Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Use OpenSSH’s ssh-agent to unlock a passphrase-protected private key once, then let SSH clients use that loaded identity while it remains in the agent. Start or connect to an agent, add the key with ssh-add, and optionally configure SSH to add it automatically. The key file stays encrypted on disk; loading it does not remove its passphrase.
How ssh-agent avoids repeated passphrase prompts
ssh-agent holds identities for public-key authentication and starts with none loaded. When you add an encrypted private key, you enter its passphrase to unlock it for the agent. SSH clients connected to that agent can then request authentication using the loaded identity without asking you to unlock the same key file for each connection. This lasts only while the identity remains loaded and the agent is available.
As an Amazon Associate I earn from qualifying purchases.
The connection is usually communicated through the SSH_AUTH_SOCK environment variable, which names the agent’s Unix-domain socket. A shell or process that has not inherited the right environment may not be able to use the agent.
Start an agent and load a key for a shell session
First check whether your environment already provides an agent. If it does, avoid starting a second one unnecessarily. Otherwise, start an agent and evaluate the shell commands it prints so its socket details are set in the current shell. For a POSIX-compatible shell:
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
eval "$(ssh-agent -s)"
Then add the private key. Substitute the path to your actual key if it is not ~/.ssh/id_ed25519:
ssh-add ~/.ssh/id_ed25519
Enter the key’s passphrase when prompted. The identity is now available to SSH clients launched from an environment connected to that agent. If you open another terminal that does not inherit the same agent environment, it may not see this identity.
Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Choose manual or automatic key loading
Manual loading with ssh-add
Run ssh-add when you want to decide explicitly when a key enters the agent. This makes the loading action visible and avoids adding a file-backed key just because you connect to a matching host. The agent’s identity list starts empty, so adding the key is a separate step.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchAutomatic loading with AddKeysToAgent
To have SSH add a file-backed identity to an agent when it is loaded, add AddKeysToAgent yes to the appropriate host entry in ~/.ssh/config:
Host example
HostName example.org
User alice
IdentityFile ~/.ssh/id_ed25519
IdentitiesOnly yes
AddKeysToAgent yes
With this setting, connecting to the matching host can add the specified key to the agent after you unlock it. The current OpenBSD ssh_config(5) manual gives AddKeysToAgent a default of no. Option availability and behavior can differ with the OpenSSH version packaged by your operating system, so check the manual installed with your client.
Set an identity lifetime or require confirmation
An identity need not remain loaded indefinitely. AddKeysToAgent also accepts a time interval, after which the added identity expires, or confirm, which requires confirmation for each use. These choices trade convenience against the time or circumstances in which a loaded key can be used. Check your installed ssh_config(5) manual for the accepted interval syntax and version-specific behavior.
Rank #4
Automatic loading is convenient when you regularly use the same key, while manual ssh-add gives you a deliberate loading step. A finite lifetime limits how long an identity remains available; leaving the lifetime unlimited is less interruption-prone but keeps it usable for longer. Choose based on how long the agent is active and how much you trust the machine and session.
Recommended Free Tools
Control which key SSH offers
If several identities are loaded, SSH may offer a key other than the one you intended. In a host entry, pair IdentityFile with IdentitiesOnly yes to restrict authentication to the configured identity rather than offering every available agent identity. Use IdentityAgent when you need to select a particular agent socket; setting it to none disables agent use for that host. Confirm the supported options in your installed client’s manual.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Understand agent forwarding before enabling it
Agent forwarding lets a remote machine ask your local agent to perform authentication operations, which can be useful when connecting onward from that remote host. It does not copy the private-key file to the remote machine. But anyone on the remote host who can access the forwarded socket may request operations using identities loaded in your local agent. Forwarding is therefore a delegation of access, not a harmless convenience. Leave it disabled unless you need it and trust the remote host.
Quick Recap
Troubleshoot a key that is not being used
- Check the connection to the agent: inspect
SSH_AUTH_SOCKin the shell running SSH. An unset or unexpected socket can mean the client is not connected to the agent you intended. - Load the identity: use
ssh-add ~/.ssh/id_ed25519, substituting your private-key path, and enter its passphrase when prompted. - Check the host’s identity rules: review its
IdentityFileandIdentitiesOnlysettings if SSH appears to select another key. - Check the shell environment: if the agent works in one terminal but not another, the second shell or process may not have inherited the correct
SSH_AUTH_SOCK.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




