---
title: How to generate an SSH key pair
description: This page explains how to generate an SSH key pair
tags: generate key ssh ssh-key create publickey public-key
dates:
  validation: 2026-01-23
  posted: 2021-06-08
---
import Requirements from '@macros/iam/requirements.mdx'

import image from './assets/scaleway-puttygen-app.webp'
import image2 from './assets/scaleway-puttygen-01.webp'
import image3 from './assets/scaleway-puttygen-02.webp'
import image4 from './assets/scaleway-puttygen-03.webp'
import image5 from './assets/scaleway-orga-drop-down.webp'


[SSH keys](/organizations-and-projects/concepts/#ssh-key) allow you to securely connect to your Instances, Elastic Metal servers, and Mac minis without using a password. An SSH key consists of a key pair, which has two elements:

- An **identification key** (also known as a private key), which you must keep securely on the computer you want to connect from.
- A **public key** is uploaded to the Scaleway console, where it is displayed with a customizable name and a hash of its value, known as a fingerprint, to make it more identifiable. The public key is transferred to your Instance during the boot process for authentication.

You can generate the SSH key pair on your local machine. The process will depend on your operating system.

We recommend you use either:

- an [Ed25519 SSH key pair](#how-to-generate-an-ed25519-ssh-key-pair), to connect to your Linux-based Instances.

- an [RSA SSH key pair](#how-to-generate-a-rsa-ssh-key-pair), to connect to your Windows-based Instances.

<Message type="note">
  SSH keys are scoped at a Project level. Ensure you add an SSH key to each Project you want to use it in.
</Message>

<Requirements />

- A Scaleway account logged into the [console](https://console.scaleway.com)
- [Owner](/iam/concepts/#owner) status or [IAM permissions](/iam/concepts/#permission) allowing you to perform actions in the intended Organization

## How to generate an SSH key pair

### How to generate an Ed25519 SSH key pair

Ed25519 SSH key pairs allow you to connect to your Linux-based Instances from a macOS, Linux or Windows machine.

<Tabs>
    <TabsTab label="macOS and Linux">

      On macOS and Linux, you can generate the SSH key pair directly from the terminal.

      1. Open a terminal.

      2. Run the following command to generate a new key:
          ```bash
          ssh-keygen -t ed25519 -C "login@example.com"
          ```
          <Message type="important">
              It is strongly recommended to use [Ed25519](https://en.wikipedia.org/wiki/EdDSA#Ed25519) for increased security and performance. If you cannot use Ed25519 keys, you can create an RSA4096 key as a fallback option:
              ```bash
              ssh-keygen -o -b 4096 -C "login@example.com"
              ```
          </Message>
      3. When prompted to enter a file path in which to save the key, either specify a path or press **Enter** to accept the default location (`~/.ssh/id_ed25519`).
          ```
          Enter file in which to save the key (~/.ssh/id_ed25519):
          ```
      4. Enter a passphrase when prompted. This step is optional but recommended for increased security. If you do not want to set a passphrase, press **Enter** directly.
          ```
          Enter passphrase (empty for no passphrase):
          ```
      5. Confirm the passphrase by entering it again when prompted, and press **Enter**:
          ```
          Enter same passphrase again:
          ```

          The key pair will be generated in the specified filepath. The key pair consists of:
          - The public key, named `id_ed25519.pub`
          - The private key, named `id_ed25519`
          <Message type="important">
            Ensure that the private key file (`<key_name>`) is kept secure. Do not share it with unauthorized parties. You can set appropriate permissions on the file to restrict access using the following command:
            ```bash
            chmod 600 <key_name>
            ```
          </Message>
      6. Display the content of the public key with the following command and copy it:
          ```bash
          cat ~/.ssh/id_ed25519.pub
          ```
          An output similar to the following displays:
          ```
          ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINPZxtCMs5sIfsMWpq7SHuqFFpBtSTmFqXWOYdf6dX4i login@example.com
          ```
      7. Copy the content of the public key displayed, as you will need this in the next step.

    </TabsTab>
    <TabsTab label="Windows">

        On Windows, you can use the third-party application [PuTTYgen](https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html) to generate an SSH key pair.

