Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To remove an obsolete SSH key safely, identify it by its public-key fingerprint, confirm with its owner or provisioning records that it is no longer needed, then remove only that entry from the active authorization source. A comment such as “experimental” is a useful lead, not proof. Keep a working session open and test a separate login before closing it.

Find the authorization source SSH actually uses

These steps assume OpenSSH. Do not assume the account’s visible ~/.ssh/authorized_keys file is authoritative: the server’s AuthorizedKeysFile setting can specify one or more other paths. If the directive is unspecified, the current OpenBSD sshd(8) manual lists ~/.ssh/authorized_keys and ~/.ssh/authorized_keys2 as defaults. A deployment may also provision keys centrally.

On the server, inspect the effective sshd configuration for the account and host in question, including applicable configuration files and any conditional settings, and determine which file or files are active. Configuration and service-management details vary by operating system; consult that system’s OpenSSH documentation if the effective setting is unclear. If a central provisioning system manages keys, identify its source of truth before editing.

Identify the candidate key with a fingerprint

Each non-comment record in an authorized-keys file is a public-key authorization record. OpenSSH records may include options before the key type, followed by the base64-encoded public key and an optional comment. Blank lines and lines beginning with # are ignored, according to the OpenBSD sshd(8) manual.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Display fingerprints for the keys in the active file with:

ssh-keygen -lf /path/to/authorized_keys

Replace the example path with the actual file path. The -l option displays fingerprints, as documented in the OpenBSD ssh-keygen(1) manual. Match the candidate fingerprint against a trusted enrollment record or the public key held by the system that created it. A fingerprint is a compact identifier for comparing key material; it does not, by itself, establish who owns the key or whether it is still in use.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Use labels as clues, not proof

The text at the end of a key record is a comment for people. The OpenBSD sshd(8) manual states: “The comment field is not used for anything (but may be convenient for the user to identify the key).” A label like experimental, temporary, or a person’s name does not determine authorization and may be stale, ambiguous, or edited. Identify the key by its fingerprint, then confirm its purpose with its owner, current users, enrollment records, or provisioning system.

Remove only the confirmed obsolete entry

  1. Preserve a recovery path. Keep an existing authenticated session open, back up the active authorization file, and make sure another known-good login method or administrator recovery path is available before editing.
  2. Change the source of truth. If the file is managed by configuration management or another provisioning system, remove the key from that system rather than only editing a generated copy. Otherwise, a later run may restore the entry.
  3. Edit the correct file. Remove only the line matching the confirmed public key. Preserve all other key records and any options attached to them.
  4. Check the edit and access. Re-read the file and verify intended users still have an authorized key. Test a login in a separate session while the recovery session remains open. For a fleet, verify that the change reached every relevant account and host.

File permissions can also affect whether OpenSSH accepts the file. The OpenBSD sshd(8) manual recommends that the user can read and write the authorized-keys file and that others cannot access it. With StrictModes enabled, sshd may reject authorization files when the file, the .ssh directory, or the home directory is writable by other users. Confirm host-specific settings and existing policy before changing permissions.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If the key may be compromised, remove it more broadly

Removing a record from one account’s authorization source removes that particular authorization there; it does not show whether the same key is installed elsewhere. If a key is lost or compromised, check known deployment sources and other relevant accounts and hosts. Where your organization uses OpenSSH Key Revocation Lists (KRLs), consider revoking the key there as well. The OpenBSD ssh-keygen(1) manual documents KRL operations, including revocation records based on key material or fingerprints; available behavior can vary with the installed OpenSSH version.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Quick ways to judge whether a key is obsolete

Evidence What it tells you How to use it
Comment or label A human-readable clue; it does not control authorization and may be outdated. Use it to find a candidate, not as the sole reason to delete it.
Fingerprint A compact identifier for matching the public key. Compare it with a trusted enrollment record or the key from its provisioning system.
Owner or provisioning record Can establish the key’s purpose and whether it is still in use. Confirm with the responsible person or system before removal.

Replacing a removed key with a FIDO authenticator-hosted SSH key is optional, not part of the cleanup requirement. The OpenBSD ssh-keygen(1) manual documents FIDO authenticator options and key types, but compatibility depends on the installed OpenSSH version, platform, supported authenticator, and recovery arrangements. Verify those details before choosing a replacement.

Best Value
Yubico - YubiKey 5Ci - Multi-Factor authentication (MFA) Security Key and passkey for iPhone/Android/PC, Dual connectors for Lighting/USB-C, FIDO Certified
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.