SSH keys are a safer, easier way to log in to your VPS than a password. You create a pair of keys on your computer. The private key stays on your computer, and the public key goes on your server. Only someone with your private key can log in, and you don't have to type a password each time.
Once keys are working, you can turn off password logins completely, which stops password-guessing attacks against your server.
Before you start
You'll need to be able to log in to your VPS with your password. See Connect from Windows or Connect from macOS or Linux.
Step 1: Create a key pair on your computer
On Windows (Windows Terminal or PowerShell), macOS or Linux (Terminal), run this on your own computer, not the server:
ssh-keygen -t ed25519
- Press Enter to save the key in the default location.
- When asked for a passphrase, we recommend entering one. It protects your key if your computer is ever lost or stolen. You can press Enter to skip it.
This creates two files in the .ssh folder in your home folder: id_ed25519 (your private key, never share it) and id_ed25519.pub (your public key).
Step 2: Copy your public key to the server
macOS or Linux:
ssh-copy-id root@YOUR_SERVER_IP
Windows (PowerShell or Windows Terminal):
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh root@YOUR_SERVER_IP "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"
Enter your root password when asked. This is the last time you'll need it.
Step 3: Test your key
ssh root@YOUR_SERVER_IP
You should be logged straight in, or asked only for your key's passphrase, not your server password. If you're still asked for the server password, check Step 2 before going any further.
Using PuTTY instead?
- Open PuTTYgen (installed with PuTTY), choose EdDSA (Ed25519) and click Generate. Move your mouse around the blank area until it finishes.
- Enter a passphrase if you'd like one, then click Save private key and keep the
.ppkfile somewhere safe. - Copy the text in the box labelled Public key for pasting into OpenSSH authorized_keys file.
- Log in to your server with your password and run the following, pasting your key between the quotes:
mkdir -p ~/.ssh && chmod 700 ~/.ssh echo "PASTE_YOUR_PUBLIC_KEY_HERE" >> ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys - In PuTTY, load your saved session, go to Connection → SSH → Auth → Credentials, and choose your
.ppkfile under Private key file for authentication. Go back to Session, click Save, then Open.
Step 4 (recommended): Turn off password logins
Only do this once you've confirmed you can log in with your key. Keep your current SSH window open while you make the change, so you can undo it if something goes wrong.
Ubuntu, Debian, AlmaLinux 9 and 10, and Rocky Linux 9 and 10:
echo -e "PasswordAuthentication no\nKbdInteractiveAuthentication no" | sudo tee /etc/ssh/sshd_config.d/01-disable-passwords.conf
AlmaLinux 8: open /etc/ssh/sshd_config with sudo nano /etc/ssh/sshd_config, find the line PasswordAuthentication yes, change it to PasswordAuthentication no, and save.
Check the configuration is valid, then restart SSH:
sudo sshd -t
sudo systemctl restart ssh 2>/dev/null || sudo systemctl restart sshd
Now open a new terminal window and check you can still log in with your key. Once it works, you can close the old window.
Keep your keys safe
- Never share your private key or send it to anyone, including us.
- Back up your private key somewhere safe. If you lose it after turning off passwords, you can still log in through Open Console on your VPS's management page in the client area.
- To use several computers, create a key on each one and add each public key to
~/.ssh/authorized_keyson the server, one per line.
Troubleshooting
- Still asked for the server password: check that
~/.ssh/authorized_keyson the server contains your public key on a single line, and that the permissions are correct:chmod 700 ~/.sshandchmod 600 ~/.ssh/authorized_keys. - "Permission denied (publickey)" after turning off passwords: your key isn't being offered or accepted. Log in through Open Console on your VPS's management page, delete
/etc/ssh/sshd_config.d/01-disable-passwords.conf(or setPasswordAuthentication yesagain on AlmaLinux 8), restart SSH, and try again. - PuTTY says the key format isn't supported: PuTTY needs a
.ppkfile. Open your key in PuTTYgen and save it as a private key.
Related guides
Need help?
Our Cloud VPS plans are self-managed, so you're responsible for installing, securing and maintaining the software on your server. If something on our side isn't working, such as the network, or your VPS won't boot, open a support ticket.







