How to Create an SSH Key and Log In to a Server Without a Password
An SSH key is a pair of files that replaces your password when you log in to a server. The private key stays only on your computer; the public key is copied to the server. When you connect, the server checks that you hold the private key matching the public one and lets you in without a password.
Why a key beats a password:
- It can't be guessed. Bots try SSH passwords on every server on the internet around the clock. A key hundreds of bits long can't be brute-forced.
- It can't be seen or intercepted. The private key is never sent over the network.
- It's more convenient. No password on every login, and with ssh-agent not even the key passphrase.
This guide shows how to create a key on Linux, macOS and Windows, copy it to a server, set up quick connections and turn off password login. We'll use Ed25519, the modern standard: short keys, high speed and strong security.
Step 1. Create an SSH Key on Linux and macOS
Open a terminal on your own computer (not on the server) and run:
ssh-keygen -t ed25519 -C "my-laptop"
-C is a comment so you can later tell which device the key belongs to. Use your computer's name or your email.
The tool asks two questions:
- Where to save the key. Press Enter to save it in the default location,
~/.ssh/id_ed25519. If a key already exists there, it will offer to overwrite it: answern, or you'll lose the old key and access to the servers that use it. - Passphrase. This password encrypts the key itself. If your laptop is stolen, the key is useless without it. We recommend setting one — you won't have to type it every time once ssh-agent is set up (see below).
Two files appear in ~/.ssh:
id_ed25519— the private key. Never send it to anyone or copy it to servers.id_ed25519.pub— the public key. It's safe to share: copy it to servers, paste it into your hosting panel, GitHub or GitLab.
View the public key:
cat ~/.ssh/id_ed25519.pub
It's a single line: ssh-ed25519 AAAAC3Nza... my-laptop.
If the server is old and doesn't support Ed25519 (OpenSSH older than 2014), create a 4096-bit RSA key: ssh-keygen -t rsa -b 4096 -C "my-laptop".
How to Create an SSH Key on Windows
Windows 10 and 11 come with a built-in OpenSSH client, so you don't need PuTTY. Open PowerShell (right-click Start → Terminal) and run the same command:
ssh-keygen -t ed25519 -C "my-laptop"
The rest is the same as on Linux: press Enter for the default location and set a passphrase. The keys are saved in C:\Users\NAME\.ssh.
View the public key in PowerShell:
type $env:USERPROFILE\.ssh\id_ed25519.pub
If ssh-keygen isn't found, enable the OpenSSH client: Settings → System → Optional features → OpenSSH Client.
If you use PuTTY. PuTTY works with keys in its own .ppk format. Create a key in PuTTYgen (type EdDSA, Ed25519), or load an existing key with the Load button and save it as .ppk. In PuTTY, set the key under Connection → SSH → Auth → Credentials.
Step 2. Copy the Public Key to the Server
The public key goes into ~/.ssh/authorized_keys on the server — in the home folder of the user you'll log in as. Pick whichever method suits you.
Method 1: ssh-copy-id (Linux and macOS). The easiest option. It logs in with your password and adds the key with the right permissions:
ssh-copy-id user@SERVER_IP
Replace user with your username on the server, for example root on a new VPS.
Method 2: PowerShell on Windows. Windows has no ssh-copy-id, but one command does the same:
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh user@SERVER_IP "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"
Method 3: your hosting panel. Most hosts let you add a public key in the panel when you create a VPS. The key is then on the server from the start, and you never need a password. Paste the full contents of the .pub file as one line.
Method 4: manually on the server. Copy the public key to your clipboard, log in with your password and run:
mkdir -p ~/.ssh && chmod 700 ~/.ssh
echo "YOUR_PUBLIC_KEY" >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys
Permissions matter: if the .ssh folder or authorized_keys file is accessible to other users, SSH ignores the key and asks for a password again.
Step 3. Connect and Set Up Quick Login
Connect to the server:
ssh user@SERVER_IP
If everything is set up correctly, the server won't ask for the user's password. It may ask only for the key passphrase — that's normal, it decrypts the key on your computer.
If your key isn't in the default location, specify it explicitly:
ssh -i ~/.ssh/my_server_key user@SERVER_IP
The config file: log in with one word. To avoid typing the username, IP, port and key path every time, save them in ~/.ssh/config on your computer (on Windows, C:\Users\NAME\.ssh\config, with no extension). Open it in any text editor and add:
Host myvps
HostName 203.0.113.10
User admin
Port 22
IdentityFile ~/.ssh/id_ed25519
Now you log in with just:
ssh myvps
The name from the Host line works in other commands too: for example, scp file.zip myvps:~/ copies a file to the server. For several servers, add several Host blocks, each with its own name.
