What You Need
root on a new VPSIf you have not connected to your VPS yet, start with our How to Connect to a Linux VPS guide first, then come back here.
Step 1: Generate an SSH Key (If You Don't Have One)
An SSH key is actually two files: a private key that stays on your computer and a public key that you give to the server. Never share or upload the private key — only the .pub file.
Check if You Already Have a Key
Open a terminal on your local computer and run:
ls ~/.sshWindows PowerShell:
dir $env:USERPROFILE\.sshIf you see files like id_ed25519 and id_ed25519.pub (or id_rsa and id_rsa.pub), you already have a key — skip to Step 2. If the folder is empty or doesn't exist, generate one now:
ssh-keygen -t ed25519 -C "[email protected]"Press Enter to accept the default location, and either set a passphrase (recommended) or press Enter twice to leave it empty. You will now have two new files in ~/.ssh/: id_ed25519 (private) and id_ed25519.pub (public).
Step 2: Add the Key to Your VPS
You have three options below. Pick the one you are most comfortable with — they all do the same thing in the end: append your public key to ~/.ssh/authorized_keys on the server.
Method 1: ssh-copy-id (Easiest)
This is the recommended way on Mac and Linux. One command handles everything: creating the .ssh folder on the server, setting permissions, and appending the key.
ssh-copy-id [email protected]Enter your password when prompted. If your VPS uses a non-standard SSH port, add -p:
ssh-copy-id -p 2222 [email protected]That's it. Test it by running ssh [email protected] — you should be logged in without being asked for a password.
ssh-copy-id. Use Method 2 or Method 3 instead, or run the one-line equivalent:type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh [email protected] "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"Method 2: Upload the Key with SCP
SCP (Secure Copy) is the standard tool for moving files over SSH. It is useful if you want a clear, two-step process: first upload the public key to the server, then move it into place.
Step 1: Upload the Public Key
From your local terminal (not the VPS), run:
scp ~/.ssh/id_ed25519.pub [email protected]:/tmp/mykey.pubWindows PowerShell:
scp $env:USERPROFILE\.ssh\id_ed25519.pub [email protected]:/tmp/mykey.pubEnter your password when prompted. The file is now in /tmp/mykey.pub on the server.
Step 2: SSH In and Install the Key
Connect to the VPS and run these commands one at a time:
ssh [email protected]mkdir -p ~/.sshchmod 700 ~/.sshcat /tmp/mykey.pub >> ~/.ssh/authorized_keyschmod 600 ~/.ssh/authorized_keysrm /tmp/mykey.pubThe >> appends the key to the file (instead of overwriting), so this is safe to repeat for multiple keys. Type exit to disconnect, then run ssh [email protected] again — you should be in without a password.
-P (capital P) for the port, while SSH uses lowercase -p. This catches a lot of people out:scp -P 2222 ~/.ssh/id_ed25519.pub [email protected]:/tmp/mykey.pubMethod 3: Manual Placement (Full Control)
If you would rather see every byte of what is happening — or you only have access to the VPS through a web console (like our client area's noVNC console), this method works without needing SCP or ssh-copy-id.
Step 1: Get Your Public Key
On your local machine, display the contents of your public key:
cat ~/.ssh/id_ed25519.pubWindows PowerShell:
type $env:USERPROFILE\.ssh\id_ed25519.pubYou will see one long line that starts with ssh-ed25519 (or ssh-rsa) and ends with your email comment. Select and copy the entire line.
Step 2: Connect to Your VPS
Log into the VPS however you normally would — SSH with a password, or the web console in your hosting control panel.
Step 3: Create the .ssh Folder
On the server, run:
mkdir -p ~/.sshchmod 700 ~/.sshThe -p flag means "don't error if it already exists". The chmod 700 makes the folder readable only by you — SSH will refuse to use the folder if it has loose permissions.
Step 4: Open the authorized_keys File
Use nano (the friendliest editor for beginners):
nano ~/.ssh/authorized_keysIf the file doesn't exist yet, nano will create it. If it does exist, move the cursor to the bottom of the file (Ctrl + End on most systems, or use the arrow keys) so you don't overwrite existing keys.
Step 5: Paste Your Public Key
Right-click in the terminal window to paste (or Cmd + V on Mac Terminal, Ctrl + Shift + V in most Linux terminals). The whole key must be on one single line — do not let it wrap with line breaks. It should look like:
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAI...rest-of-key... [email protected]Step 6: Save and Exit
Press Ctrl + O then Enter to save, then Ctrl + X to exit nano.
Step 7: Set the Correct File Permissions
chmod 600 ~/.ssh/authorized_keysThis makes the file readable and writable only by you. SSH is strict about this — wrong permissions and it will silently ignore the file.
Step 8: Test It
Open a new terminal window on your local machine (keep the old session open just in case something is wrong) and run:
If you get logged in without a password prompt, it worked. If it still asks for a password, see the troubleshooting section below — do not close your original SSH session yet.
Disabling Password Login (Strongly Recommended)
Once your SSH key works, you should disable password authentication completely. This blocks the most common attack on Linux servers: someone trying millions of passwords against your root account.
Make sure your key works first by logging in fresh in a new terminal window. Then on the VPS, edit the SSH config:
nano /etc/ssh/sshd_configFind these lines (use Ctrl + W in nano to search) and change them:
PasswordAuthentication noPubkeyAuthentication yesPermitRootLogin prohibit-passwordSave with Ctrl + O, Enter, then Ctrl + X. Reload SSH so the changes take effect:
systemctl reload sshFrom now on, only people with a matching private key can log in. Brute-force attacks against your VPS become useless.
authorized_keys.Adding More Than One Key
You can have as many keys in authorized_keys as you want — one per line. To add a second computer or share access with a colleague, just append their public key to the file using any of the methods above. Each cat ... >> command adds a new line; nano lets you paste extra keys at the end. Removing access is just deleting that one line.
Troubleshooting
- Still being asked for a password — your key file permissions are probably wrong. On the VPS, run
chmod 700 ~/.sshandchmod 600 ~/.ssh/authorized_keys. SSH refuses to use the file if either is world-readable. - "Permission denied (publickey)" after disabling passwords — usually means the key was pasted with a line break, or you used the wrong key file on the client. Run
ssh -v root@your-ipfrom your local machine to see which key SSH is offering. - Key looks weird when you cat it — make sure you copied the
.pubfile, not the private key. The public key starts withssh-ed25519orssh-rsa. If your file starts with-----BEGIN OPENSSH PRIVATE KEY-----, stop — that's the private key and must never leave your machine. - SCP says "Permission denied" — you cannot scp directly into
/root/.ssh/as another user. Upload to/tmp/first, then move the file into place after logging in (as shown in Method 2). - Locked out after disabling password login — open your hosting control panel's web console (noVNC). Edit
/etc/ssh/sshd_configdirectly, setPasswordAuthentication yes, reload SSH, and try again.
Frequently Asked Questions
Next Steps
Now that you can log in with a key, consider setting up a non-root user with sudo, installing fail2ban for extra brute-force protection, and configuring an unattended-upgrades policy. Check our other hosting guides for more tutorials.
Get Your Own UK VPS
AMD Ryzen 9 VPS with full root access, DDoS protection, and instant deployment. From £1.50/mo.