Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To set up SSH access, check for an existing key, generate a suitable key pair if needed, protect its private key with a passphrase, load it into an SSH agent when useful, and register only the public key with the service you want to access. Then test the connection and periodically review which keys remain trusted.
Understand what an SSH key pair does
An SSH key pair contains a private key and a public key. Keep the private key on your computer and do not upload or share it. Add the public key to the service or server that should recognize you. For GitHub, adding the public key to your account is required before that key can authenticate SSH connections. GitHub’s account setup guide explains its registration process.
Check for existing keys before creating one
A key may already be configured for another service or machine. Inspect the existing keys before generating a new pair; reuse a suitable key or choose a distinct filename if you need another. Avoid overwriting a key whose purpose you do not know. GitHub provides steps for checking for existing SSH keys.
Recommended Free Tools
Generate a key that your client and service support
GitHub’s documented default example uses Ed25519. For a system that does not support Ed25519, its guide gives RSA with a 4096-bit key as a legacy alternative. These are GitHub examples, not a guarantee that every SSH client or remote service accepts the same algorithms; check the requirements for your target.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
ssh-keygen -t ed25519 -C "your_email@example.com"
When prompted for a file location, accept the default only if it will not overwrite a key you need. Otherwise, enter a new filename. GitHub’s guide includes the platform-specific generation and agent steps: Generating a new SSH key and adding it to the ssh-agent.
For a legacy system without Ed25519 support, GitHub documents this RSA command:
Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
ssh-keygen -t rsa -b 4096
Protect the private key with a passphrase
Set a passphrase when you create the key. It adds protection if someone gains access to the computer holding the private key; GitHub describes it as an extra layer of security. GitHub’s passphrase guide also explains how to change the passphrase on an existing key without generating a replacement:
ssh-keygen -p -f ~/.ssh/id_ed25519
Replace the path with the actual private-key filename if yours differs. The passphrase protects the private key; an agent does not replace that protection.
Use ssh-agent when repeated passphrase entry is inconvenient
An SSH agent can hold an unlocked key for use by SSH clients, reducing repeated passphrase prompts. The steps to start and configure it depend on the operating system and SSH binary, so follow the matching platform section rather than assuming one startup command works everywhere.
- macOS: GitHub documents options for integrating with Apple’s Keychain tools.
- Windows: GitHub’s guide covers the Windows OpenSSH service. Git for Windows may instead use its bundled
ssh.exe, which can fail to communicate with keys held by the Windows OpenSSH agent. The guide describes configuring Git to use the system SSH binary. - Other Unix-like systems: Follow the agent startup and key-addition steps for the shell and SSH client in use.
See the platform-specific instructions in GitHub’s SSH key and agent guide.
Rank #4
Register the public key and test access
- Find the public-key file. It has a
.pubextension and corresponds to the private key you generated. - Add that public key to the target service. For GitHub, use its account instructions for adding a new SSH key. Never paste the private-key file into an account form.
- Test using the service’s current procedure. Authentication behavior and test instructions differ by service, so use its own guidance and confirm it recognizes the intended account or server.
- Record the key’s purpose. Note which machine and service it belongs to, so you can identify it during later reviews.
Choose between a software-held and hardware-backed key
For a conventional key pair, the private key is stored on the computer and protected with a passphrase. A hardware-backed OpenSSH security key involves a physical security device during authentication. GitHub documents the ed25519-sk type and ecdsa-sk as an alternative when the hardware does not support Ed25519. The device must be connected when authenticating. Compatibility depends on the security key, OpenSSH build, operating system, and target service; verify support before relying on this route. GitHub’s overview of SSH describes its supported key approaches.
Review, identify, and remove keys over time
Review the SSH keys associated with your account and remove keys that are compromised, unrecognized, invalid, or no longer trusted. A SHA-256 fingerprint helps identify a key without revealing its private contents. To list fingerprints for keys available through the agent, run:
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
ssh-add -l -E sha256
Compare the local fingerprint with the key shown on the hosting account. GitHub’s key review guidance explains its account audit process.
Troubleshoot a key that is not being accepted
- Check which SSH program is running. In particular, determine whether Git is using the Windows system OpenSSH binary or Git for Windows’ bundled binary.
- Check the active agent. Confirm the agent used by the client has the intended key loaded; a mismatch between SSH binary and agent can make an otherwise valid key unavailable.
- Compare identities. Match the local public key or SHA-256 fingerprint to the key registered with the target account.
- Verify service-specific requirements. Confirm that the service accepts the key algorithm and follow its current test and connection instructions.
These checks distinguish a registration mismatch from a local agent or client configuration problem. GitHub’s platform setup guide covers its Windows, macOS, and Unix-like agent flows.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

