What an SSH key does and why you need one

An SSH key is a pair of linked text files — one public, one private — that prove your identity to GitHub without you typing a password every time you push code. When you set one up, your computer uses the private key (which stays on your machine) to sign a message, and GitHub checks it against your public key (which you upload to your account). If they match, GitHub knows it's really you.

The practical benefit: you can push, pull, and fetch from the command line without entering credentials. The security benefit: your actual GitHub password never travels over the network, and if someone steals your computer, they can't use your GitHub account unless they also crack the passphrase protecting your private key.

GitHub stopped accepting password authentication for command-line operations in 2021, so if you're cloning repositories or pushing code from the terminal, you need either an SSH key or a personal access token. SSH keys are simpler for regular use.

Key Takeaways

  • You generate an SSH key pair on your own computer using the ssh-keygen command, which creates two files: a private key you keep secret and a public key you upload to GitHub.
  • The public key goes into your GitHub account settings under SSH and GPG keys; the private key stays on your computer and should never be shared.
  • On Windows, you can use Git Bash (which comes with Git for Windows) or Windows PowerShell with OpenSSH to generate and manage SSH keys.
  • After adding your key to GitHub, you test the connection by running ssh -T git@github.com to confirm everything is working before you try to push code.
  • If you use multiple computers or accounts, you can create separate SSH keys for each and tell your computer which key to use for which GitHub account.

Generating your SSH key pair on Mac or Linux

Open Terminal and run this command, replacing the email with the one you use for your GitHub account:

ssh-keygen -t ed25519 -C "your-email@example.com"

The system will ask where to save the key. Press Enter to accept the default location (~/.ssh/id_ed25519). Then it will ask for a passphrase — this is a password that protects your private key. Use something you'll remember but that's not your GitHub password. If you leave it blank, anyone with access to your computer can use your key, so a passphrase is worth the extra typing.

The command creates two files in your ~/.ssh folder: id_ed25519 (your private key) and id_ed25519.pub (your public key). You'll upload the .pub file to GitHub and never touch the other one.

Generating your SSH key pair on Windows

If you have Git for Windows installed, open Git Bash and run the same command as above:

ssh-keygen -t ed25519 -C "your-email@example.com"

Git Bash is a terminal that comes with Git for Windows and understands Unix-style commands. If you don't have Git for Windows yet, download it from git-scm.com and run the installer with default settings.

Alternatively, if you're using Windows PowerShell and have OpenSSH installed (Windows 10 build 1809 and later), you can run the same ssh-keygen command there. The process and file locations are identical.

Uploading your public key to GitHub

Go to github.com and sign into your account. Click your profile picture in the top right, then select Settings. On the left sidebar, click SSH and GPG keys.

Click the green "New SSH key" button. Give it a name that describes where you're using it — for example, "MacBook Pro" or "Work Desktop" — so you can recognize it later if you need to revoke it. In the "Key" field, paste the contents of your public key file (id_ed25519.pub). On Mac or Linux, you can copy it with cat ~/.ssh/id_ed25519.pub | pbcopy. On Windows with Git Bash, use cat ~/.ssh/id_ed25519.pub | clip.

Click "Add SSH key" and GitHub will save it. You're done uploading — your private key never leaves your computer.

Testing your connection to GitHub

Open Terminal or Git Bash and run this command:

ssh -T git@github.com

If this is your first time connecting, you'll see a message asking if you trust github.com's fingerprint. Type "yes" and press Enter. If everything is set up correctly, you'll see a message like "Hi username! You've successfully authenticated, but GitHub does not provide shell access."

If you get a "Permission denied" error, the most common cause is that your SSH agent isn't running or doesn't know about your key. On Mac and Linux, run ssh-add ~/.ssh/id_ed25519 to add your key to the agent, then test again. On Windows with Git Bash, the ssh-agent usually starts automatically, but you can manually start it with eval $(ssh-agent -s) followed by ssh-add ~/.ssh/id_ed25519.

Cloning and pushing with your SSH key

When you clone a repository, use the SSH URL instead of the HTTPS URL. On GitHub, click the green "Code" button on any repository page and select the SSH tab. Copy the URL that starts with git@ (not https://), then run git clone followed by that URL.

From that point on, git push, git pull, and git fetch will all use your SSH key automatically. You won't be prompted for a password.

If you've already cloned a repository using HTTPS and want to switch it to SSH, navigate into that repository folder and run git remote set-url origin followed by the SSH URL from the Code button.

Managing multiple SSH keys for different accounts

If you use GitHub for work and personal projects with different accounts, or if you use multiple computers, you can create separate SSH keys for each. Generate each key with a different name — for example, id_ed25519_work and id_ed25519_personal — by specifying the filename when ssh-keygen asks where to save it.

Then create or edit a file called config in your ~/.ssh folder (no file extension) and add entries like this:

Host github.com-work   HostName github.com   User git   IdentityFile ~/.ssh/id_ed25519_work Host github.com-personal   HostName github.com   User git   IdentityFile ~/.ssh/id_ed25519_personal

Upload each public key to its corresponding GitHub account. When you clone a repository, use github.com-work or github.com-personal instead of github.com in the SSH URL, and git will automatically use the right key.

Frequently Asked Questions

What if I lose my private key or my computer crashes?

Your private key is gone, but that's okay — you can generate a new one on a different computer and upload the new public key to GitHub. Your old key will still be listed in your GitHub settings, so go back and delete it. You don't need to do anything to your repositories; they'll work with the new key immediately.

Can someone use my SSH key if they get my computer?

Not without your passphrase. If you set a passphrase when you created the key, they'd need to crack it to use the key. If you didn't set a passphrase, they could use it, which is why a passphrase is worth setting even if it's inconvenient.

Do I need a different SSH key for each repository?

No. One SSH key can push to and pull from all your repositories. You only need separate keys if you're using different GitHub accounts or want to restrict which computers can access which accounts.

What's the difference between ed25519 and RSA keys?

Ed25519 is newer, shorter, and just as secure as RSA for most uses. GitHub recommends it. If you see instructions telling you to use RSA, you can safely use ed25519 instead — it's supported everywhere RSA is.

Why does GitHub ask for my password after I set up SSH?

You might be using an HTTPS URL instead of an SSH URL when you clone. Check that your remote URL starts with git@ by running git remote -v in your repository folder. If it shows https://, switch it to SSH using git remote set-url origin followed by the SSH URL from GitHub's Code button.