---
title: "Set up an SSH key on Windows to access your VPS | StreetHosting"
description: "Generate an ED25519 key in PowerShell, enable the Windows SSH agent, copy the public key to your VPS, add shortcuts in the config file and use PuTTYgen."
url: "https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows"
type: "page"
language: "en-US"
---

VPS · 9 min · Beginner

Published on Sep 28, 2026 · Updated on Sep 28, 2026

# SSH keys on Windows 10 and 11 with the built-in OpenSSH client

Windows already ships the OpenSSH client, so you can generate and use keys without installing anything. Here is the step by step in PowerShell, the most common permission errors and the path for anyone who prefers PuTTY.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Security and hardening](https://streethosting.com.br/en/guides/topics/security) [Linux administration](https://streethosting.com.br/en/guides/topics/linux) [Windows and RDP](https://streethosting.com.br/en/guides/topics/windows)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fset-up-ssh-key-windows.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fset-up-ssh-key-windows.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fset-up-ssh-key-windows.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fset-up-ssh-key-windows.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fset-up-ssh-key-windows.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=Set%20up%20an%20SSH%20key%20on%20Windows%20to%20access%20your%20VPS&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fset-up-ssh-key-windows "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fset-up-ssh-key-windows "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fset-up-ssh-key-windows "Share on LinkedIn") [](https://wa.me/?text=Set%20up%20an%20SSH%20key%20on%20Windows%20to%20access%20your%20VPS%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fset-up-ssh-key-windows "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows.md)

In this guide 8 sections

* [What you need first](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#requisitos)
* [Generate the key in PowerShell](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#gerar-chave)
* [Enable the Windows SSH agent](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#agente-ssh)
* [Send the public key to the VPS](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#enviar-chave)
* [Shortcuts in the config file](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#arquivo-config)
* [Permissions and common errors](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#erros-comuns)
* [PuTTY users: PuTTYgen and Pageant](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#putty)
* [After the key: close password login](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#proximos-passos)

Quick answer

To **set up an SSH key on Windows**, open PowerShell, run `ssh-keygen -t ed25519`, enable the `ssh-agent` service as administrator and load the key with `ssh-add`. Since Windows has no `ssh-copy-id`, send the **.pub** file to `authorized_keys` on the VPS with a one-line command. Then just connect and, once everything is tested, turn off password login.

## What you need first[](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#requisitos)

Windows 10 from version 1809 onward and Windows 11 ship with the OpenSSH client, the same one used on Linux. On most machines it is already installed. To check, open PowerShell or Windows Terminal and run:

`ssh -V`

If the answer is an OpenSSH version, you are good to go. If the command is not recognized, install **OpenSSH Client** under Settings, System, Optional features, or from a PowerShell window opened as administrator:

`Get-WindowsCapability -Online | Where-Object Name -like 'OpenSSH.Client*' Add-WindowsCapability -Online -Name OpenSSH.Client~~~~0.0.1.0`

On the VPS side, you need the IP, a user to log in with and password access still working, because that is how the key gets there. If you have not done the first login yet, follow [how to access your VPS for the first time over SSH](https://streethosting.com.br/en/guides/vps/connect-to-vps-via-ssh-first-time). Ideally use a regular user with sudo instead of root, as shown in the guide to [create a user with sudo](https://streethosting.com.br/en/guides/vps/create-sudo-user-linux-vps).

## Generate the key in PowerShell[](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#gerar-chave)

In a regular PowerShell window, with no administrator privileges, generate an ED25519 key pair. The text after **\-C** is just a comment so you can tell which computer the key came from:

`ssh-keygen -t ed25519 -C "notebook-casa"`

1. When asked where to save it, press Enter to accept `C:\Users\SeuUsuario\.ssh\id_ed25519`.
2. Set a passphrase. It protects the key if the file leaks or if someone copies your profile folder. With the agent running, you will not be typing that passphrase all the time.
3. Check the two files that were created: **id\_ed25519**, the private key that never leaves your computer, and **id\_ed25519.pub**, the public key that goes to the VPS.

