OpenSSH command guide

Generate an SSH Key

Create an Ed25519 public/private key pair on your own Windows, macOS, or Linux computer, protect the private key, and add only the public key to GitHub, GitLab, or a server.

Recommended command

Run this in PowerShell, Terminal, or a Linux shell. Replace the example comment with an email address or label that helps you identify the key.

Ed25519 SSH key pair
ssh-keygen -t ed25519 -C "you@example.com"

Accept the default file only if it will not overwrite an existing key. Enter a strong, unique passphrase when prompted.

Before generating a new key

An SSH key pair contains a shareable public key and a private key that must remain private. Anyone who obtains the private key may be able to authenticate as you wherever that key is trusted.

Check your OpenSSH version
ssh -V

Check the contents of your .ssh directory before accepting a default filename. If id_ed25519 already exists, choose a descriptive new filename rather than overwriting it.

Step 1: Generate an Ed25519 key

GitHub documents Ed25519 as its normal new-key command, and GitLab identifies Ed25519 as its preferred key type. It is compact, widely supported by current OpenSSH clients, and does not require choosing an RSA bit length.

Default Ed25519 filename
ssh-keygen -t ed25519 -C "you@example.com"

Use a custom filename when you have multiple keys

Dedicated GitHub key
ssh-keygen -t ed25519 -C "you@example.com" -f ~/.ssh/id_ed25519_github

The command creates two files: id_ed25519_github is the private key; id_ed25519_github.pub is the public key. Never upload, email, paste, or publish the file without .pub.

When to use RSA instead

Use RSA only when a legacy or FIPS-constrained destination does not support Ed25519 and its own documentation calls for RSA. GitHub and GitLab both document 4096-bit RSA as the compatibility alternative.

RSA compatibility key
ssh-keygen -t rsa -b 4096 -C "you@example.com"
Do not use DSA. GitHub no longer supports new DSA keys, and current platforms treat it as obsolete.

Step 2: Protect the private key with a passphrase

ssh-keygen prompts for a passphrase after the filename. A passphrase encrypts the private key file at rest. Use a strong unique passphrase and let ssh-agent remember the unlocked key during your session instead of leaving the key unprotected.

OpenSSH’s -a option controls the bcrypt PBKDF rounds used for passphrase-protected private keys. Higher values slow offline guessing if the encrypted key file is stolen. Defaults vary by installed OpenSSH version; avoid copying aggressive values without testing the devices that must unlock the key.

Step 3: Add the key to ssh-agent

Linux

Start agent and add default key
eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_ed25519

macOS

Add key and store passphrase in Keychain
ssh-add --apple-use-keychain ~/.ssh/id_ed25519

GitHub documents --apple-use-keychain for Apple’s current ssh-add. If the key has no passphrase, omit that option and use ssh-add ~/.ssh/id_ed25519.

Windows PowerShell

Windows 10 build 1809 and later can provide OpenSSH as an optional feature. In an elevated PowerShell window, configure and start the Windows agent:

Elevated PowerShell
Get-Service -Name ssh-agent | Set-Service -StartupType Manual
Start-Service ssh-agent

Then use a regular, non-elevated terminal to add the private key:

Regular PowerShell
ssh-add $env:USERPROFILE\.ssh\id_ed25519

Git for Windows may use a different bundled SSH client than the Windows service. Use one SSH implementation consistently if the agent appears to forget a key.

Step 4: Copy only the public key

macOS

Copy public key
tr -d '\n' < ~/.ssh/id_ed25519.pub | pbcopy

Linux with xclip installed

Copy public key
xclip -selection clipboard < ~/.ssh/id_ed25519.pub

Windows PowerShell

Display public key for copying
Get-Content $env:USERPROFILE\.ssh\id_ed25519.pub

A public Ed25519 key begins with ssh-ed25519. Copy the whole single line, including the optional comment. Verify the filename ends in .pub before copying.

Add the public key to GitHub

  1. Open GitHub settings and select SSH and GPG keys.
  2. Select New SSH key, give it a device-specific title, and paste the public key.
  3. Test the connection:
Verify GitHub authentication
ssh -T git@github.com

On the first connection, compare the displayed host-key fingerprint with GitHub’s published fingerprints before answering yes.

Add the public key to GitLab

  1. Open your GitLab profile and go to Access → SSH keys.
  2. Select Add new key, paste the public key, and choose an identifying title.
  3. Set an expiration date when appropriate, then verify the connection:
Verify GitLab authentication
ssh -T git@gitlab.com

Add the public key to a Linux server

If password login is currently allowed, ssh-copy-id can append the public key to the remote account’s authorized_keys file:

Install public key on a server
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@example.com

Test key authentication in a second terminal before disabling another access method. Server policy, file permissions, account restrictions, and cloud-provider access workflows can differ.

Should you use an online SSH key generator?

No online generator is needed for normal OpenSSH use. Native ssh-keygen creates the private key on your own machine, supports passphrase encryption, and avoids asking you to trust a website with private-key material. This page provides commands and copy buttons only; it never generates or receives your SSH key.

Hardware-backed SSH keys

OpenSSH 8.2 and later can use compatible FIDO security keys with ed25519-sk or ecdsa-sk. GitHub and GitLab document these separately because the hardware must be present during enrollment and authentication. Use their current hardware-key instructions rather than treating the resulting files like an ordinary portable private key.

Sources and reviewed scope

Commands and platform steps were reviewed against current first-party documentation on October 1, 2026.