If you need to generate SSH keys on Mac for VPS access, or you searched for generate ssh key mac, the cleanest path is to use the built-in OpenSSH tools that already ship with macOS. In practice, that means generating an Ed25519 key pair with ssh-keygen, optionally loading it into the ssh-agent, and then adding the public key to your VPS provider panel or directly to the server.
That is the standard flow because SSH keys are safer than passwords, easier to automate, and much better suited to long-term VPS administration. Once you get this right once, it becomes your default login pattern for every Linux server you touch.
In this guide I will show you the exact commands, what each step is doing, how to avoid the common Mac-specific mistakes, and how to test the key against your server when you are done.
Quick answer
On a modern Mac, the short version is:
ssh-keygen -t ed25519 -C "you@example.com"
Then:
- press Enter to accept the default save location
- set a passphrase if you want the key protected at rest
- add the key to your agent if you want macOS to remember it
- copy the
.pubkey to your VPS or hosting control panel - test the login with
ssh
That is the whole workflow. The rest of this guide is the careful version that explains why each step matters.
Why use SSH keys instead of a password?
For VPS administration, SSH keys are the default for a reason:
- they are far harder to brute-force than passwords
- they let you disable password login on the server later
- they work cleanly with automation, configuration management, and Git-based workflows
- they reduce the chance that you will reuse a weak or exposed password across machines
A password is something you know. An SSH key pair is a private/public credential pair:
- the private key stays on your Mac
- the public key goes onto the server
When you connect, the server proves you own the private key without the private key ever leaving your machine.
If you are still at the stage of choosing the server itself, the broader context also matters. These related guides are useful alongside this one:
- Cloud VPS if you are provisioning the server now
- Server Operating Systems Compared – Linux vs Windows if you are choosing the OS
- What Is IOPS? A Guide to VPS Storage Performance if you are sizing the plan
Step 1: open terminal on your mac
You do not need third-party software for this. Open the built-in Terminal app on macOS and use the OpenSSH tools already installed with the system.
Once Terminal is open, you can generate the key pair directly.
Step 2: generate a new Ed25519 SSH key
The current default recommendation for most users is an Ed25519 key:
ssh-keygen -t ed25519 -C "you@example.com"
Here is what the flags mean:
-
-t ed25519chooses the Ed25519 key type -
-C "you@example.com"adds a label or comment so you can identify the key later
When I verified this locally on macOS, ssh-keygen successfully created both of these files:
-
id_ed25519 -
id_ed25519.pub
The private key is the file without .pub. The public key is the one with .pub at the end.
What to expect during generation
After you run the command, macOS will prompt you for a few things:
- File location — press Enter to accept the default location unless you have a reason to keep multiple named keys.
- Passphrase — optional, but strongly recommended if the Mac is a laptop.
- Confirmation — enter the passphrase again.
For most users, the default location is the right answer because it works cleanly with the SSH client and common tooling.
Step 3: add the key to the ssh-agent
If you want the Mac to remember the key for future SSH sessions, start the agent and add the key:
eval "$(ssh-agent -s)"
ssh-add --apple-use-keychain ~/.ssh/id_ed25519
Why this matters:
-
ssh-agentkeeps decrypted keys available for your session so you do not need to retype the passphrase constantly -
--apple-use-keychainis the macOS-friendly option for saving the passphrase in the Apple keychain
This is the step many guides skip, but it is the difference between "SSH keys are annoying" and "SSH keys are invisible once set up".
If you do not want macOS to remember the passphrase, you can skip the keychain-friendly add step and just type the passphrase when needed.
Step 4: show or copy the public key
You only upload the public key, never the private one.
To print the public key in Terminal:
cat ~/.ssh/id_ed25519.pub
On macOS, a very convenient option is to copy it directly to the clipboard:
pbcopy < ~/.ssh/id_ed25519.pub
Now you can paste the public key into:
- your VPS provider's SSH key field during provisioning
- the server user's
authorized_keysfile - a hosting control panel that imports SSH keys for you
A quick rule worth repeating: if the file does not end in .pub, do not upload it anywhere.
Step 5: add the public key to the VPS
How you do this depends on where the server is in its lifecycle.
If the VPS is not created yet
Many providers let you paste a public SSH key during provisioning. That is usually the cleanest option because the server is born with passwordless key-based access enabled from day one.
If the VPS already exists
You have two common options:
- paste the public key into the server user's
authorized_keysfile - use the provider's panel or rescue console to add the key remotely
If the server still only allows passwords, use that one last password-based login to install the public key — then move toward disabling password access once you confirm key login works.
Step 6: test the SSH login
Once the public key is on the server, test the connection:
ssh user@your-server-ip
On the first connection you may be asked to confirm the server fingerprint. After that:
- if you skipped the agent, enter the key passphrase when prompted
- if you added the key to the agent and keychain, the login should feel nearly passwordless
This is the moment to verify the setup is actually working before you harden the server further.