu will either refuse to launch games or show a decryption error. Re-extract the keys from your Switch using Lockpick_RCM, making sure the tool completes without errors, and replace the old file with the new one.