1. Home
  2. ›
  3. Guides
  4. ›
  5. How to Add an SSH Key to a VPS

How to Add an SSH Key to a VPS (Beginner Guide)

Adding an SSH key to your VPS lets you log in without typing a password and protects your server against the brute-force attacks that pound every public SSH port. This guide walks you through three ways to do it: the one-command ssh-copy-id method, uploading the key with SCP, and placing it on the server manually if you prefer to see every step. Works for Linux, Mac, and Windows.

What You Need

A working VPS
You can already log in with a password
Your VPS IP
From your welcome email or control panel
Username
Usually root on a new VPS
A local terminal
Terminal (Mac), PowerShell (Windows 10/11), or any Linux shell

If you have not connected to your VPS yet, start with our How to Connect to a Linux VPS guide first, then come back here.

Step 1: Generate an SSH Key (If You Don't Have One)

An SSH key is actually two files: a private key that stays on your computer and a public key that you give to the server. Never share or upload the private key — only the .pub file.

Check if You Already Have a Key

Open a terminal on your local computer and run:

Mac / Linux: ls ~/.ssh
Windows PowerShell: dir $env:USERPROFILE\.ssh

If you see files like id_ed25519 and id_ed25519.pub (or id_rsa and id_rsa.pub), you already have a key — skip to Step 2. If the folder is empty or doesn't exist, generate one now:

ssh-keygen -t ed25519 -C "[email protected]"

Press Enter to accept the default location, and either set a passphrase (recommended) or press Enter twice to leave it empty. You will now have two new files in ~/.ssh/: id_ed25519 (private) and id_ed25519.pub (public).

Why ed25519? ed25519 keys are smaller, faster, and more secure than older RSA keys. Use them unless you have a specific reason to use RSA.

Step 2: Add the Key to Your VPS

You have three options below. Pick the one you are most comfortable with — they all do the same thing in the end: append your public key to ~/.ssh/authorized_keys on the server.

Method 1: ssh-copy-id (Easiest)

This is the recommended way on Mac and Linux. One command handles everything: creating the .ssh folder on the server, setting permissions, and appending the key.

ssh-copy-id [email protected]

Enter your password when prompted. If your VPS uses a non-standard SSH port, add -p:

ssh-copy-id -p 2222 [email protected]

That's it. Test it by running ssh [email protected] — you should be logged in without being asked for a password.

Windows note: PowerShell on Windows does not ship with ssh-copy-id. Use Method 2 or Method 3 instead, or run the one-line equivalent:

type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh [email protected] "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"

Method 2: Upload the Key with SCP

SCP (Secure Copy) is the standard tool for moving files over SSH. It is useful if you want a clear, two-step process: first upload the public key to the server, then move it into place.

Step 1: Upload the Public Key

From your local terminal (not the VPS), run:

Mac / Linux: scp ~/.ssh/id_ed25519.pub [email protected]:/tmp/mykey.pub
Windows PowerShell: scp $env:USERPROFILE\.ssh\id_ed25519.pub [email protected]:/tmp/mykey.pub

Enter your password when prompted. The file is now in /tmp/mykey.pub on the server.

Step 2: SSH In and Install the Key

Connect to the VPS and run these commands one at a time:

ssh [email protected]
mkdir -p ~/.ssh
chmod 700 ~/.ssh
cat /tmp/mykey.pub >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys
rm /tmp/mykey.pub

The >> appends the key to the file (instead of overwriting), so this is safe to repeat for multiple keys. Type exit to disconnect, then run ssh [email protected] again — you should be in without a password.

Non-standard port? SCP uses -P (capital P) for the port, while SSH uses lowercase -p. This catches a lot of people out:

scp -P 2222 ~/.ssh/id_ed25519.pub [email protected]:/tmp/mykey.pub

Method 3: Manual Placement (Full Control)

If you would rather see every byte of what is happening — or you only have access to the VPS through a web console (like our client area's noVNC console), this method works without needing SCP or ssh-copy-id.

Step 1: Get Your Public Key

On your local machine, display the contents of your public key:

Mac / Linux: cat ~/.ssh/id_ed25519.pub
Windows PowerShell: type $env:USERPROFILE\.ssh\id_ed25519.pub

You will see one long line that starts with ssh-ed25519 (or ssh-rsa) and ends with your email comment. Select and copy the entire line.

