What an SSH key does and why GitHub uses it
An SSH key is a pair of linked security codes — one public, one private — that proves you own your GitHub account without typing your password every time you push code. When you create a key on your computer, GitHub stores the public half. Each time you connect, your computer proves it has the matching private half, and GitHub lets you through.
This matters because passwords can be guessed or stolen. SSH keys are mathematically harder to forge. GitHub now requires SSH keys or a personal access token for any push over the command line, so you cannot avoid setting one up if you plan to work with repositories from your terminal.
Key Takeaways
- You generate an SSH key pair on your own computer using a built-in tool, then add the public key to your GitHub account settings.
- On Windows, use Git Bash (which comes with Git for Windows); on Mac and Linux, use the Terminal application that is already installed.
- The command ssh-keygen -t ed25519 -C "your_email@example.com" creates a modern, secure key in about 30 seconds.
- After generating the key, you must add it to GitHub's SSH keys page and test the connection before you can push code.
- If you lose your private key file, you can delete the public key from GitHub and create a new pair without affecting your repositories.
Generating your SSH key on Windows, Mac, or Linux
Open your terminal. On Windows, right-click in a folder and select "Git Bash Here" (if you have Git for Windows installed). On Mac and Linux, open the Terminal application from your Applications or system menu.
Type this command and press Enter:
ssh-keygen -t ed25519 -C "your_email@example.com"
Replace your_email@example.com with the email address you use for your GitHub account. The command creates a modern SSH key that is shorter and faster than older types.
The terminal will ask where to save the key. Press Enter to accept the default location (usually ~/.ssh/id_ed25519 on Mac and Linux, or C:\Users\YourName\.ssh\id_ed25519 on Windows). Then it will ask for a passphrase — a password to protect your private key file. You can leave this blank by pressing Enter twice, or type a passphrase and press Enter twice. A passphrase adds security if someone gains access to your computer, but you will type it each time you push code.
Finding and copying your public key
After the key is generated, you need to view the public half (the part you give to GitHub). In the same terminal window, type:
cat ~/.ssh/id_ed25519.pub
On Windows Git Bash, use the same command. The terminal will print a long string starting with ssh-ed25519 and ending with your email address. Highlight this entire string, right-click, and select Copy (or use Ctrl+C on Windows, Cmd+C on Mac).
Do not copy the private key file (the one without .pub at the end). Keep that file secret — it is what proves you own the key.
Adding your public key to GitHub
Go to github.com and sign in to your account. Click your profile picture in the top right corner and select Settings. On the left sidebar, click SSH and GPG keys.
Click the green New SSH key button. In the Title field, type a name for this key — something like "My Laptop" or "Work Computer" so you remember which device it is. Paste the public key you copied into the Key field. Leave the key type as Authentication Key. Click Add SSH key.
GitHub may ask you to confirm your password. Type it and click Confirm password. The key is now added to your account.
Testing your connection to GitHub
Go back to your terminal and type:
ssh -T git@github.com
Press Enter. The first time you connect, the terminal will ask if you trust GitHub's server. Type yes and press Enter. If your key is set up correctly, you will see a message like "Hi username! You've successfully authenticated, but GitHub does not provide shell access."
If you get a "Permission denied" error, the key was not added correctly. Go back to GitHub's SSH keys page and make sure the entire public key string was pasted without extra spaces or line breaks.
Using your SSH key when you clone or push
When you clone a repository, use the SSH URL instead of the HTTPS URL. On GitHub, click the green Code button, select the SSH tab, and copy the address that starts with git@github.com. Paste it into your terminal command:
git clone git@github.com:username/repository.git
From now on, when you push code with git push, your SSH key will authenticate you automatically. If you set a passphrase, you will type it once per terminal session, then it stays unlocked until you close the terminal.
What to do if you lose your private key or need a new one
Your private key file is stored on your computer. If you delete it, lose your computer, or want to use a different device, you can create a new key pair. The old key will no longer work, but your repositories are not affected.
To remove an old key from GitHub, go to Settings > SSH and GPG keys, find the key you no longer use, and click the trash icon next to it. Then generate a new key on your new device using the same steps above and add it to GitHub.
If you have multiple devices, you can add multiple SSH keys to your GitHub account — one per device. Each key gets its own entry on the SSH keys page.
Frequently Asked Questions
Do I need a different SSH key for each GitHub account?
You can use the same key for multiple accounts, but it is cleaner to create separate keys. If you manage more than one GitHub account, generate a second key with a different name (like id_ed25519_work) and add both public keys to GitHub. Then configure Git to use the right key for each account using a config file in ~/.ssh/.
What is the difference between SSH and HTTPS for GitHub?
HTTPS uses your GitHub username and password (or a personal access token). SSH uses your key pair. SSH is more secure because your password never travels over the network, and you do not have to type it repeatedly. GitHub now requires one or the other, so SSH is the standard choice.
Can I use the same SSH key on multiple computers?
Yes, you can copy your private key file to another computer and use it there. However, this means if one computer is compromised, both are at risk. It is safer to generate a separate key on each device and add each public key to GitHub separately.
What if I set a passphrase and keep forgetting it?
You cannot recover a forgotten passphrase. You will need to delete the key from GitHub and generate a new one without a passphrase (or with a passphrase you will remember). This does not affect your repositories.
Why does GitHub ask for my password after I set up SSH?
GitHub asks for your password when you add a new SSH key to your account for security — it confirms you own the account. This is separate from the passphrase on your key file. After you confirm, SSH handles authentication from then on.