# SSH keys

> Add the public keys you use to open a shell in a Workspace.

Source: https://nodus-platform-site.pages.dev/docs/guides/access/ssh-keys/
Build revision: 211ad9f836655b1c3a2668c4693e442471f28614

An **SSH key** belongs to you, not to an org. Add it once and it works in the Workspaces of every org you belong to. Console › Account › SSH keys lists yours whatever org is selected.

Terminal window

```bash
nodus create sshkey laptop --from-file ~/.ssh/id_ed25519.pub
nodus get sshkeys
```

Without a key yet, let the CLI make one. `--generate` writes a new Ed25519 key pair to `~/.ssh/id_ed25519` (the public key next to it, with `.pub`) and adds the public key. The private key file is readable by you alone, and `nodus` never sends it anywhere. It refuses to overwrite a file that is there: use `--key-file PATH` to write elsewhere. Add a passphrase afterwards with `ssh-keygen -p -f ~/.ssh/id_ed25519`.

Terminal window

```bash
nodus create sshkey --generate
```

Leave the name out and the key is called `<email-local-part>-<hostname>`. `--from-file -` reads the key from standard input, and a file that holds a private key is refused.

Or over the API:

Terminal window

```bash
curl -X POST "$NODUS_API_URL/apis/nodus.dev/v1/sshkeys" \
  -H "Authorization: Bearer $NODUS_API_KEY" -H "Content-Type: application/json" \
  -d "{\"name\": \"laptop\", \"publicKey\": \"$(cat ~/.ssh/id_ed25519.pub)\"}"
```

Nodus accepts `ssh-ed25519`, `ecdsa-sha2-*` and `ssh-rsa` keys of at least 3072 bits. It stores the key without its comment and shows its `SHA256:` fingerprint, which is what `ssh-keygen -lf ~/.ssh/id_ed25519.pub` prints. Each name and each key can be added once, and you can hold up to 20 keys.

## Who can connect

`nodus ssh workspace/<name>` authenticates with your keys when you are an Owner, Admin or Member of the Workspace’s org and your membership covers its project. Viewers cannot open a shell. When you leave an org, your keys stop working in its Workspaces, and they keep working everywhere else.

## Removing a key

Terminal window

```bash
nodus delete sshkey laptop
```

Deleting a key ends the live sessions opened with it, and the next login with it is refused.
