What an SSH key does and why GitHub needs one

An SSH key is a pair of linked codes — one public, one private — that proves to GitHub that you own the account you're trying to access. Instead of typing your password every time you push code, your computer uses the private key to sign off on the request, and GitHub's servers verify it with the public key. This is faster, more secure, and means you don't have to store your actual password on your machine.

When you set up SSH, you're telling GitHub: "This computer is allowed to make changes to my repositories without asking for a password." The private key stays on your computer. The public key goes to GitHub. They never meet, and GitHub never sees your private key.

Key Takeaways

  • You generate an SSH key pair on your own computer using a built-in tool, then add the public key to your GitHub account settings.
  • Windows users need to open PowerShell or Git Bash; Mac and Linux users open Terminal — all three come with the tools you need.
  • The command to generate the key is the same across all operating systems: ssh-keygen -t ed25519 -C "your-email@example.com"
  • After generating the key, you copy the public key file and paste it into GitHub's SSH keys settings page, then test the connection.
  • Once set up, you clone repositories using the SSH URL instead of HTTPS, and you won't be asked for a password on future pushes.

Generating your SSH key on Windows

Open PowerShell by right-clicking on your desktop or in File Explorer and selecting "Open PowerShell here," or search for PowerShell in the Start menu. Paste this command and press Enter:

ssh-keygen -t ed25519 -C "your-email@example.com"

Replace your-email@example.com with the email address you use for GitHub. The system will ask where to save the key — just press Enter to accept the default location. Then it will ask for a passphrase. You can leave this blank by pressing Enter twice, or type a password for extra security. If you add a passphrase, you'll type it once per session when you first use SSH, not every time you push.

PowerShell will show you a fingerprint and a random image. This confirms the key was created. You're done with the generation step.

Generating your SSH key on Mac or Linux

Open Terminal (on Mac, search for Terminal in Spotlight; on Linux, right-click the desktop or use your application menu). Paste this command and press Enter:

ssh-keygen -t ed25519 -C "your-email@example.com"

Again, replace the email with your GitHub email. Press Enter to accept the default save location, then press Enter twice for no passphrase, or type a passphrase and press Enter twice if you want one.

The system will display a fingerprint and a visual key. The key is now stored in a hidden folder called .ssh in your home directory.

Adding your public key to GitHub

You now have two files: a private key (which stays on your computer) and a public key (which goes to GitHub). You need to copy the public key and paste it into GitHub's settings.

On Windows in PowerShell, type:

cat ~/.ssh/id_ed25519.pub

On Mac or Linux in Terminal, type the same command. The system will print a long string starting with ssh-ed25519. Highlight the entire output with your mouse and copy it (Ctrl+C on Windows or Linux, Command+C on Mac).

Go to GitHub.com, sign in, and click your profile picture in the top right corner. Select Settings, then SSH and GPG keys on the left sidebar. Click the green New SSH key button. Give it a title like "My Laptop" or "Work Computer" so you remember which machine it is. Paste the key you copied into the Key field and click Add SSH key.

Testing your SSH connection

Go back to PowerShell (Windows) or Terminal (Mac/Linux) and type:

ssh -T git@github.com

The first time you run this, the system will ask if you trust GitHub's server. Type yes and press Enter. If everything is set up correctly, you'll see a message like "Hi [your username]! You've successfully authenticated, but GitHub does not provide shell access."

If you see an error, the most common cause is that you copied the wrong file. Make sure you copied from id_ed25519.pub (the public key with .pub at the end), not id_ed25519 (the private key with no extension). The public key is safe to share; the private key must never leave your computer.

Cloning and pushing with SSH from now on

When you clone a repository from GitHub, use the SSH URL instead of the HTTPS URL. On the repository page, click the green Code button and select the SSH tab. Copy the URL (it starts with git@github.com). In your terminal, type:

git clone [paste the SSH URL here]

From this point forward, when you push changes to GitHub, you won't be asked for a password. Your SSH key handles the authentication automatically. If you set a passphrase when creating the key, you may be asked for it once per terminal session, but not for every push.

What to do if you lose access to your computer

If your computer is stolen, lost, or you're switching machines, you should remove the SSH key from GitHub. Sign into GitHub, go to Settings > SSH and GPG keys, find the key you want to remove, and click the trash icon. This prevents anyone with that computer from accessing your repositories.

On your new computer, generate a fresh SSH key using the same steps above and add it to GitHub. You can have multiple SSH keys on GitHub at once — one for each computer you use — so you don't have to delete the old one before creating a new one.

Frequently Asked Questions

What's the difference between the public and private key?

The public key is safe to share and goes to GitHub. The private key is secret and stays on your computer. GitHub uses the public key to verify that requests are coming from someone who has the matching private key. Never paste your private key anywhere or share it with anyone.

Can I use the same SSH key on multiple computers?

Technically yes, but it's not recommended. If one computer is compromised, someone could use that key to access your GitHub account. It's better to generate a separate key on each computer and add each one to GitHub separately. You can have as many keys on GitHub as you need.

What if I forget my passphrase?

If you set a passphrase and forget it, you'll need to generate a new SSH key. The old one will still work for pushing code, but you won't be able to use it if you need to re-authenticate. Delete the old key from GitHub and create a new one without a passphrase, or with a passphrase you'll remember.

Do I need SSH if I'm just reading repositories?

No. SSH is only required when you want to push changes (write to a repository). You can clone and read public repositories over HTTPS without any setup. SSH becomes necessary once you start contributing code.

Why does GitHub recommend ed25519 instead of RSA?

Ed25519 keys are shorter, faster to verify, and considered more secure than older RSA keys. If you see guides recommending RSA, they're still valid but ed25519 is the current standard. Both work fine with GitHub.