In SSH, public/private key login lets a client prove it holds a private key by signing an authentication request. The server checks the signature with the matching public key and confirms that the key is accepted for the requested user. The private key is not sent to the server.
What does public/private key login mean?
It is a way to authenticate using a related pair of cryptographic keys. In SSH public-key user authentication, the client uses the private key to create a signature, and the server uses the corresponding public key to verify it. The SSH standard describes the essential idea succinctly: “With this method, the possession of a private key serves as authentication.” (RFC 4252, section 7)
This explanation is specifically about SSH. Other systems may use public/private keys in different protocols or workflows.
Which key goes on the server, and which stays private?
- Private key: Keep it protected on the client device or in a suitable hardware-backed credential. It is used to sign the authentication request and should not be shared. Microsoft warns that a private key can allow sign-in to SSH servers that accept it; its OpenSSH for Windows key-management guidance says each private key file is equivalent to a password.
- Public key: Give this to the server or service as required so it can associate the key with the relevant account and verify signatures. Sharing the public key does not reveal the private key.
Copying or learning a public key alone does not prove possession of its private counterpart.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How does SSH public-key login work?
- The client requests authentication as a named user and identifies a public key.
- If the server accepts that key for the user, the client signs data for the authentication request using the matching private key. The signature is bound to the SSH session and request, rather than being a reusable password.
- The server checks that the key is acceptable for the account and verifies the signature. If both checks succeed, public-key authentication succeeds; server policy can still require another authentication method.
The server receives the public key and signature for verification, not the private key. SSH also has a transport layer that provides server authentication, confidentiality, and integrity; user authentication is a distinct part of the protocol (RFC 4251).
Does key login still use a password or passphrase?
It may involve a passphrase, but that is not the same as the SSH account password. A passphrase can unlock a locally stored, encrypted private-key file so the client can use it to sign. The server password is a separate authentication method in SSH; the standard treats password authentication and public-key authentication separately (RFC 4252, sections 7–8).
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
A passphrase protects the key at rest, but it does not by itself establish that a deployment meets a particular multifactor-authentication policy. The server can require additional authentication independently.
What does the key prove—and what does it not prove?
- A valid signature demonstrates that the client can use the private key corresponding to the offered public key.
- The server’s account and key checks determine whether that credential is accepted for the requested user.
- Successful authentication does not grant unrestricted access. Server and service authorization policies govern what the account can do, and the server may require another authentication step.
- User public-key login does not, on its own, verify the server’s identity. SSH’s transport layer handles server authentication separately from user authentication (RFC 4251).
How is it different from SSH password login?
With public-key authentication, the client proves possession through a signature checked with the offered public key. With SSH password authentication, the password is sent within the protected SSH transport. Neither method is automatically best in every configuration: security also depends on how credentials are protected, how the server is configured, and what authentication and authorization policies it enforces (RFC 4252; RFC 4251).
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Do you need a hardware key?
No. SSH public-key login can use key files; the protocol does not require a physical security key. A smartcard or other hardware-backed credential may be an option where a policy needs enforceable protection for private-key use. Compatibility depends on the specific SSH client, server, and credential, so a generic USB security key should not be assumed to work everywhere (RFC 4251, section 9.4.4).
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.One platform-specific limitation
Microsoft’s documented OpenSSH for Windows implementation supports key-based authentication for local Windows and Active Directory accounts, but not Microsoft Entra ID accounts. This is a limitation of that documented Windows implementation, not a general limitation of SSH (Microsoft Learn).
Quick Recap
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




