What are SSH keys?
SSH is a safe way to control a remote computer by typing commands. An SSH key is a pair of files. One is the private key. You keep it secret on your computer, like the key to your house. The other is the public key. You place it on the server, like a lock that only your key can open. Keys are much harder to steal than passwords.

Step 1: Make the key pair on your computer
- Open a terminal on your own computer.
- Run:
ssh-keygen -t ed25519 -C "my key"
This creates a new key pair. If your system is very old and does not support this type, use ssh-keygen -t rsa -b 4096 instead.
- Press Enter to save in the default place.
- Type a passphrase when asked. A passphrase is a short password that protects the private key file. You can leave it empty, but a passphrase is safer.
Two files appear in the ~/.ssh folder: id_ed25519 (private) and id_ed25519.pub (public).
.pub.Step 2: Copy the public key to the server
- Run this, with your own user name and server address from your welcome email:
ssh-copy-id username@your_server_ip
This logs in with your password once and adds your public key to the server.
- If
ssh-copy-idis not available, copy by hand. First show the key:
cat ~/.ssh/id_ed25519.pub
This prints the public key. Copy the whole line.
- Log in to the server with your password.
- Run these commands:
mkdir -p ~/.ssh
chmod 700 ~/.ssh
nano ~/.ssh/authorized_keys
This makes the folder, protects it and opens the key list in an editor.
- Paste the key on a new line. Press Ctrl+O, Enter, then Ctrl+X to save.
- Set the file rules:
chmod 600 ~/.ssh/authorized_keys
This lets only you read and write the file.
Step 3: Test the login
ssh username@your_server_ip
You should enter without a server password. You may need the key passphrase.
Step 4: Turn off password login (optional)
- Open the SSH settings file:
sudo nano /etc/ssh/sshd_config
- Set
PasswordAuthentication no. - Restart SSH:
sudo systemctl restart ssh
This applies the new setting. If you need help, open a support ticket.
Quick recap
- A key pair has a private and a public part.
- Create it with
ssh-keygen. - Copy the public key with
ssh-copy-id. - Test before turning off passwords.