> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.ai/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.ai/docs/_mcp/server.

# SSH Keys

> Add and manage SSH public keys on IBEE Solutions to authenticate into servers without a password.

SSH keys let you authenticate into IBEE Solutions servers securely without a password. Add your public key once to your organization, then select it when creating a VM — it will be injected automatically at boot.

## Before you begin

* An active IBEE Solutions organization ([Create an organization](/docs/getting-started/account-setup/create-a-project))
* An SSH key pair on your local machine — generate one if you don't have one yet:

```bash
# Generate an ed25519 key (recommended)
ssh-keygen -t ed25519 -C "your-email@example.com"

# Or RSA
ssh-keygen -t rsa -b 4096 -C "your-email@example.com"
```

Your public key is at `~/.ssh/id_ed25519.pub` (or `~/.ssh/id_rsa.pub`).

## Add an SSH key

### Go to SSH Keys

In the IBEE Solutions portal, click **SSH Keys** in the left sidebar under **Tools**.

### Add a key

Click **+ Add SSH Key**.

### Fill in the details

| Field          | Required | Description                                                                            |
| -------------- | -------- | -------------------------------------------------------------------------------------- |
| Name           | Yes      | A label for this key, e.g. `My Laptop Key`                                             |
| SSH Public Key | Yes      | Paste the contents of your `.pub` file. Must start with `ssh-rsa`, `ssh-ed25519`, etc. |
| Description    | No       | e.g., Production server key                                                            |

### Save

Click **Add SSH Key**. The key appears in the SSH Keys list.

## SSH Keys list

| Column      | Description                              |
| ----------- | ---------------------------------------- |
| NAME        | Key label                                |
| KEY TYPE    | Algorithm, e.g. `ssh-ed25519`, `ssh-rsa` |
| FINGERPRINT | SHA256 fingerprint for verification      |
| CREATED AT  | Date added                               |
| ACTIONS     | View · Delete                            |

## Delete a key

Click **Delete** in the Actions column. Deleting a key does **not** remove it from servers it was already deployed to — it only prevents the key from being selected for new servers.

## Use an SSH key when creating a server

When creating a VM, select your saved SSH key in the **SSH Key** step. The key is injected into the server at first boot under the default user (typically `root` or `ubuntu`).

## SSH keys on VM details

The VM detail page shows the names of SSH keys authorized for the instance, so you can verify which keys have access without logging in.

## Connect to a server

Once a key is injected, connect with:

```bash
ssh -i ~/.ssh/id_ed25519 root@<server-ip>
```

## Troubleshooting

**Key rejected — must start with ssh-rsa, ssh-ed25519, etc.**
Ensure you are pasting the **public** key (`.pub` file), not the private key. Public keys begin with `ssh-rsa`, `ssh-ed25519`, or similar.

**Permission denied when connecting**

* Verify the correct private key is being used with `-i`
* Check that the public key was selected during VM creation
* Ensure the server is running and the IP is correct

**Key deleted but still works on an existing server**
Deleting a key from the portal only removes it from future server deployments. To revoke access on a running server, remove the key from `~/.ssh/authorized_keys` on the server.

## Related pages

* [Create a VM](/docs/infrastructure/cloud-vms/create-a-vm)
* [API Tokens](/docs/tools/api-tokens)