SSH Keys

Generating and Adding an SSH Key

An SSH key pair is a private key that never leaves your machine and a public key you give GitHub 29 . Generate an Ed25519 key with a passphrase, then load it into ssh-agent so you type the passphrase once per session:

Generating an Ed25519 key and loading it into ssh-agentShell
mkdir -m 700 -p ~/.ssh
ssh-keygen -t ed25519 -C "sam@example.com" -f ~/.ssh/id_ed25519_github
eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_ed25519_github
Output
Generating public/private ed25519 key pair.
Enter passphrase for "/home/dev/.ssh/id_ed25519_github" (empty for no passphrase):
...
The key fingerprint is:
SHA256:mGQH6bx5Oy1REdBpUlie5Ps0Bq98/dx8wXdFXC0jukI sam@example.com
...
Agent pid 492602
Enter passphrase for /home/dev/.ssh/id_ed25519_github:
Identity added: /home/dev/.ssh/id_ed25519_github (sam@example.com)

Next, give GitHub the public half, check that the server you reach is really GitHub, and test the login:

Uploading the key with gh, verifying GitHub's host key, testing SSHShell
gh ssh-key add ~/.ssh/id_ed25519_github.pub --title "Sam's WSL laptop" --type authentication
ssh-keyscan -t ed25519 github.com 2>/dev/null >> ~/.ssh/known_hosts
ssh-keygen -lf ~/.ssh/known_hosts
ssh -T git@github.com
Output
HTTP 403: Resource not accessible by personal access token
(https://api.github.com/user/keys?per_page=100)
256 SHA256:+DiY3wvvV6TuJJhbpZisF/zLDA0zPMSvHdkr4UvCOqU github.com (ED25519)
git@github.com: Permission denied (publickey).

Uploading through the API needs the account permission "Git 1,932 SSH keys: write", which this book's fine-grained token does not have. So add the key in the browser, as GitHub's documentation describes: Settings, SSH and GPG keys, New SSH key; enter a title, choose Authentication Key (a Signing Key only signs commits, SSH Signing), paste the one-line contents of id_ed25519_github.pub, and click Add SSH key. The host key fingerprint matches the Ed25519 value GitHub publishes on docs.github.com, so the connection is genuine; the denial only means the key is not registered yet. Once it is, ssh -T greets you with Hi binarybehemoth! You've successfully authenticated. For a non-default file name, add IdentityFile ~/.ssh/id_ed25519_github under Host github.com in ~/.ssh/config. Use one key per machine.