Recommended command
Run this in PowerShell, Terminal, or a Linux shell. Replace the example comment with an email address or label that helps you identify the key.
ssh-keygen -t ed25519 -C "you@example.com"Accept the default file only if it will not overwrite an existing key. Enter a strong, unique passphrase when prompted.
Before generating a new key
An SSH key pair contains a shareable public key and a private key that must remain private. Anyone who obtains the private key may be able to authenticate as you wherever that key is trusted.
ssh -VCheck the contents of your .ssh directory before accepting a default filename. If id_ed25519 already exists, choose a descriptive new filename rather than overwriting it.
Step 1: Generate an Ed25519 key
GitHub documents Ed25519 as its normal new-key command, and GitLab identifies Ed25519 as its preferred key type. It is compact, widely supported by current OpenSSH clients, and does not require choosing an RSA bit length.
ssh-keygen -t ed25519 -C "you@example.com"Use a custom filename when you have multiple keys
ssh-keygen -t ed25519 -C "you@example.com" -f ~/.ssh/id_ed25519_githubThe command creates two files: id_ed25519_github is the private key; id_ed25519_github.pub is the public key. Never upload, email, paste, or publish the file without .pub.
When to use RSA instead
Use RSA only when a legacy or FIPS-constrained destination does not support Ed25519 and its own documentation calls for RSA. GitHub and GitLab both document 4096-bit RSA as the compatibility alternative.
ssh-keygen -t rsa -b 4096 -C "you@example.com"Step 2: Protect the private key with a passphrase
ssh-keygen prompts for a passphrase after the filename. A passphrase encrypts the private key file at rest. Use a strong unique passphrase and let ssh-agent remember the unlocked key during your session instead of leaving the key unprotected.
OpenSSH’s -a option controls the bcrypt PBKDF rounds used for passphrase-protected private keys. Higher values slow offline guessing if the encrypted key file is stolen. Defaults vary by installed OpenSSH version; avoid copying aggressive values without testing the devices that must unlock the key.
Step 3: Add the key to ssh-agent
Linux
eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_ed25519macOS
ssh-add --apple-use-keychain ~/.ssh/id_ed25519GitHub documents --apple-use-keychain for Apple’s current ssh-add. If the key has no passphrase, omit that option and use ssh-add ~/.ssh/id_ed25519.
Windows PowerShell
Windows 10 build 1809 and later can provide OpenSSH as an optional feature. In an elevated PowerShell window, configure and start the Windows agent:
Get-Service -Name ssh-agent | Set-Service -StartupType Manual
Start-Service ssh-agentThen use a regular, non-elevated terminal to add the private key:
ssh-add $env:USERPROFILE\.ssh\id_ed25519Git for Windows may use a different bundled SSH client than the Windows service. Use one SSH implementation consistently if the agent appears to forget a key.
Step 4: Copy only the public key
macOS
tr -d '\n' < ~/.ssh/id_ed25519.pub | pbcopyLinux with xclip installed
xclip -selection clipboard < ~/.ssh/id_ed25519.pubWindows PowerShell
Get-Content $env:USERPROFILE\.ssh\id_ed25519.pubA public Ed25519 key begins with ssh-ed25519. Copy the whole single line, including the optional comment. Verify the filename ends in .pub before copying.
Add the public key to GitHub
- Open GitHub settings and select SSH and GPG keys.
- Select New SSH key, give it a device-specific title, and paste the public key.
- Test the connection:
ssh -T git@github.comOn the first connection, compare the displayed host-key fingerprint with GitHub’s published fingerprints before answering yes.
Add the public key to GitLab
- Open your GitLab profile and go to Access → SSH keys.
- Select Add new key, paste the public key, and choose an identifying title.
- Set an expiration date when appropriate, then verify the connection:
ssh -T git@gitlab.comAdd the public key to a Linux server
If password login is currently allowed, ssh-copy-id can append the public key to the remote account’s authorized_keys file:
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@example.comTest key authentication in a second terminal before disabling another access method. Server policy, file permissions, account restrictions, and cloud-provider access workflows can differ.
Should you use an online SSH key generator?
No online generator is needed for normal OpenSSH use. Native ssh-keygen creates the private key on your own machine, supports passphrase encryption, and avoids asking you to trust a website with private-key material. This page provides commands and copy buttons only; it never generates or receives your SSH key.
Hardware-backed SSH keys
OpenSSH 8.2 and later can use compatible FIDO security keys with ed25519-sk or ecdsa-sk. GitHub and GitLab document these separately because the hardware must be present during enrollment and authentication. Use their current hardware-key instructions rather than treating the resulting files like an ordinary portable private key.
Sources and reviewed scope
Commands and platform steps were reviewed against current first-party documentation on October 1, 2026.