Use an SSH key on your phone
A phone is a fine SSH client, but it is also easy to lose. Give it its own key, move key files only over safe paths, protect the key with a passphrase, and know how to revoke it.
Quick answer. Best: generate a new Ed25519 key inside your SSH client on the phone and add its public key to your servers and GitHub. If you create the key elsewhere, give it a passphrase, move it over a local connection, import it, and delete every other copy. Never send a private key by email or chat.
ssh-keygen -t ed25519 -C "you@phone" -f ~/phone_ed25519
ssh-copy-id -i ~/phone_ed25519.pub [email protected]
Generate on the phone or bring a key?
An SSH key is a pair: the public key goes onto every server and account you want to reach, and the private key stays with you. Anyone who has the private key file, and its passphrase if it has one, can log in as you. So the question for a phone is where the private key is born and how many places it passes through.
| Approach | Private key travels | Good for |
|---|---|---|
| Generate in the SSH client on the phone | Nowhere | Almost everyone |
| Generate on a computer, move it to the phone | Once, over a path you choose | Clients that cannot generate keys, or a key you need in a specific format |
| Copy your laptop's existing key | Once, and now lives on two devices | Avoid it; see one key per device |
Option 1: generate the key on the phone
Most SSH clients for phones can create a key. Pick Ed25519, give it a name that says which device
it belongs to, such as you@phone, and set a passphrase if the client offers one. The client then shows
or exports the public key, a single line that starts with ssh-ed25519.
Put that public line wherever you want to log in:
-
A server you can already reach from another computer: append the line to
~/.ssh/authorized_keyson the server. - GitHub, GitLab or Bitbucket: paste it under your account's SSH keys, as described in SSH key for GitHub.
- A server you reach with a password from the phone: log in once with the password and append the line from there, then consider turning password logins off.
mkdir -p ~/.ssh && chmod 700 ~/.ssh
echo 'ssh-ed25519 AAAAC3Nz... you@phone' >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys
Getting the public line from the phone to your computer is harmless: it is public. Email, chat or a notes app are all fine for this half. Details and permissions are in Add an SSH key to a server.
Option 2: create it elsewhere and move it
If your client cannot generate keys, create a dedicated key for the phone on a computer, or with the generator on this site, which runs in the browser and never sends the key anywhere. Use a passphrase: it means the file is encrypted while it is in transit and sitting in a Downloads folder.
ssh-keygen -t ed25519 -C "you@phone" -f ~/phone_ed25519
# type a passphrase when asked
ssh-copy-id -i ~/phone_ed25519.pub [email protected]
Then move the private file phone_ed25519 to the phone over a path that stays between your devices:
- AirDrop or a similar direct device-to-device transfer, accepted only on your own phone.
- A USB cable, copying the file into the phone's storage or the client's import folder.
- A local file on the phone itself, if you generated the key in a browser on the phone.
- Scanning a QR code, if your client supports importing keys that way, from a screen nobody else can see.
After importing, delete every other copy, including the one on the computer if it is not needed there:
rm ~/phone_ed25519
rm ~/Downloads/phone_ed25519 # if the browser saved one
On the phone, delete the file from Downloads or Files once the client has imported it. Check the recently deleted folder too, if your file manager has one.
Ways not to move a private key
- Email, even to yourself. The key ends up on mail servers and in every synced mailbox, for years.
- Chat apps and messengers, including "message to self". They keep history and sync it to other devices.
- Cloud drives and notes apps, unless the file is protected by a strong passphrase and you delete it right after. Cloud copies show up in backups and version history.
- A shared clipboard. Clipboard sync between your devices and clipboard history apps keep what you copy. If you must paste a key, clear the clipboard afterwards.
- Screenshots of the key. They go to photo libraries and photo backups.
Import the key into an SSH client
Clients differ in the details but the steps are the same: open the key settings, choose import, pick the file or
paste its contents, and type the passphrase if the key has one. The file must be the private key, the one without
.pub, starting with:
-----BEGIN OPENSSH PRIVATE KEY-----
Keys from current ssh-keygen and from this site use this OpenSSH format. A key that starts with
-----BEGIN RSA PRIVATE KEY----- is the older PEM format, which most clients also read. A PuTTY
.ppk file usually needs converting first, with PuTTYgen or puttygen key.ppk -O private-openssh -o key.
Termphin, an SSH client made by the team behind this site, is one example: it can generate a key on the device or import an OpenSSH key, including one encrypted with a passphrase, and keeps keys in an encrypted vault. Once the key is imported, attach it to a host entry and connect; check the fingerprint the first time, as described in SSH key fingerprints.