Step 4. Disable Password Login
As long as password login is on, bots keep trying to guess it. Once key login works, turn passwords off — this shuts down password guessing completely.
Don't close your current SSH session until you've tested key login in a new terminal window.
On the server, create a settings file:
sudo nano /etc/ssh/sshd_config.d/01-hardening.conf
Add these lines:
PasswordAuthentication no
KbdInteractiveAuthentication no
PubkeyAuthentication yes
Check the config and restart SSH:
sudo sshd -t && sudo systemctl restart ssh
The 01-... name matters: many hosts put a 50-cloud-init.conf file with PasswordAuthentication yes in the same folder, and SSH uses the first value it finds.
From your computer, confirm that password login is really off:
ssh -o PubkeyAuthentication=no user@SERVER_IP
You should get Permission denied (publickey), meaning passwords are no longer accepted. For the remaining server hardening steps, see what to do right after buying a VPS.
SSH-AGENT: Stop Typing Your Passphrase Every Time
ssh-agent keeps the decrypted key in memory: you enter the passphrase once per session, while the key stays protected on disk.
Linux. On most desktop distributions the agent is already running. Add your key to it:
ssh-add ~/.ssh/id_ed25519
If you see Could not open a connection to your authentication agent, start the agent first: eval "$(ssh-agent -s)".
macOS. Add the key to the agent and store the passphrase in Keychain:
ssh-add --apple-use-keychain ~/.ssh/id_ed25519
Then add two lines to the top of ~/.ssh/config so the key loads automatically after a reboot:
AddKeysToAgent yes
UseKeychain yes
Windows. The ssh-agent service is disabled by default. Open PowerShell as administrator and enable it:
Get-Service ssh-agent | Set-Service -StartupType Automatic
Start-Service ssh-agent
Then, in a regular PowerShell window, add your key:
ssh-add $env:USERPROFILE\.ssh\id_ed25519
On any system, you can list the keys loaded into the agent with ssh-add -l.
How to Store and Use Keys Safely
- The private key never leaves your computer. Don't send it in messengers, put it in cloud storage or copy it to servers. Even your host's support only ever needs the public key.
- One key per device. Don't copy the same key to your laptop and work PC. If a device is lost, you just remove one line from
authorized_keyson the server — the-Ccomment shows whose key it is. - Always set a passphrase. With ssh-agent it doesn't get in the way, and if a device is stolen it protects access to all your servers. To add or change the passphrase on an existing key:
ssh-keygen -p -f ~/.ssh/id_ed25519. - Correct permissions. On Linux and macOS:
chmod 700 ~/.sshandchmod 600 ~/.ssh/id_ed25519. Otherwise SSH refuses to use the key. - A way back in if you lose the key. Add keys from two devices to the server and know where the web console (VNC) is in your hosting panel: it lets you log in without SSH and add a new key.
- Clean up
authorized_keysregularly. Remove keys from old devices and former team members.
Common Errors
Permission denied (publickey). The server rejected the key. Check that the public key is inauthorized_keysof the exact user you're logging in as, and that~/.sshandauthorized_keyshave 700 and 600 permissions. Connect with-vfor details:ssh -v user@SERVER_IP.WARNING: UNPROTECTED PRIVATE KEY FILE!Other users can read your private key. Fix it withchmod 600 ~/.ssh/id_ed25519. On Windows this happens when the key was copied from another drive: in the file's Properties → Security, leave access only for your own user.WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!The server's fingerprint changed — usually after reinstalling the OS on the VPS. If you did reinstall it, remove the old fingerprint:ssh-keygen -R SERVER_IP. If not, don't connect and contact support.Too many authentication failures. The agent offers the server too many keys in turn. Specify the right one:ssh -o IdentitiesOnly=yes -i ~/.ssh/id_ed25519 user@SERVER_IP, or addIdentitiesOnly yesto theHostblock in your config file.- The server still asks for a password. Usually wrong permissions on
.ssh, or the key was pasted with line breaks and split into pieces. Each key inauthorized_keysmust be exactly one line.
Checklist
FAQ
Which is better: Ed25519 or RSA? Ed25519: the key is shorter, faster and just as secure as RSA. You need RSA only for very old systems — use 4096 bits.
Can I use one key for several servers? Yes. One public key can be added to any number of servers, as well as GitHub and GitLab.
What if I lose my private key? It can't be recovered. Log in via your host's web console or with a backup key, create a new key, add its public part to authorized_keys and delete the old line.
What if I forget my passphrase? The key can't be decrypted without it. Create a new key and replace it on your servers, just as if you'd lost the key.
Do I need an SSH key for GitHub? Yes, the same one works. Copy the public key to Settings → SSH and GPG keys and test the connection with ssh -T git@github.com.