An SSH key pair is a private key that never leaves your machine and a public key you give GitHub 29 . Generate an Ed25519 key with a passphrase, then load it into ssh-agent so you type the passphrase once per session:
mkdir -m 700 -p ~/.ssh
ssh-keygen -t ed25519 -C "sam@example.com" -f ~/.ssh/id_ed25519_github
eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_ed25519_githubGenerating public/private ed25519 key pair. Enter passphrase for "/home/dev/.ssh/id_ed25519_github" (empty for no passphrase): ... The key fingerprint is: SHA256:mGQH6bx5Oy1REdBpUlie5Ps0Bq98/dx8wXdFXC0jukI sam@example.com ... Agent pid 492602 Enter passphrase for /home/dev/.ssh/id_ed25519_github: Identity added: /home/dev/.ssh/id_ed25519_github (sam@example.com)
Next, give GitHub the public half, check that the server you reach is really GitHub, and test the login:
gh ssh-key add ~/.ssh/id_ed25519_github.pub --title "Sam's WSL laptop" --type authentication
ssh-keyscan -t ed25519 github.com 2>/dev/null >> ~/.ssh/known_hosts
ssh-keygen -lf ~/.ssh/known_hosts
ssh -T git@github.comHTTP 403: Resource not accessible by personal access token (https://api.github.com/user/keys?per_page=100) 256 SHA256:+DiY3wvvV6TuJJhbpZisF/zLDA0zPMSvHdkr4UvCOqU github.com (ED25519) git@github.com: Permission denied (publickey).
Uploading through the API needs the account permission "Git 1,932 SSH keys: write", which this book's fine-grained token does not have. So add the key in the browser, as GitHub's documentation describes: Settings, SSH and GPG keys, New SSH key; enter a title, choose Authentication Key (a Signing Key only signs commits, SSH Signing), paste the one-line contents of id_ed25519_github.pub, and click Add SSH key. The host key fingerprint matches the Ed25519 value GitHub publishes on docs.github.com, so the connection is genuine; the denial only means the key is not registered yet. Once it is, ssh -T greets you with Hi binarybehemoth! You've successfully authenticated. For a non-default file name, add IdentityFile ~/.ssh/id_ed25519_github under Host github.com in ~/.ssh/config. Use one key per machine.