Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To set up SSH key authentication on your Mac, create a key pair, add the private key to macOS’s SSH agent and Keychain, then authorize the matching public key with the remote account or service. The private key stays on your Mac; a key passphrase protects it locally and is not the same as the remote account password. This is for connecting from your Mac. Letting other computers connect to your Mac is a separate setting.

What SSH keys do—and what they do not do

SSH key authentication uses a private key on your Mac and a matching public key registered with the account or service you want to access. Creating the pair is only the client-side step; until the destination authorizes the public key, it will not grant access.

For routine SSH access, a key pair avoids repeatedly authenticating with a reusable remote-account password. Protect the private key with a strong passphrase. The passphrase unlocks the local key; it is not sent as the remote account password. Keys do not make a compromised Mac or an unprotected, stolen private key safe. You may also still need password-based recovery or another sign-in method.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do I create an SSH key on a Mac?

1. Check for an existing key before making one

Open Terminal and inspect the SSH directory:

ls -la ~/.ssh

If you already have a working key for this destination, do not replace it. If the default key file exists, either verify it is the key you intend to use or select a different filename when generating a new pair. Overwriting a working key can interrupt access to services that still depend on it.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

2. Generate an Ed25519 key pair

For a new key, run the following command, replacing the example email with an identifying address:

ssh-keygen -t ed25519 -C "your_email@example.com"

When prompted for a file location, accept the default only if it will not overwrite an existing key. Otherwise enter a distinct path, such as /Users/yourname/.ssh/id_ed25519_work. Choose a strong passphrase when prompted. GitHub’s instructions document this Ed25519 workflow and passphrase prompt in its SSH key setup guide; other services may have their own accepted key types or policies.

The private key is the file without the .pub suffix. Keep it on your Mac and never paste or upload it where a public key is requested. The corresponding .pub file is the public key to register with the destination.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How do I add my SSH key to the ssh-agent on macOS?

The SSH agent can manage an unlocked key, and macOS Keychain can retain its passphrase. For the default Ed25519 filename, GitHub documents this command:

ssh-add --apple-use-keychain ~/.ssh/id_ed25519

If you chose a different filename, substitute that path. GitHub’s macOS-specific setup also uses a host entry in ~/.ssh/config. Create or edit that file and adapt the host and key path for your destination:

Host github.com
  AddKeysToAgent yes
  UseKeychain yes
  IdentityFile ~/.ssh/id_ed25519

The example applies to GitHub. For another service, replace github.com with its actual host and set IdentityFile to your chosen private-key path; do not copy the host entry unchanged. GitHub provides the full macOS agent and Keychain instructions.

Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Authorize the public key and test the connection

Register only the public key

Copy the contents of the matching .pub file into the destination’s SSH-key mechanism. A code-hosting account typically provides an SSH keys page. On a server, the administrator or provider must authorize the key for the intended user, commonly through that user’s authorized_keys file. The exact procedure varies by destination, so follow its instructions rather than assuming there is one universal installation command.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Connect as the intended remote user

Use the destination’s normal SSH command, for example:

ssh username@hostname

If SSH still asks for the remote account password, check that the public key was registered for the same remote user you are connecting as, that your Mac is offering the matching private key, and that the server permits key authentication. Apple documents the ssh username@hostname form for connecting to a Mac in its Remote Login guide.

Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Do not disable password authentication on a server unless you administer it and have confirmed a separate key-based login works, with a recovery path available. A failed change can lock you out, and server-side policy is not controlled by creating a key on your Mac.

How do I enable Remote Login on a Mac?

Remote Login allows other computers to connect into your Mac. It is separate from using your Mac as an SSH client, and turning it on does not automatically add a public key or disable password authentication.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. On the Mac, open Apple menu → System Settings → General → Sharing.
  2. Select the info button beside Remote Login.
  3. Turn on Remote Login.
  4. Under Allow access for, choose Only these users and add only the accounts that need access, when practical.

Apple Support warns: “Allowing remote login to your Mac can make it less secure.” Its Remote Login instructions show the setting and the SSH command to use from the other computer. The guide illustrates password login; it does not provide a complete key-only server configuration. Do not enable full disk access for remote users unless the task specifically requires it.

Best Value
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When to consider a FIDO2 hardware-backed SSH key

A FIDO2 security key is an optional, more advanced alternative to a standard file-based Ed25519 key. Yubico documents SSH support for the YubiKey 5 Series and says FIDO2 SSH requires OpenSSH 8.2 or later. It also states that the OpenSSH bundled with macOS lacks FIDO support; using this route therefore requires a compatible OpenSSH installation and ensuring it is the one your shell runs.

Consideration File-based Ed25519 key FIDO2 hardware-backed key
Compatibility GitHub documents this standard setup for macOS. Requires OpenSSH 8.2 or later with FIDO support; macOS’s bundled OpenSSH lacks that support, according to Yubico.
What you use A private-key file stored on the Mac, protected by a passphrase. A compatible hardware security key must be available when authenticating.
Setup Generate the key, configure the agent, and register the public key. More involved: install and use a compatible OpenSSH build as well as configure the FIDO key.
Recovery if lost Recovery depends on your key backup and the destination’s account recovery options; the sources do not establish a universal recovery standard. Recovery depends on whether you registered a backup key or have another access method; the sources do not establish a universal recovery standard.

Yubico’s SSH documentation describes the product and OpenSSH requirements. This hardware route is not necessary for the ordinary Ed25519 setup.

What about FIPS requirements?

Apple documents that OpenSSH can be configured to use FIPS 140-3 validated modules for select algorithms. That is specialized compliance guidance for organizations with explicit requirements, not a general consumer security upgrade. See Apple’s macOS security certifications documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.