Every repository has two clone URLs, https://github.com/OWNER/REPO.git 29 and git@github.com:OWNER/REPO.git. For a public repository, HTTPS reads anonymously, while SSH always authenticates, even to read:
git ls-remote https://github.com/cli/cli.git HEAD | cut -f1
git ls-remote git@github.com:cli/cli.git HEAD9b031151a825bda919203c5202876a725d637368 git@github.com: Permission denied (publickey). fatal: Could not read from remote repository. ...
HTTPS uses port 443 and a token or OAuth sign-in supplied by a credential helper; SSH uses port 22 and a key in ssh-agent. HTTPS with a fine-grained token is the more precise choice: the token can be limited to one repository and expires, while an SSH key opens every repository the account can push to until you delete it. SSH is convenient where no credential helper is available. If a firewall blocks port 22, set Hostname ssh.github.com and Port 443 for Host github.com in ~/.ssh/config. Switch an existing clone with git remote set-url (Managing Remotes).