To see the contents of the public key and its fingerprint:

`Get-Content $env:USERPROFILE\.ssh\id_ed25519.pub ssh-keygen -lf $env:USERPROFILE\.ssh\id_ed25519.pub`

The public key is a single line that starts with `ssh-ed25519 AAAA` and ends with the comment. ED25519 is short, fast and accepted by every current OpenSSH server, including Ubuntu 24.04. RSA with 4096 bits only makes sense if you need to log in to very old equipment.

Create one key per computer. If your laptop gets stolen, you remove only its line from the server and the other devices keep working. Never send, paste into a chat or push to a repository the file without the .pub extension.

## Enable the Windows SSH agent[](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#agente-ssh)

The agent holds the unlocked key and hands it to the SSH client when you connect. On Windows it is a service that ships disabled. Open PowerShell as administrator (right-click and choose Run as administrator) and run:

`Get-Service ssh-agent | Set-Service -StartupType Automatic Start-Service ssh-agent Get-Service ssh-agent`

The last line should show the status **Running**. Close that window and, in a regular PowerShell window, add the key to the agent:

`ssh-add $env:USERPROFILE\.ssh\id_ed25519 ssh-add -l`

The first command asks for the passphrase once. The second lists the loaded keys. Unlike the Linux agent, the Windows one keeps the key tied to your account and it stays available after the computer restarts. It is convenient, but it means anyone using your Windows session can use the key. Lock the screen when you step away.

Git for Windows ships its own SSH, with a separate agent. If Git keeps asking for the key passphrase, point it to the system OpenSSH with `git config --global core.sshCommand "C:/Windows/System32/OpenSSH/ssh.exe"`.

## Send the public key to the VPS[](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#enviar-chave)

On Linux this is done with `ssh-copy-id`, which does not exist on Windows. The equivalent is to send the .pub file over SSH itself and let a command on the server create the folder, append the key and fix the permissions. Replace usuario and IP\_DA\_VPS with your own details:

`type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh usuario@IP_DA_VPS "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"`

Your user password is asked for this one last time. Then open a new window and connect with `ssh usuario@IP_DA_VPS`. If the agent has the key loaded, you get straight in. If not, it asks for the key passphrase, not the user password. That difference is the sign that the key worked.

If you would rather do it by hand, copy the public key line shown in the generation step, log in to the VPS with your password and paste the key, as a single line, into the authorized keys file:

`mkdir -p ~/.ssh nano ~/.ssh/authorized_keys chmod 700 ~/.ssh chmod 600 ~/.ssh/authorized_keys`

The key is valid for the user whose folder it was written to. If you run the command logged in as root, it goes to `/root/.ssh` and does nothing for your regular user. If you create another user's folder using sudo, give ownership back with `sudo chown -R usuario:usuario /home/usuario/.ssh`, otherwise SSH ignores the file.

The same process, seen from the Linux or macOS side, is in the guide on [passwordless SSH keys on your VPS](https://streethosting.com.br/en/guides/vps/passwordless-ssh-login-vps).

## Shortcuts in the config file[](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#arquivo-config)

Typing user, IP and port every time gets old. The `C:\Users\SeuUsuario\.ssh\config` file stores aliases for each server. It has no extension. Create it with `New-Item $env:USERPROFILE\.ssh\config -ItemType File` (only if it does not exist yet) and open it in whatever editor you prefer. If you use Notepad, check afterwards with `Get-ChildItem $env:USERPROFILE\.ssh` that the name did not pick up a .txt at the end.

`Host minha-vps HostName IP_DA_VPS User usuario Port 22 IdentityFile ~/.ssh/id_ed25519 IdentitiesOnly yes Host * ServerAliveInterval 60`

Now `ssh minha-vps` is enough. The alias also works in `scp arquivo.zip minha-vps:/home/usuario/` and in Visual Studio Code with the Remote SSH extension, which reads the same file. To move files with more control, see [transfer files with SCP and rsync](https://streethosting.com.br/en/guides/vps/transfer-files-to-vps-scp-rsync).

