What an SSH key does and why GitHub uses it
An SSH key is a pair of linked text files — one public, one private — that prove your identity to GitHub without you typing your password every time. When you push code to a repository, GitHub checks your private key against the public one you uploaded. If they match, the push goes through. If they don't, it fails.
SSH is more secure than typing a password because your private key never leaves your computer. GitHub never sees it. A stolen password can be used from anywhere; a stolen private key only works if someone also has access to your machine or the file itself. GitHub requires SSH keys for any account that uses the command line, and recommends them even if you use the web interface.
You generate both keys on your own computer. You keep the private key secret. You upload the public key to GitHub. That's the entire setup.
Key Takeaways
- SSH keys are generated in pairs on your computer using a tool called ssh-keygen, which creates a private key you keep secret and a public key you upload to GitHub.
- The private key file should never be shared, moved, or uploaded anywhere — it stays in a folder called .ssh on your computer.
- You add the public key to GitHub through your account settings under SSH and GPG keys, and GitHub will use it to verify every push and pull you make from the command line.
- After you add the key, test it by running ssh -T git@github.com from your terminal to confirm GitHub recognizes your computer.
Generate an SSH key pair on your computer
Open your terminal (Terminal on Mac, PowerShell on Windows, or your Linux terminal). Type this command exactly:
ssh-keygen -t ed25519 -C "your_email@example.com"
Replace your_email@example.com with the email address you use for your GitHub account. The -t ed25519 part tells ssh-keygen to use a modern, secure algorithm. Press Enter.
The tool will ask where to save the key. It will suggest a default path like /Users/yourname/.ssh/id_ed25519. Press Enter to accept this. Do not change the path unless you have a specific reason — the .ssh folder is where SSH tools expect to find keys.
Next, it will ask for a passphrase. This is optional but recommended. A passphrase is a password that protects your private key file itself. If someone gains access to your computer's files, they still cannot use your private key without the passphrase. You can leave it blank by pressing Enter twice, but adding one (even a short phrase like "github-key-2024") is safer.
When the command finishes, you will see two files created in your .ssh folder: id_ed25519 (your private key) and id_ed25519.pub (your public key). The .pub file is the one you will upload to GitHub.
Copy your public key to your clipboard
You need to read the contents of your public key file and copy it. On Mac or Linux, type:
cat ~/.ssh/id_ed25519.pub
On Windows PowerShell, type:
Get-Content $env:USERPROFILE\.ssh\id_ed25519.pub | Set-Clipboard
The cat command (Mac/Linux) will print the key to your screen. It will look like a long string starting with ssh-ed25519 and ending with your email address. Select all of it and copy it to your clipboard. The PowerShell command (Windows) copies it directly without printing it.
Do not modify the key or add spaces. Copy it exactly as it appears.
Add the public key to your GitHub account
Go to github.com and sign in. Click your profile picture in the top right corner, then click Settings. On the left sidebar, click SSH and GPG keys. Click the green New SSH key button.
In the Title field, give the key a name so you remember which computer it belongs to — something like "MacBook Pro" or "Work Desktop" is fine. In the Key field, paste the public key you just copied. Leave the Key type set to Authentication Key. Click Add SSH key.
GitHub may ask you to confirm your password. Enter it and click Confirm password. The key is now added to your account.
Test the connection from your terminal
Go back to your terminal and type:
ssh -T git@github.com
Press Enter. The first time you connect, your terminal will ask if you trust GitHub's server. Type yes and press Enter. If everything is set up correctly, you will see a message like "Hi username! You've successfully authenticated, but GitHub does not provide shell access."
If you see an error like "Permission denied (publickey)", the key was not added correctly. Check that you copied the entire public key, including the ssh-ed25519 part at the start and your email at the end. If you added a passphrase, your terminal may ask for it when you run the test — type it and press Enter.
Use the key when cloning or pushing code
When you clone a repository from GitHub, use the SSH URL, not the HTTPS URL. On the repository page, click the Code button, select SSH, and copy the URL. It will look like git@github.com:username/repository-name.git. Then run:
git clone git@github.com:username/repository-name.git
Replace the URL with the one you copied. Git will use your SSH key automatically — you will not need to type a password. If you added a passphrase to your key, your terminal will ask for it once per session.
If you already cloned a repository using HTTPS and want to switch to SSH, go into that repository's folder and run:
git remote set-url origin git@github.com:username/repository-name.git
Again, replace the URL with your repository's SSH URL. Future pushes and pulls will use the SSH key.
Frequently Asked Questions
What if I lose my private key or my computer crashes?
Your private key is gone, but your GitHub account is not. Go to github.com, find the SSH key you added in your settings, and delete it. Then generate a new key pair on your new computer or after reinstalling your system, and add the new public key to GitHub. You can have multiple SSH keys on one GitHub account — one for each computer you use.
Can I use the same SSH key on multiple computers?
Technically yes, but it is not recommended. If one computer is compromised, someone could use that key from anywhere. It is safer to generate a separate key pair on each computer you use and add each public key to GitHub separately. GitHub lets you add as many keys as you need.
Do I need to do this for every repository?
No. Once you add an SSH key to your GitHub account, it works for every repository you own or have access to. You only add the key once per computer.
What if my terminal says "command not found" when I run ssh-keygen?
On Mac and Linux, ssh-keygen is built in. On Windows, you need either Git Bash (which comes with Git for Windows) or Windows Subsystem for Linux. If you installed Git for Windows, open Git Bash instead of PowerShell and run the ssh-keygen command there.
Is a passphrase really necessary?
It adds a layer of security, but it is not required. Without a passphrase, anyone who gains access to your .ssh folder can use your key. With a passphrase, they would also need to know the password. If you are the only person with access to your computer and you trust its security, you can skip it. If you share your computer or work in a shared environment, a passphrase is worth the extra step.