GitHub Authentication: SSH Keys & Access Tokens
In August 2021, GitHub permanently deprecated account password authentication for all Git operations in favor of cryptographic authentication. Today, developers must authenticate using either SSH Keys (Secure Shell) or Personal Access Tokens (PAT) over HTTPS.
Mastering cryptographic authentication using modern Ed25519 SSH keys allows you to push and pull code securely without ever typing your password or token in terminal prompts.
┌─────────────────────────────────────────────────────────────┐
│ SSH Asymmetric Cryptography │
│ │
│ Local Developer Machine GitHub Cloud Server │
│ ┌─────────────────────────┐ ┌────────────────────┐ │
│ │ Private Key (id_ed25519)│ │ Public Key (.pub) │ │
│ │ (STRICTLY CONFIDENTIAL) │ │ (Uploaded to │ │
│ │ Encrypted on your disk │ │ GitHub Settings) │ │
│ └─────────────────────────┘ └────────────────────┘ │
│ │ │ │
│ └────────── Cryptographic ───────┘ │
│ Handshake │
│ (Proves identity without transmitting key) │
└─────────────────────────────────────────────────────────────┘
1. Generating Modern SSH Keys (Ed25519)
The Ed25519 algorithm is the current gold standard in asymmetric cryptography, providing superior security and performance compared to legacy RSA keys:
# Generate a new Ed25519 SSH key pair with your GitHub email as a comment
ssh-keygen -t ed25519 -C "hesam@front-heaven.com"
# Press Enter to accept default file location (~/.ssh/id_ed25519)
# Enter a secure passphrase for key encryption
This creates two files in ~/.ssh/:
id_ed25519: Your Private Key. NEVER share, upload, or email this file!id_ed25519.pub: Your Public Key. This is the key you safely upload to GitHub.
2. Adding the SSH Key to the SSH Agent
The SSH Agent caches your decrypted private key in memory so you do not have to enter your passphrase on every single git push:
# Start the SSH agent in the background
eval "$(ssh-agent -s)"
# Add your private key to the agent
ssh-add ~/.ssh/id_ed25519
3. Adding Public Key to GitHub
Copy the contents of your public key file to your clipboard:
# macOS
pbcopy < ~/.ssh/id_ed25519.pub
# Linux (with xclip)
xclip -selection clipboard < ~/.ssh/id_ed25519.pub
# Windows (Git Bash)
clip < ~/.ssh/id_ed25519.pub
- Navigate to GitHub Settings -> SSH and GPG keys.
- Click New SSH Key.
- Set Title (e.g.
MacBook Pro Work M3) and paste the public key string starting withssh-ed25519. - Click Add SSH Key.
Testing the SSH Connection
ssh -T git@github.com
# Expected response: "Hi username! You've successfully authenticated, but GitHub does not provide shell access."
4. Personal Access Tokens (Fine-Grained PATs)
When interacting with GitHub over HTTPS (or inside CI/CD automation and scripts), use Fine-Grained Personal Access Tokens:
- Navigate to GitHub Settings -> Developer Settings -> Personal Access Tokens -> Fine-grained tokens.
- Set token name, expiration (e.g. 90 days), and select specific repository access.
- Grant minimal required permissions (e.g.
Contents: Read and write). - Copy the generated token (
github_pat_...) and store it in your password manager.
Summary & Key Takeaways
- Passwords are deprecated for Git CLI operations; use SSH keys or Personal Access Tokens.
- Ed25519 (
ssh-keygen -t ed25519) is the industry standard for SSH keys. - Private keys stay securely on your machine; public keys are uploaded to GitHub.
ssh -T git@github.comtests and confirms active SSH authentication.
Best Practices & Senior Guidance
- Always Set a Passphrase on SSH Keys: A passphrase encrypts your private key on disk, preventing unauthorized access if your laptop is lost or stolen.
- Never Commit SSH Keys or Tokens to Repositories: If a token is committed accidentally, GitHub's Secret Scanning will detect it and revoke it immediately.
- Use Fine-Grained PATs with Expiration: Avoid classic tokens with infinite lifespans and full account permissions; enforce least-privilege access.