Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

SSH key authentication proves that the client can create a valid signature with the private key corresponding to a public key the server accepts for the account. The private key is not sent to the server. Password authentication works differently: it sends the password value inside an SSH authentication packet, but the SSH transport encrypts that packet when confidentiality is active. Keys change the authentication proof and the credential-management risks; they do not make a poorly secured SSH account automatically safe.

What an SSH key proves

RFC 4252 describes public-key authentication as proof of possession: “With this method, the possession of a private key serves as authentication.” The server must also check that the corresponding public key is valid for the user and that the signature is valid. RFC 4252

  1. The server identifies acceptable keys. In a common OpenSSH setup, it checks configured authorized-keys files. The documented default filenames are .ssh/authorized_keys and .ssh/authorized_keys2. A key’s presence in an authorized-keys source grants authentication rights subject to its options and server policy. OpenSSH sshd(8)
  2. The client accesses the matching private key. It may be stored locally, accessed through an agent, or held by a supported hardware authenticator.
  3. The client signs the authentication data. The signature includes the SSH session identifier and authentication request fields, binding it to that session and request rather than presenting a reusable password string. RFC 4252
  4. The server verifies both authorization and proof. The associated public key must be accepted for that user, and the signature must verify. Server policy may require another authentication method as well.

This establishes that the client can use an authorized private-key credential for the requested authentication. It does not establish that a particular person is at the keyboard, that the client device is uncompromised, or that nobody has copied the private key.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How password authentication differs

With SSH password authentication, the client sends the password value in the authentication packet. That does not mean the password is ordinarily exposed in cleartext to a passive network observer: RFC 4252 specifies that the packet is encrypted by the SSH transport, and says both endpoints should check that the transport provides confidentiality. RFC 4252

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Question Public-key authentication Password authentication
What the client presents A public-key identity and a signature made with the corresponding private key. The password value inside an SSH authentication packet.
What the server checks That the key is authorized for the account and the signature is valid. That the supplied password passes the server’s configured password validation.
Effect of SSH transport encryption Authentication takes place within the SSH connection. The authentication packet is encrypted when the transport provides confidentiality.

The difference is not that one method uses encryption and the other does not. SSH protects the connection with its transport; the methods differ in what the client uses as its authentication proof.

Why keys can be preferable—and where the risk moves

A key-based login avoids presenting the password itself as the authentication proof. Instead, the client demonstrates use of a private credential by signing data bound to the SSH session. This changes the risks an attacker must address, but it is not a universal guarantee that keys are safer under every configuration. The outcome depends on the account, server policy, client device, key storage, and recovery practices.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Private-key exposure: Someone who obtains an usable private key may gain access until the key is removed or revoked. Limit access to the key file or agent; OpenSSH documents that a private-key file should not be readable by others. OpenSSH ssh-keygen(1)
  • Passphrase trade-off: A passphrase encrypts the private portion of a local key. If forgotten, it cannot be recovered; the user must create a replacement key and install its public key again. OpenSSH ssh-keygen(1)
  • Client compromise: Malware or an attacker controlling the client may be able to use credentials available to that device, even if the key file itself is protected.
  • Overbroad authorization: An authorized key grants access under the configured key options and server policy. OpenSSH supports per-key restrictions such as forced commands and source-address constraints. OpenSSH sshd(8)
  • Weak recovery or revocation: OpenSSH supports revoked-key files and key revocation lists, but administrators must maintain the revocation mechanism and remove or reject exposed credentials. OpenSSH sshd(8)
  • Password-related risks remain distinct: Password reuse, guessing, exposure at endpoints, and account password policy still matter when password authentication is enabled. SSH transport encryption does not address those endpoint or account-management risks.

Using a key with another authentication method

Key authentication does not have to be the only step. OpenSSH’s AuthenticationMethods setting can require sequences such as publickey,password or publickey,keyboard-interactive. The server’s configured policy determines whether an additional method is required. OpenSSH sshd_config(5)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Optional: hardware-backed FIDO2 SSH keys

OpenSSH supports FIDO authenticator-backed key types including ecdsa-sk and ed25519-sk. The authenticator must be present to sign; it can keep a device-specific private key non-exportable. User-presence or user-verification requirements are configurable for supported FIDO keys. This is an optional way to strengthen key custody, not a prerequisite for ordinary SSH key authentication. OpenSSH ssh-keygen(1)

Rank #3
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Compatibility depends on the client, operating system, firmware, and key model. Yubico’s documentation says FIDO support generally requires OpenSSH 8.2 or later; its verify-required PIN-per-use option requires OpenSSH 8.4 or later. The bundled macOS OpenSSH may lack FIDO support, Windows has a separate version requirement, and some key types depend on device firmware. Check the specific setup before choosing a hardware authenticator. Yubico: Securing SSH with the YubiKey

Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Rank #4
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.