CH.15 · PART 3

Your key.
Your access.

Connect with SSH without exposing secrets. Public keys travel; private keys stay with you.

LOCALSHAREDCheck where the work goes.

Two keys. Only one is shared.

Public key

The .pub file. Add this to your GitHub account so GitHub can recognize your key.

Private key

Keep this on your computer. Never paste it into GitHub, chat, a repository or a screenshot.

Passphrase

Protects the key file. It is not your GitHub password. Use a strong one and store it safely.

Check before you create

Look for existing SSH keys using your operating system's file browser or terminal. Do not overwrite a key you do not recognize. If you already have a suitable key, use the existing-key instructions in the official guide.

ssh-keygen -t ed25519 -C "YOUR_EMAIL"

YOUR_EMAIL is a placeholder label. Run this on your own computer. Choose a new filename if a key already exists, and enter a secure passphrase when prompted. The command is sourced from GitHub docs, not a transcript of a key created by this page.

Operating systems differ

Windows

Use Git Bash or the Windows OpenSSH setup described in GitHub's Windows tab. Keep the agent and SSH executable choice consistent.

macOS

Use the macOS instructions for ssh-agent and Keychain. GitHub's guide covers ssh-add --apple-use-keychain and the required SSH config. Do not copy those flags to Linux.

Linux

Use GitHub's Linux ssh-agent instructions, then add your chosen key file with ssh-add. Paths must match the filename you selected.

Use the official guide's OS tab linked below. This chapter deliberately avoids one-size-fits-all agent setup.

Add the public key to GitHub

  1. Open GitHub Settings, then SSH and GPG keys.
  2. Choose New SSH key.
  3. Give it a recognizable title, such as the device name.
  4. Choose Authentication Key for Git access.
  5. Paste the contents of the .pub file, not the private key.
  6. Add the key and complete any account verification.

Authentication and commit signing are different uses. Adding an authentication key does not make all your commits signed.

Spot the safe file

Which file is the public key?

Choose a filename.

Test without trusting blindly

ssh -T git@github.com

On the first connection, SSH may ask you to trust the host. Compare the fingerprint with GitHub's published fingerprints before accepting. The official test guide explains the expected response and why a successful authentication test can still exit with status 1.

The command above is a sourced example, not a test run for your account. We do not print invented authentication output. To use SSH for a repository, copy its SSH clone URL from GitHub's Code menu. If access fails, check account permissions and the key in use; do not share the private key to troubleshoot.

Sources

Generate a key and configure the agent · Add the public key · Test the SSH connection · GitHub SSH fingerprints

Git, Visually · Part 3 · English