Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
World desk5 min

Set Up GitLab SSH Keys and Fix Common Connection Errors

Create a GitLab SSH key, add its public half to the right account, verify the host, and trace common authentication failures to the right layer.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To use GitLab over SSH, create a key pair on your computer, add only the public key to the correct GitLab account, verify the instance’s host key, and test the connection. If SSH still fails, identify whether the problem is the server name, the key Git is offering, or the account and instance accepting it.

Before you start: check your SSH client and instance

You need an OpenSSH client; GitLab’s setup documentation specifies SSH 6.5 or later. Check the installed version with ssh -V. For GitLab.com, the SSH host is gitlab.com. For a self-managed or Dedicated instance, use its actual hostname. The default SSH username is git, though a self-managed administrator can change it.

As an Amazon Associate I earn from qualifying purchases.

Choose a key type that your client and GitLab instance accept. GitLab lists ED25519 as the preferred option, but notes it may not be fully supported on some FIPS systems. If you need RSA for compatibility, GitLab recommends at least 4096 bits and documents a maximum of 8192 bits. Self-managed administrators may impose additional key restrictions. See GitLab’s supported SSH key types.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set up a key and connect to GitLab

  1. Create a key pair on your computer

    Generate an SSH key pair using the instructions for your operating system in GitLab’s SSH key setup guide. Keep the private key on your device. Do not upload it, paste it into GitLab, or share it; the public key is the file you register with your account.

    #1 Best Overall
    Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
    • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
    • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
    • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
    • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
    • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  2. Add the public key to the intended account

    In GitLab, open Profile → Access → SSH keys, then add the contents of your public-key file. The key can be configured for authentication, signing, or both; the interface defaults to both. Check the account’s key expiration settings as you add it. The GitLab account-key instructions describe the available fields.

  3. Verify the server and test authentication

    Before accepting a first-connection host-key prompt, compare the fingerprint shown by SSH with the published fingerprint for the host. For GitLab.com, use GitLab’s SSH host-key fingerprints. For a self-managed instance, verify against that instance’s official information or administrator; do not assume GitLab.com’s fingerprint applies.

    Rank #2
    Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
    • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
    • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
    • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
    • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
    • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

    Then test using the bare instance hostname:

    ssh -T [email protected]

    For a self-managed or Dedicated instance, substitute its hostname:

    Free tools Windows power users keep installed

    One-click scans. No signup required.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
    ssh -T [email protected]

    A successful connection returns a GitLab welcome message. If SSH reports that it cannot verify the host, stop and confirm the fingerprint before proceeding.

    Rank #3
    Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
    • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
    • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
    • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
    • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
    • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  4. Use the project’s SSH clone URL

    Open the project in GitLab, select Code, and copy its SSH clone URL. Use that URL for cloning or update an existing remote to it. The repository URL belongs in Git’s clone or remote command, not in the hostname position of the SSH connection test.

Diagnose the error by layer

Start with the exact message. A DNS or hostname error points to the destination; a public-key rejection points to key selection, local access, account enrollment, or instance policy. For unclear failures, SSH’s verbose output can show which key it offers and what happens during authentication.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Permission denied (publickey)

Check these causes in order:

  • Account enrollment: Confirm the public key is registered to the GitLab account you intend to use, not another account.
  • Key support: Confirm the algorithm is supported by the local OpenSSH client and accepted by the GitLab instance. A self-managed administrator may restrict accepted key types.
  • Key selection: If you have several keys, SSH may be offering the wrong private key. See GitLab’s SSH troubleshooting guidance for key-selection checks.
  • File access and permissions: The private key must be readable by your user. GitLab’s troubleshooting guidance specifies permissions of 600 for the private key and 700 for the .ssh directory.
  • Agent state: If your configuration relies on ssh-agent, check that the key is loaded. A reboot or a new terminal session can leave it unavailable.

To see more detail for a self-managed host, run:

ssh -Tvvv [email protected]

Replace the hostname with the instance you actually use. For a Git operation, GitLab also documents collecting SSH details with GIT_SSH_COMMAND="ssh -vvv"; see Git troubleshooting: see what SSH is doing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Password prompt while cloning

If a clone over an SSH URL prompts for a password for git@host, SSH authentication is not working as expected. Recheck that you copied the SSH URL, enrolled the public key, selected a compatible private key, and made it available to your agent if needed. On Windows, also check the relevant client and agent setup. GitLab recommends testing the connection with ssh -Tv git@host; replace host with your instance hostname. Its password-prompt troubleshooting page covers further checks.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Could not resolve hostname

Use only the instance hostname in the connection test. For example, gitlab.com:group/project.git is a clone address, not a hostname to pass after git@. Check spelling and the instance URL first. For a self-managed service, also check DNS, VPN access, and whether local name-resolution information is stale. GitLab explains this error in its hostname troubleshooting guide.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose the right setup for multiple accounts or repositories

A single account-wide key is simplest when one GitLab account is used from a device. If you use multiple accounts, or need different keys for different repositories, configure SSH to select the intended identity rather than relying on whichever key it tries first.

Multiple accounts: use SSH host aliases

GitLab’s advanced guide shows aliases in the SSH configuration that point to gitlab.com while selecting a corresponding identity file. Use the alias in the Git remote so the right account key is chosen for that connection. Follow GitLab’s advanced SSH configuration guide for the configuration pattern and remote update steps.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

One repository: set a repository-specific SSH command

Git supports a per-repository core.sshCommand setting that names a key and uses IdentitiesOnly=yes. GitLab notes this approach does not use ssh-agent and requires Git 2.10 or later. Keep the named private key restricted to its owner. See GitLab’s single-repository key instructions.

When a hardware-backed SSH key makes sense

Most GitLab SSH setups do not require a hardware security key. If you specifically want a FIDO2-backed SSH key, GitLab documents the ED25519_SK and ECDSA_SK key types. These require OpenSSH 8.2 or later on both the local client and GitLab server. Enrollment can fail if the device does not support the requested type or the client’s OpenSSH version is too old; confirm the requirements in GitLab’s supported-key documentation and its FIDO2 troubleshooting notes.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.