* **IdentitiesOnly yes:** makes the client offer only the key specified. Without it, with several keys in the agent, the server may drop the connection with Too many authentication failures before it reaches the right one, especially if it limits attempts with MaxAuthTries.
* **ServerAliveInterval 60:** sends a signal every minute and stops your home router from dropping an idle session.
* **Port:** if you changed the SSH port on the VPS, this is where it gets recorded, instead of in your memory.

## Permissions and common errors[](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#erros-comuns)

Almost every key problem on Windows lands on one of these lines. To see what is going on in detail, connect with `ssh -v minha-vps` and read which keys the client offers and what the server replies.

| Message                                         | Likely cause                                                                                  | How to fix it                                                                                 |
| ----------------------------------------------- | --------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- |
| Permission denied (publickey)                   | Key missing or broken on the server, wrong user, or permissions on the .ssh folder on the VPS | Check the right user's authorized\_keys and apply chmod 700 to the folder and 600 to the file |
| UNPROTECTED PRIVATE KEY FILE or Bad permissions | Key or config readable by other Windows users                                                 | Remove inheritance and leave access only to your account with icacls                          |
| Error connecting to agent                       | Agent service stopped or disabled                                                             | Enable the service in PowerShell as administrator                                             |
| Too many authentication failures                | The agent offers too many keys before the right one                                           | Use IdentityFile with IdentitiesOnly yes in the config                                        |
| Connection timed out                            | Wrong IP, port blocked by the firewall or SSH on another port                                 | Check the IP, the VPS firewall and the Port parameter                                         |
| REMOTE HOST IDENTIFICATION HAS CHANGED          | The VPS was reinstalled and the server key changed                                            | Remove the old entry from known\_hosts and check the new fingerprint                          |

To fix the private key permissions on Windows, remove inheritance and grant access only to your user. Do the same with the config file if the warning mentions it:

`icacls $env:USERPROFILE\.ssh\id_ed25519 /inheritance:r icacls $env:USERPROFILE\.ssh\id_ed25519 /grant:r "$($env:USERNAME):(F)"`

After a VPS reinstall, delete the old fingerprint with `ssh-keygen -R IP_DA_VPS`. On the server side, when the key is rejected because of permissions, the reason shows up in the SSH log: `sudo journalctl -u ssh -n 30`. A line with bad ownership or modes points to a .ssh folder or home directory with permissions that are too open.

## PuTTY users: PuTTYgen and Pageant[](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#putty)

PuTTY does not read keys in the OpenSSH format directly; it uses .ppk files. There are two paths, and both use PuTTYgen, which comes bundled with the PuTTY installation.

1. **Generate directly in PuTTYgen:** choose the EdDSA type with the Ed25519 curve, click Generate and move the mouse until it finishes. Set the Key passphrase, click Save private key to write the .ppk and copy the text from the Public key for pasting into OpenSSH authorized\_keys file box. That text goes, as a single line, into authorized\_keys on the VPS.
2. **Reuse the key you already generated:**in PuTTYgen, use Conversions > Import key, pick the id\_ed25519 file, type the passphrase and save with Save private key. The public key is the same, so nothing changes on the server.

In PuTTY, point to the .ppk under Connection > SSH > Auth > Credentials (in older versions the field sits directly under Auth), fill in user and IP and save the session. Pageant is PuTTY's agent: load the .ppk into it once per Windows login and PuTTY, WinSCP and the other programs in the family stop asking for the passphrase.

## After the key: close password login[](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#proximos-passos)

As long as password login stays on at the VPS, the key is only a convenience: the bots that test passwords all day long still have a way in to try. With the key working in a second window, turn off password authentication, block root and restrict who can log in. The full strategy, with the configuration file and the second-session test, is in [protect SSH against brute force](https://streethosting.com.br/en/guides/infrastructure/protect-ssh-from-brute-force), and automatically banning whoever keeps insisting is handled by [Fail2Ban on the VPS](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup).

Before turning off passwords, do two things. Keep a copy of the private key somewhere safe, such as a password manager or an encrypted USB drive. And set a strong password for your user on the VPS with `sudo passwd usuario`: it will not get you in over SSH once password login is turned off, but it is what lets you log in through the control panel console if the key is lost.

