How to generate and use SSH keys on a Mac
By Lucas Russo, developer of SSHive · Updated
From no key at all to a server that refuses passwords, in about five minutes: an ed25519 key made in Terminal or in SSHive, installed on the server, then used by your profiles.
Password logins are exactly what the bots scanning port 22 try to guess, around the clock. A key pair replaces "something you know" with "something you have": the private half never leaves your Mac, the server only keeps the public half, and once it is in place you stop typing a password at every connection. This guide uses ed25519, the short and fast key type that every current OpenSSH server accepts. You can create the key in Terminal, as a file in ~/.ssh, or in SSHive, which keeps it encrypted and out of ~/.ssh. Both routes end in the same place, and neither needs Pro: password, key and agent sign-in work the same way in the free version of the SSH client.
Step-by-step
Create the key pair, in SSHive or in Terminal
In SSHive: Settings › SSH Keys › Generate a key. Give it a name you will recognise (prod-web, say), keep Ed25519, the type marked recommended (RSA 4096 and ECDSA are there for servers that refuse it), add a passphrase if you want one, and click Generate. The private key is encrypted with a key held by the macOS Keychain and is never written to~/.ssh. In Terminal:ssh-keygen -t ed25519 -C "you@example.com", Enter to accept~/.ssh/id_ed25519, then a passphrase. Take this route when other tools on the Mac, git or your scripts, need the key as a file.Put the public key on the server (the last password you type there)
Key made in SSHive: connect to the server once with its password, then in Settings › SSH Keys open Install on host next to the key and pick that session. SSHive appends the public key to~/.ssh/authorized_keysthrough the open connection, asssh-copy-idwould, and tells you if it was already there. Copy public key is next to it if you would rather paste it yourself. Key file made in Terminal:ssh-copy-id -i ~/.ssh/id_ed25519.pub user@host, then the password one last time.Point the profile at the key
Open the profile (right-click › Edit, or + for a new one). Under Authentication pick Private Key, and an SSH Key menu appears. A key made in SSHive is listed under Managed keys (Keys tab), and its passphrase is looked up for you. For a file, leave Local file…, click Browse and select~/.ssh/id_ed25519: a green ✓ means SSHive can read it, an orange ⚠ means macOS wants you to pick the same file again to grant access. Tick Key protected by a passphrase if it has one and type it once. Already haveIdentityFilelines in~/.ssh/config? Importing that file fills this in for every host.What SSHive keeps, and where
A key file you pick stays in~/.ssh: SSHive records its path and the macOS permission to read it, nothing more. Keys generated in SSHive, passphrases and saved passwords are encrypted on your Mac with a key that the macOS Keychain holds. Touch ID is optional: Require Touch ID before decrypting passwords is a switch in Settings, off by default.Switch off password logins on the server
Once SSHive connects with the key, harden the server: in/etc/ssh/sshd_configsetPasswordAuthentication no, then reload sshd (sudo systemctl reload sshon Debian and Ubuntu). Keep that session open and try a new connection before you log out: if the key is refused, you still have a way in. From then on nothing on that server accepts a password, and the bots on port 22 have nothing left to guess.
Frequently asked questions
Should I use RSA, ECDSA or ed25519?+
Where are my SSH keys stored on macOS?+
ssh-keygen are files in ~/.ssh/; add one with ssh-add --apple-use-keychain and macOS keeps its passphrase in the Keychain. Keys generated in SSHive are not files: SSHive stores them encrypted and shows their public half in Settings › SSH Keys. Back up key files yourself: losing the only copy of a private key locks you out of every server that trusted it.Can one key serve several servers?+
Related SSHive features
SSH Terminal
GPU-accelerated terminal
Try SSHive Free for macOS
Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.
Download SSHive Free