Step 2: Connect to Your VPS

Log into the VPS however you normally would — SSH with a password, or the web console in your hosting control panel.

Step 3: Create the .ssh Folder

On the server, run:

mkdir -p ~/.ssh
chmod 700 ~/.ssh

The -p flag means "don't error if it already exists". The chmod 700 makes the folder readable only by you — SSH will refuse to use the folder if it has loose permissions.

Step 4: Open the authorized_keys File

Use nano (the friendliest editor for beginners):

nano ~/.ssh/authorized_keys

If the file doesn't exist yet, nano will create it. If it does exist, move the cursor to the bottom of the file (Ctrl + End on most systems, or use the arrow keys) so you don't overwrite existing keys.

Step 5: Paste Your Public Key

Right-click in the terminal window to paste (or Cmd + V on Mac Terminal, Ctrl + Shift + V in most Linux terminals). The whole key must be on one single line — do not let it wrap with line breaks. It should look like:

ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAI...rest-of-key... [email protected]

Step 6: Save and Exit

Press Ctrl + O then Enter to save, then Ctrl + X to exit nano.

Step 7: Set the Correct File Permissions

chmod 600 ~/.ssh/authorized_keys

This makes the file readable and writable only by you. SSH is strict about this — wrong permissions and it will silently ignore the file.

Step 8: Test It

Open a new terminal window on your local machine (keep the old session open just in case something is wrong) and run:

ssh [email protected]

If you get logged in without a password prompt, it worked. If it still asks for a password, see the troubleshooting section below — do not close your original SSH session yet.

Disabling Password Login (Strongly Recommended)

Once your SSH key works, you should disable password authentication completely. This blocks the most common attack on Linux servers: someone trying millions of passwords against your root account.

Make sure your key works first by logging in fresh in a new terminal window. Then on the VPS, edit the SSH config:

nano /etc/ssh/sshd_config

Find these lines (use Ctrl + W in nano to search) and change them:

PasswordAuthentication no
PubkeyAuthentication yes
PermitRootLogin prohibit-password

Save with Ctrl + O, Enter, then Ctrl + X. Reload SSH so the changes take effect:

systemctl reload ssh

From now on, only people with a matching private key can log in. Brute-force attacks against your VPS become useless.

Keep your private key safe. Once password login is off, losing your private key means losing access to the VPS. Back it up somewhere safe (a password manager works well), and if you have multiple computers, add a key from each one to authorized_keys.

Adding More Than One Key

You can have as many keys in authorized_keys as you want — one per line. To add a second computer or share access with a colleague, just append their public key to the file using any of the methods above. Each cat ... >> command adds a new line; nano lets you paste extra keys at the end. Removing access is just deleting that one line.

Troubleshooting

Frequently Asked Questions

SSH keys are far more secure than passwords. They cannot be brute-forced, they are not vulnerable to phishing, and they let you log in without typing a password every time. Once set up, they are also faster and more convenient.
The private key stays on your local computer and must never be shared. The public key (ending in .pub) is the one you upload to your VPS. The two are mathematically linked, so the server can verify your identity without ever seeing the private key.
Inside the user's home directory at ~/.ssh/authorized_keys. Each line in that file is one allowed public key. The .ssh folder must be chmod 700 and the authorized_keys file must be chmod 600 or SSH will refuse to use them.
Yes. Each public key is one line in authorized_keys. Append additional keys to the file (do not overwrite) and every matching private key will be able to log in.
Yes, once you have confirmed the key works. Edit /etc/ssh/sshd_config and set PasswordAuthentication no, then restart SSH. This blocks the most common attack against VPS servers — brute-forced passwords.

Next Steps

Now that you can log in with a key, consider setting up a non-root user with sudo, installing fail2ban for extra brute-force protection, and configuring an unattended-upgrades policy. Check our other hosting guides for more tutorials.

Get Your Own UK VPS

AMD Ryzen 9 VPS with full root access, DDoS protection, and instant deployment. From £1.50/mo.

View VPS Plans → Learn More
← Back to Guides