Servers
SSH keys explained
What a key is, which file to use, where to get one, and the mistake almost everyone makes.
Some hosting companies never send you a password. Instead they give you a key — a file — and the server only lets in whoever holds it. If that is your situation, this page is for you. If you have a password, you can skip it entirely.
A key is two files
When a key is created, two files are made at the same time:
| File | Also called | Where it belongs |
|---|---|---|
id_rsa, id_ed25519, mykey.pem | the private key | With you. Never share it |
id_rsa.pub, id_ed25519.pub | the public key | On the server. Safe to share |
They are a matched pair. The public key on the server recognises the private key you hold, and lets you in.
DevOps Agent needs the private key — the file without .pub at the end.
The mistake almost everyone makes
Pasting the
.pubfile. It looks like a key, it is the one that is safe to share, so it feels like the right one to hand over. It is not. We detect this and tell you straight away: "This is the public key (the .pub file). The server needs the private key: the file without .pub."
How to recognise the private key
Open it in a text editor. It will start and end like this:
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gt…
-----END OPENSSH PRIVATE KEY-----
The word PRIVATE appears in the first line. Older keys say
-----BEGIN RSA PRIVATE KEY-----, which is also fine.
A public key is a single line beginning ssh-rsa, ssh-ed25519 or
ecdsa-sha2-…. If that is what you are looking at, you have the wrong file.
Where to find your key
- AWS EC2 — the
.pemfile you downloaded when you created the instance. AWS lets you download it once; if it is gone, you cannot get it back and you will need to attach a new key from the EC2 console. - DigitalOcean, Hetzner, Linode and similar — if you chose "SSH key" when
creating the server, the key is on the computer you created it from, usually
in a hidden folder called
.sshin your home directory. - A developer set it up — ask them for the private key for your user, or better, ask them to add a key you generate yourself.
Making a new key
On your own computer. Mac and Linux have this built in; on Windows it works in PowerShell or Git Bash.
ssh-keygen -t ed25519 -C "devops-agent"
Press Enter to accept the default location. When it asks for a passphrase you may leave it empty (simpler) or set one (safer — you will then type it into the Key passphrase field when adding the server).
You now have two files in the .ssh folder of your home directory:
id_ed25519— the private key, the one you give DevOps Agentid_ed25519.pub— the public key, the one that goes on the server
To put the public key on a server you can already reach:
ssh-copy-id -i ~/.ssh/id_ed25519.pub root@167.99.12.34
If you cannot reach the server at all, use your hosting company's web console or their "add SSH key" screen.
Copying a key correctly
When using Paste a key, you must copy the entire file including the first
and last lines. A key missing its -----END …----- line will be rejected with
"The key looks cut off."
If copy-and-paste keeps mangling it, use Upload a key file instead and pick the file directly.
Keys and usernames go together
A key is installed for one user on the server. A key added for ubuntu will
not let you in as root. If you get "The server refused this key", the
username is as likely to be wrong as the key.
Passphrases
A passphrase is a password on the key file itself. Most keys do not have one.
- If yours does, type it in the Key passphrase field when adding the server.
- If you type one for a key that has none, you get "This key is protected by a passphrase … it doesn't match this key." Clear the field and try again.
Other formats
- PuTTY
.ppkfiles are accepted as they are. - If you have something else entirely and it will not load, the simplest path is to generate a fresh key with the command above and add its public half to the server.
Is it safe to give you my private key?
It is encrypted with AES-256-GCM before being written to our database, decrypted only inside our server's memory at the moment it makes a connection you asked for, never sent back to any browser, and never shown to the AI model.
If you would rather not share a key at all, create a new key used only for DevOps Agent, and remove its public half from the server whenever you want access to stop. More detail: How we protect your credentials.