Passphrase and app lock
A phone can be unlocked, borrowed or backed up, so treat the key like one on a laptop. Two layers help, and they do different jobs:
- The passphrase or the client's encrypted key store protects the key at rest. A copy of the file or of the app's data is not enough to use it.
- An app lock (a PIN or fingerprint before the client opens) stops someone who picks up your unlocked phone from opening a session. It is an access barrier, not encryption; keep the passphrase or vault as well.
Termphin has both: keys live in an encrypted vault, and an optional app lock asks for a PIN or fingerprint before the app opens. Whatever client you use, keep the phone itself locked with a strong code. More on choosing one in SSH key passphrases.
One key per device
Give every device its own key and label it in the comment: you@laptop, you@phone,
you@tablet. The comment appears at the end of each line in authorized_keys and in GitHub's
key list, so you can see at a glance which device a key belongs to.
It costs a few more lines in authorized_keys and pays off the day a device is lost: you remove its key
and nothing else changes. With one shared key, losing the phone means a new key for every device and every server.
You can also limit what the phone key may do. In authorized_keys, options in front of the key restrict
it, for example to no port forwarding:
no-port-forwarding,no-agent-forwarding ssh-ed25519 AAAAC3Nz... you@phone
Revoke the key of a lost phone
Revoking means removing the public key wherever it is trusted. Do it from another device as soon as you can, even if the key has a passphrase.
On each server
List the keys with their fingerprints and comments, then delete the phone's line:
ssh-keygen -lf ~/.ssh/authorized_keys
cp ~/.ssh/authorized_keys ~/.ssh/authorized_keys.bak
grep -v 'you@phone' ~/.ssh/authorized_keys.bak > ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys
Check that your own access still works from a second terminal before you close the first, then delete the backup.
Repeat for root's authorized_keys and any other account the phone could reach, including jump hosts.
On GitHub, GitLab and Bitbucket
Open your account's SSH key settings (github.com/settings/keys on GitHub), find the key by its title or fingerprint, and delete it. If the same key was also added as a signing key or a deploy key in a repository, delete those too.
Everything else
Sign the phone out of your accounts, wipe it remotely if you can, and change any passwords the SSH client stored. Then create a fresh key on the replacement phone.
Troubleshooting
"Permission denied (publickey)" from the phone
The server does not have this key's public line, or ignores it. Compare the fingerprint the client shows with
ssh-keygen -lf ~/.ssh/authorized_keys on the server, and check the permissions: 700 on
~/.ssh and 600 on authorized_keys.
The client says the key is invalid or unsupported
You probably picked the .pub file, or the file was changed in transit, for example by a notes app that
replaced line breaks. Copy the original file again without opening it in an editor. A PuTTY key needs converting
first.
"Incorrect passphrase"
Phone keyboards add capital letters and replace quotes with typographic ones. Turn off auto-capitalisation for the
field, or test the passphrase on a computer with ssh-keygen -y -f phone_ed25519.
GitHub says "Key is already in use"
A key can belong to only one GitHub account. You are re-adding a key that is already on another account; create a new one for the phone.
FAQ
Can I use the same SSH key on my laptop and my phone?
You can, but it is better not to. With one key per device you can revoke a lost phone by deleting one line on each server, and your laptop keeps working. A shared key means replacing it everywhere at once.
Is it safe to email a private key to myself?
No. The key then sits in your mailbox, the provider's servers and every device that syncs mail, usually for years. Generate the key on the phone instead, or move it over a local connection and delete the copies.
Do I need a passphrase on a phone key?
Yes, unless the client keeps keys in an encrypted store and you accept that. A passphrase means a copied key file is useless on its own. Most clients ask for it once per session or keep it unlocked while the app is open.
Which key type should I use on a phone?
Ed25519. It is small, fast on any phone and accepted by GitHub, GitLab and every current OpenSSH server. Use RSA 4096 only for old systems that reject Ed25519. See Ed25519 vs RSA.
What should I do first if my phone is stolen?
Remove the phone's public key from every server's ~/.ssh/authorized_keys and from GitHub, GitLab and any other account. A passphrase buys you time, but revoking the key is what actually locks the phone out.
Can a phone use a hardware security key for SSH?
OpenSSH supports FIDO2 keys of type ed25519-sk and ecdsa-sk, but support on phones depends on the SSH client and the connection to the security key. Check your client's documentation before relying on it.