ssh-keygen -t ed25519 -a 100 -C "me@laptop"

ssh-keygen Command Builder

Choose a key type and where it goes, and get the ssh-keygen command plus the steps that follow: copying the public key to a server and checking its fingerprint.

Saved in ~/.ssh/

Which key type to use

Use Ed25519 for new keys: short, fast, and supported by every OpenSSH release since 6.5. Choose RSA with 4096 bits only for old systems or appliances that cannot handle Ed25519. If you own a FIDO2 security key such as a YubiKey, the -sk types keep the private key on the hardware, so a stolen laptop alone cannot log in. Always set a passphrase on keys you use interactively; ssh-agent means you type it once per session, not every connection.

Generate SSH keys with ssh-keygen

This builder writes ssh-keygen commands for every common case: an everyday Ed25519 key, a 4096-bit RSA key for legacy hosts, and ed25519-sk or ecdsa-sk keys backed by a FIDO2 hardware token, with resident (discoverable) and verify-required options. It sets a descriptive comment, a separate file per purpose so you do not overwrite id_ed25519, and extra key derivation rounds that make a stolen key file harder to crack. It also prints the ssh-copy-id, fingerprint, and passphrase-change commands you need next.

ssh-keygen FAQ

Will this overwrite my existing key?

ssh-keygen asks before overwriting a file that exists, but it is easy to answer yes by reflex. Give each key its own file with -f, such as ~/.ssh/id_ed25519_work, and point at it from ~/.ssh/config with IdentityFile.

What does -a do?

It sets how many rounds of the bcrypt key derivation function protect the private key's passphrase. More rounds make brute-forcing a stolen key file slower, at the cost of a slightly slower unlock. 100 is a sensible value; the default is 16.

What is a resident FIDO2 key?

With -O resident the key handle is stored on the security key itself, so on a new machine you can run ssh-keygen -K to download it and log in without copying any files. Without it, you need the small key handle file from the machine where you generated it, alongside the hardware.

How do I add a passphrase to a key that has none?

Run ssh-keygen -p -f ~/.ssh/id_ed25519. It asks for the old passphrase, empty in this case, and the new one, and rewrites the file in place without changing the key itself.