October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk4 min

Stop Repeated SSH Passphrase Prompts with ssh-agent

Use ssh-agent to unlock an encrypted SSH key once and let connected clients use it while the identity remains loaded. Learn manual and automatic loading, lifetimes, and forwarding risks.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use OpenSSH’s ssh-agent to unlock a passphrase-protected private key once, then let SSH clients use that loaded identity while it remains in the agent. Start or connect to an agent, add the key with ssh-add, and optionally configure SSH to add it automatically. The key file stays encrypted on disk; loading it does not remove its passphrase.

How ssh-agent avoids repeated passphrase prompts

ssh-agent holds identities for public-key authentication and starts with none loaded. When you add an encrypted private key, you enter its passphrase to unlock it for the agent. SSH clients connected to that agent can then request authentication using the loaded identity without asking you to unlock the same key file for each connection. This lasts only while the identity remains loaded and the agent is available.

As an Amazon Associate I earn from qualifying purchases.

The connection is usually communicated through the SSH_AUTH_SOCK environment variable, which names the agent’s Unix-domain socket. A shell or process that has not inherited the right environment may not be able to use the agent.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start an agent and load a key for a shell session

First check whether your environment already provides an agent. If it does, avoid starting a second one unnecessarily. Otherwise, start an agent and evaluate the shell commands it prints so its socket details are set in the current shell. For a POSIX-compatible shell:

#1 Best Overall
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
eval "$(ssh-agent -s)"

Then add the private key. Substitute the path to your actual key if it is not ~/.ssh/id_ed25519:

ssh-add ~/.ssh/id_ed25519

Enter the key’s passphrase when prompted. The identity is now available to SSH clients launched from an environment connected to that agent. If you open another terminal that does not inherit the same agent environment, it may not see this identity.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Choose manual or automatic key loading

Manual loading with ssh-add

Run ssh-add when you want to decide explicitly when a key enters the agent. This makes the loading action visible and avoids adding a file-backed key just because you connect to a matching host. The agent’s identity list starts empty, so adding the key is a separate step.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Automatic loading with AddKeysToAgent

To have SSH add a file-backed identity to an agent when it is loaded, add AddKeysToAgent yes to the appropriate host entry in ~/.ssh/config:

Host example
    HostName example.org
    User alice
    IdentityFile ~/.ssh/id_ed25519
    IdentitiesOnly yes
    AddKeysToAgent yes

With this setting, connecting to the matching host can add the specified key to the agent after you unlock it. The current OpenBSD ssh_config(5) manual gives AddKeysToAgent a default of no. Option availability and behavior can differ with the OpenSSH version packaged by your operating system, so check the manual installed with your client.

Set an identity lifetime or require confirmation

An identity need not remain loaded indefinitely. AddKeysToAgent also accepts a time interval, after which the added identity expires, or confirm, which requires confirmation for each use. These choices trade convenience against the time or circumstances in which a loaded key can be used. Check your installed ssh_config(5) manual for the accepted interval syntax and version-specific behavior.

Automatic loading is convenient when you regularly use the same key, while manual ssh-add gives you a deliberate loading step. A finite lifetime limits how long an identity remains available; leaving the lifetime unlimited is less interruption-prone but keeps it usable for longer. Choose based on how long the agent is active and how much you trust the machine and session.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Control which key SSH offers

If several identities are loaded, SSH may offer a key other than the one you intended. In a host entry, pair IdentityFile with IdentitiesOnly yes to restrict authentication to the configured identity rather than offering every available agent identity. Use IdentityAgent when you need to select a particular agent socket; setting it to none disables agent use for that host. Confirm the supported options in your installed client’s manual.

Best Value
Yubico - YubiKey 5Ci - Multi-Factor authentication (MFA) Security Key and passkey for iPhone/Android/PC, Dual connectors for Lighting/USB-C, FIDO Certified
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Understand agent forwarding before enabling it

Agent forwarding lets a remote machine ask your local agent to perform authentication operations, which can be useful when connecting onward from that remote host. It does not copy the private-key file to the remote machine. But anyone on the remote host who can access the forwarded socket may request operations using identities loaded in your local agent. Forwarding is therefore a delegation of access, not a harmless convenience. Leave it disabled unless you need it and trust the remote host.

Troubleshoot a key that is not being used

  • Check the connection to the agent: inspect SSH_AUTH_SOCK in the shell running SSH. An unset or unexpected socket can mean the client is not connected to the agent you intended.
  • Load the identity: use ssh-add ~/.ssh/id_ed25519, substituting your private-key path, and enter its passphrase when prompted.
  • Check the host’s identity rules: review its IdentityFile and IdentitiesOnly settings if SSH appears to select another key.
  • Check the shell environment: if the agent works in one terminal but not another, the second shell or process may not have inherited the correct SSH_AUTH_SOCK.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.