        1. Download and install [PuTTY](https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html) on your local computer. The **PuTTYgen** application is automatically installed along with the main PuTTY application.
            <Lightbox image={image} alt="PuTTYgen App" />
        2. Launch PuTTYgen by double-clicking the application icon.
        3. Select **EdDSA** and click the **Generate** button. You can also add a passphrase before generating the key to increase security.
            <Lightbox image={image2} alt="PuTTYgen Generate Key" />
        4. Move the mouse around the blank area as instructed to generate randomness.
            <Lightbox image={image3} alt="PuTTYgen Randomness" />

            The public and private key are generated, and the following screen will display:
            <Lightbox image={image4} alt="PuTTYgen Keys Generated" />
        5. Complete the steps on the screen to finish:
            - Fill in the **Key comment** field with a name to help you identify this key pair.
            - Click the **Save public key** button and save it in the folder of your choice.
            - Click the **Save private key** button to save it in the same folder.
                <Message type="important">
                    Ensure that the private key file (`<key_name>`) is kept secure. Do not share it with unauthorized parties.
                </Message>
            - Select the content of the public key (the sequence of characters under "Public key for pasting into OpenSSH authorized_keys file") and copy it, as you will need this in the next step.
    </TabsTab>
</Tabs>

### How to generate a RSA SSH key pair

RSA SSH key pairs allow you to connect to your Windows-based Instances from a macOS, Linux or Windows machine. RSA (Rivest-Shamir-Adleman) is a prevalent asymmetric cryptographic algorithm used for secure data transmission.

<Message type="note">
We recommend you use [Ed25519 keys](#how-to-generate-an-ed25519-ssh-key-pair) for SSH connections to your Linux Instances.
</Message>

1. Open a terminal or command prompt on your local machine. This could be Terminal on macOS/Linux or the Command Prompt/PowerShell on Windows.
2. Run the following command to generate the RSA key pair:
    ```bash
    ssh-keygen -t rsa -b 4096 -C "login@example.com" -o -a 100
    ```
    - When prompted, enter the file in which to save the key and press Enter. If you want to save it to the default location, press Enter without typing a filename.
    - Enter a passphrase and press Enter. For added security, choose a strong passphrase.
    - Enter the same passphrase again to confirm and press Enter.

3. This command will generate two files:
    - `<key_name>`: The private key file (e.g., `id_rsa`)
    - `<key_name>.pub`: The public key file (e.g., `id_rsa.pub`)
    <Message type="important">
      Ensure that the private key file (`<key_name>`) is kept secure. Do not share it with unauthorized parties. You can set appropriate permissions on the file to restrict access using the following command:
      ```bash
      chmod 600 <key_name>
      ```
    </Message>

## How to upload the public SSH key to the Scaleway interface

You must upload the content of the public part of the SSH key pair you just generated to the Scaleway interface. This is then transferred to your Instance during the boot process. You can then connect and authenticate from your local machine, where your private key is stored, to the remote Instance, where the public key can be found.

1. Go to your Project dashboard.
    <Message type="tip">
      Check if you are in the right Project before proceeding. You can check your current Organization and Project in the top-left corner of the Scaleway console. If you wish to change your Project, click the current Project name in the breadcrumb navigation and select a different existing Project in the drop-down. Click **Create Project** to create a new one.

      <Lightbox image={image5} alt="screenshot of the left corner of the Scaleway console top-menu. The image shows 'Test' as the Organization / and 'Default' as the Project. A drop-down menu is shown under 'Default' with a list of available Projects in the Organization and a button to create a new Project." />
    </Message>

2. Click **+ Add SSH key**. A popup displays.

3. Enter a name for your SSH key, paste the content of the public key copied earlier into the **Public key** box, then click **Add SSH key**.

    You can now [connect to your Instances via SSH](/instances/how-to/connect-to-instance/).

## Troubleshooting

If you have any difficulties connecting to an Instance after uploading a new public SSH key to your Project, try the following:

  - If you cannot connect to your Instance at all via SSH, reboot your Instance from the console and try again.
  - If you can connect to your Instance using a previously uploaded SSH key but not the new one, go ahead and connect to your Instance with the old key. Once connected, run the `scw-fetch-ssh-keys --upgrade` command, which launches a script on your Instance to update your SSH keys. You can then check that the new key has been added to the `authorized_keys` file (`~/.ssh/authorized_keys`). Note that this command works only for Instances.

For further information, refer to the dedicated [SSH connection troubleshooting](/instances/troubleshooting/cant-connect-ssh/) documentation.
