SECURITY / A CONCEPT NOTE
SSH Keys & Agents
passwordless, but safe
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
SSH keys use public-key cryptography to authenticate logins. An SSH agent runs in memory to manage your private keys, decrypting them once with a passphrase so you don't enter it repeatedly.
02 / FOLLOW THE MECHANISM
How agent authentication flows
Login challenge
ssh client initiates connection; server sends a challenge encrypted with your public key.
Agent sign
local ssh-agent uses your private key to sign the challenge and returns the signature.
Verification
server checks signature with public key, granting access if valid.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
load your private key into the SSH agent
ssh-add ~/.ssh/id_rsalist all active keys managed by the agent
ssh-add -l05 / CHECK YOURSELF
Could you explain SSH Keys & Agents to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identityHashing vs Encryptionone-way vs two-way