# Adding and Managing SSH Keys

Source: https://support.kapsulehost.com/en-us/cloud-servers-ssh-keys

An SSH key lets you sign in to your server without a password. It is safer than a password and quicker to use. This guide covers creating a key, adding it to your account before you order, and removing keys you no longer use.

## How SSH Keys Work

An SSH key comes in two halves:

- The **private key** stays on your own computer. Never paste it anywhere or share it.
- The **public key** is the half you give to servers. It is safe to share.

When you connect, your computer proves it holds the private key that matches a public key on the server. No password is sent.

## Creating a Key

Create the key on your own computer, not on the server. On macOS, Linux or Windows (in PowerShell or Windows Terminal), run:

```
ssh-keygen -t ed25519 -C "you@example.com"
```

Press Enter to accept the default place to save it, then set a passphrase when asked. You now have two files:

- `~/.ssh/id_ed25519` is your private key.
- `~/.ssh/id_ed25519.pub` is your public key.

To see your public key, run:

```
cat ~/.ssh/id_ed25519.pub
```

Copy the whole line, starting with `ssh-ed25519`.

> **Warning:** Only ever copy the file that ends in `.pub`. The other file is your private key, and anyone who has it can sign in to every server that trusts it. If you share it by mistake, create a new key and replace the old one everywhere.

## Your Account's SSH Keys

SSH keys belong to your account, not to one server. Every new server is ordered with a key, and at launch that is how you sign in. Add your keys on the **SSH Keys** page in the sidebar, next to the server sections. The page works before you have any server, so you can add a key first and then order. The same list is on the **SSH Keys** tab of every server.

To add a key:

1. In the sidebar, click **SSH Keys**, or open any server and click **SSH Keys** in its menu.
2. Click **Add SSH Key**.
3. Type a **Name**, for example "My Laptop", and paste the whole line from your `.pub` file into **Public key**.
4. Click **Add Key**. KPanel says the key was added.

![The SSH Keys tab on a server in KPanel](https://support.kapsulehost.com/help/screenshots/cloud-servers-ssh-keys.2f07b4bd.webp)

Ed25519 keys are recommended. RSA keys must be at least 3072 bits, and ECDSA keys work too. An account can keep up to 50 keys, and the same key cannot be added twice.

To rename a key, click the pencil icon next to it. To delete one, click the bin icon, then **Delete Key**. Click a key's **Fingerprint** to copy it.

> **Warning:** Adding a key here does not put it on servers that already exist. It is offered for servers you order after you add it. Deleting a key here does not take it off servers either: remove it on each server too, as shown below.

## Adding a Key to a New Server

On the order's **SSH Key and Name** step, tick each key that can sign in as root. You can choose more than one, up to 20 for one order. To add a new key there, click **Add an SSH Key**, type a **Key Name**, paste the **Public Key** and click **Add Key**. It is saved to your account and ticked. Windows servers sign in with a password, so SSH keys are not used for them.

If you rebuild the server later, the keys you ticked here are put back. Keys added after the order are not.

## Adding a Key to a Server You Can Reach

If you can already sign in to the server, add another public key by appending it to the `authorized_keys` file of the user you sign in as. For the root user:

```
echo "ssh-ed25519 AAAA... you@example.com" >> /root/.ssh/authorized_keys
```

Paste your own public key line in place of the example. Then open a new terminal and check you can sign in with the key before you close your current session.

## Removing a Key

To stop a key working, sign in to the server and delete its line from `authorized_keys`:

```
nano /root/.ssh/authorized_keys
```

Remove the line for the key, save the file, and close the editor. Do this when a laptop is lost, when someone leaves your team, or when you replace a key.

KapsuleHost keeps a management key (named kapsulehost-management) on every server we build, for backups, monitoring and security updates. Removing it stops those features.

> **Note:** Keys you add yourself inside the server are stored on its disk, so a [rebuild](https://support.kapsulehost.com/en-us/cloud-servers-rebuild) erases them.

## Keys for Websites

SSH access to a website on our hosting is separate from servers. For a website, go to **Websites**, open the site, then **SSH Keys**.

## Related Articles

- [Connecting to Your Server by SSH](https://support.kapsulehost.com/en-us/cloud-servers-ssh-connect)
- [Creating a Server](https://support.kapsulehost.com/en-us/cloud-servers-create)
- [Rescue Mode](https://support.kapsulehost.com/en-us/cloud-servers-rescue)
- [Rebuilding a Server](https://support.kapsulehost.com/en-us/cloud-servers-rebuild)