If you have not ordered the server yet, the [StreetHosting Linux VPS](https://streethosting.com.br/en/vps) plans come with root access over SSH from the first minute, with activation within 60 seconds, a datacenter in São Paulo and Anti-DDoS included. The Xeon line starts at R$ 26.00 per month with 2 vCPU and 2 GB of RAM, and the Ryzen 9 9950X starts at R$ 40.00 with 1 vCPU, 2 GB DDR5 and 20 GB NVMe. For a website with a database or a few bots, the R$ 66.00 Ryzen plan, with 2 vCPU and 4 GB, is usually the most balanced starting point.

In this guide

* [What you need first](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#requisitos)
* [Generate the key in PowerShell](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#gerar-chave)
* [Enable the Windows SSH agent](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#agente-ssh)
* [Send the public key to the VPS](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#enviar-chave)
* [Shortcuts in the config file](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#arquivo-config)
* [Permissions and common errors](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#erros-comuns)
* [PuTTY users: PuTTYgen and Pageant](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#putty)
* [After the key: close password login](https://streethosting.com.br/en/guides/vps/set-up-ssh-key-windows#proximos-passos)

## Frequently asked questions

Does Windows have a command to copy the key to the VPS?

There is no native equivalent of the Linux one. The way around it is to send the contents of the .pub file over SSH itself, with a one-line PowerShell command that creates the .ssh folder on the VPS and appends the key to authorized\_keys. The other option is to paste the key by hand in a session that is already open.

Where does Windows store the SSH key?

In the .ssh folder inside your profile, at C:\\Users\\SeuUsuario\\.ssh. The private key is the file with no extension, such as id\_ed25519, and the public key is the file with the same name ending in .pub. Only the public one goes to the server.

Do I have to type the key passphrase every time I connect?

No, as long as the Windows SSH agent is running. You add the key once and it keeps it tied to your Windows account, even after the computer restarts. The trade-off is that anyone with access to your Windows session can also use the key.

Can I use the same key in PuTTY and in PowerShell?

Yes. PuTTY uses the .ppk format, so open the OpenSSH key in PuTTYgen through the import option and save a copy as .ppk. The public key stays the same, so nothing changes on the server.

Why do I get Permission denied (publickey)?

The server rejected every key that was offered. The most common causes are a public key that is missing or broken across two lines in authorized\_keys, wrong permissions on the .ssh folder on the VPS, the wrong user in the command, or a private key different from the one you sent. Run ssh with the -v option to see which key is being tried.

Next step

See VPS plans

Root VPS in Brazil with NVMe and Anti-DDoS.

[See VPS plans](https://streethosting.com.br/en/vps)

[See Ryzen VPS Ryzen 9 9950X VPS in São Paulo with root access, NVMe and gamer Anti-DDoS.](https://streethosting.com.br/en/vps/ryzen) [See Xeon VPS Xeon VPS for steady workloads, automation and long-running projects.](https://streethosting.com.br/en/vps/xeon)

## Related guides

[VPS Intermediate How to set up passwordless SSH key login on a VPS Key-based login is safer and easier than a password. You generate a key pair, copy the public key to the server, and log in without typing anything. Here is how, in a few steps. 3 min Read guide](https://streethosting.com.br/en/guides/vps/passwordless-ssh-login-vps) [VPS Beginner How to connect to your VPS for the first time via SSH You bought the VPS and received an IP, a user and a password. Now it is time for the first login. Here is how to connect over SSH from any system and what to do in the first few minutes. 3 min Read guide](https://streethosting.com.br/en/guides/vps/connect-to-vps-via-ssh-first-time) [Infrastructure Intermediate Protect SSH from brute force: a layered strategy Minutes after an IP goes live, bots start trying root and leaked passwords on SSH. This guide builds the defense in layers, from sshd\_config to a VPN, without locking your team out of the server. 8 min Read guide](https://streethosting.com.br/en/guides/infrastructure/protect-ssh-from-brute-force)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
