> ## Documentation Index
> Fetch the complete documentation index at: https://docs.acasia.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SSH Keys

> Create, review, and delete the public keys authorized to reach your clusters.

![SSH Keys page showing a default-keys info banner, an Add New Key button, and a table of four registered SSH keys.](https://docs.acasia.com/assets/settings-ssh-keys-CzT1nxQd.png)

Keys registered here can be attached to clusters. When you attach a public key to a cluster, the cluster accepts SSH connections authenticated with the corresponding private key on your local machine.

## Default key behavior

Acasia may apply a **default SSH key** to new clusters automatically. The info banner on the SSH Keys page indicates when a default key is configured for your organization.

If a default key is set:

* New clusters automatically receive that key
* You can still attach additional keys to individual clusters

## SSH key table fields

| Field      | Description                      |
| ---------- | -------------------------------- |
| Name       | Label you assigned to the key    |
| Public Key | Truncated public key value       |
| Added      | Date the key was registered      |
| Actions    | Remove the key from your account |

## Adding an SSH key

<Steps>
  <Step title="Generate a key pair locally">
    If you do not already have an SSH key pair, generate one:

    ```bash theme={null}
    ssh-keygen -t ed25519 -C "your-email@example.com"
    ```
  </Step>

  <Step title="Copy your public key">
    ```bash theme={null}
    cat ~/.ssh/id_ed25519.pub
    ```

    Copy the full output — it starts with `ssh-ed25519` or `ssh-rsa`.
  </Step>

  <Step title="Click Add New Key">
    Enter a descriptive name and paste your public key.
  </Step>

  <Step title="Save">
    The key appears in your SSH Keys table and can be attached to clusters.
  </Step>
</Steps>

<Warning>
  Only upload **public keys** (the `.pub` file). Never upload your private key to Acasia or any other service. Your private key must remain on your local machine or in an approved secret-management system.
</Warning>

## Removing an SSH key

Select **Remove** from the key's Actions menu. Removing a key from Settings does not immediately revoke access to clusters it is already attached to — remove the key from the cluster directly if you need to revoke access immediately.

## Security guidance

* Use separate SSH keys for different machines, environments, or team members
* Rotate SSH keys when a team member with key access leaves
* Do not share SSH private keys — each user should have their own key pair
* Use `ed25519` keys where possible — they are more secure and faster than `rsa`
