Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteUse ssh-agent to keep a passphrase-protected SSH key available to your local SSH client for a session, so you do not have to enter its passphrase for every connection. The agent holds the key identity locally and makes it available through a Unix-domain socket; it does not send your private key or passphrase to the remote server.
How ssh-agent works
ssh-agent holds private-key identities used for public-key authentication. When you add a key, ssh-add makes it available to the agent; your SSH client finds the agent through environment variables, especially SSH_AUTH_SOCK. The agent performs authentication operations without handing the private key itself to the remote host. See the OpenBSD ssh-agent(1) manual.
Starting an agent and making its environment available are separate steps. For the usual interactive-shell setup, evaluate the startup command’s output in the same shell where you will run ssh-add and ssh.
How do I start ssh-agent in Linux?
For sh, bash, zsh, and other Bourne-style shells
Run:
eval "$(ssh-agent -s)"
This starts the agent and evaluates the environment assignments it prints in the current shell. Commands launched from that shell can then locate the agent through SSH_AUTH_SOCK.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
For csh-style shells
Use the csh output format:
eval `ssh-agent -c`
The shell syntax matters: use -s with Bourne-style shells and -c with csh-style shells.
Run one command under an agent
OpenSSH also supports starting a command as a child of an agent, such as ssh-agent command. The command receives the agent environment, and the agent exits when that command ends. This scopes the agent to that command rather than leaving a separately managed agent running for the shell session. See the ssh-agent(1) manual for the installed version’s syntax and options.
How do I add and manage an SSH key?
Add a key and verify it is loaded
-
Start the agent in your current shell using the command for your shell above.
-
Add the key you want to use. For example:
ssh-add ~/.ssh/id_ed25519. If the key is passphrase-protected, enter its passphrase when prompted.Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
-
List identities held by the agent with
ssh-add -l. -
Connect as usual, for example with
ssh user@host. The SSH client can use the loaded identity for public-key authentication.
To remove every identity from the agent, run ssh-add -D. If you omit a filename when adding a key, ssh-add tries identity filenames supported by that installed OpenSSH version. The current OpenBSD manual lists RSA, ECDSA, Ed25519, security-key variants, and an ML-DSA/Ed25519 hybrid filename; older Linux or Unix installations may not recognize every newer filename. See OpenBSD ssh-add(1) and check man ssh-add locally.
Limit how long an identity stays available
To give identities added to a newly launched agent a default lifetime, use an option such as:
ssh-agent -t 1h
To set a lifetime for a particular identity, use:
ssh-add -t 1h ~/.ssh/id_ed25519
A per-identity lifetime overrides the agent’s default. Without a configured lifetime, the current ssh-agent(1) and ssh-add(1) manuals say identities do not expire automatically. The example lifetime is one hour; choose a duration appropriate to your session and risk tolerance.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Why does ssh-add say it cannot connect to the agent?
The message Could not open a connection to your authentication agent usually means ssh-add cannot reach the socket named by SSH_AUTH_SOCK. The agent must be running and the variable must point to its socket. Check these items:
-
Run the appropriate startup command and evaluate its output in the exact shell where you are running
ssh-add. -
Check whether
SSH_AUTH_SOCKis set:printf '%sn' "$SSH_AUTH_SOCK". -
Make sure the socket path still exists and belongs to the active agent session. A different terminal may have a different environment or a stale socket path.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
If the agent was started in another shell, start or connect to an agent in this shell using the environment provided for that agent; do not assume environment variables transfer between terminals.
If ssh-add rejects a key rather than failing to connect, verify the path and file permissions. The current ssh-add(1) manual says identity files should not be readable by anyone but the user and that ssh-add ignores identity files accessible by others.
The socket is normally accessible to the current user, but it is security-sensitive: root or another process running as the same user may be able to use it. Treat access to your account and its agent socket accordingly.
What if SSH offers too many keys?
An agent can hold multiple identities, and SSH may try them when authenticating. If a server rejects authentication after too many attempts, clear the agent and load only the identity you need:
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
ssh-add -D
ssh-add ~/.ssh/id_ed25519
You can also specify a key explicitly for a connection, for example ssh -i ~/.ssh/id_ed25519 user@host. The available identity-selection behavior can vary with client configuration; consult man ssh on your system.
How can I use ssh-agent when connecting through a jump host?
If you only need a jump host to reach a destination, use OpenSSH’s jump-host option:
ssh -J jump-host user@destination
This connects through the intermediate host without enabling agent forwarding to it. Agent forwarding is a separate feature: ssh -A host makes access to your agent available on the remote host, while ssh -a host disables forwarding.
Forwarding does not copy the private key or its passphrase to the remote machine. However, someone who can access the forwarded socket can ask the agent to perform authentication operations with loaded identities, potentially authenticating onward as you. Use forwarding only when the remote workflow requires it, and do not treat the absence of private-key files on the remote host as proof that forwarding is harmless. The OpenBSD ssh(1) manual documents forwarding behavior.
For workflows that require forwarding but should be limited to specific routes, ssh-add -h can apply destination constraints. OpenSSH introduced destination constraints in release 8.9; they require support from the participating client and server, so availability depends on the versions in use. Check ssh-add(1) and your local manuals before relying on them.
Why might agent forwarding be unavailable?
The client can disable forwarding with -a or its SSH configuration, and the server can restrict it through AllowAgentForwarding in sshd_config. The current OpenBSD sshd_config(5) manual documents a default of yes, but Linux distributions and managed servers may use different settings. The same manual cautions that disabling this option alone is not a meaningful security boundary when users still have shell access and can install other forwarders.
Check your installed OpenSSH version
The cited manuals are current OpenBSD documentation, which may describe options newer than those available in a Linux or Unix package. If an option is unrecognized or behaves differently, check the local versions with man ssh-agent, man ssh-add, and man ssh. Use the documentation for the software installed on the client and, for server-side forwarding policy, the server.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

