> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.co.in/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/docs/_mcp/server.

# SSH Keys

> Create or import SSH keys in an IBEE Solutions workspace so you can log in to your VMs without a password.

SSH keys let you log in to your VMs securely without a password. Save a key once in a workspace, then select it when you deploy a VM in that workspace — the public key is added to the VM at first boot.

SSH keys belong to a **workspace**. A key saved in one workspace is not available in another; save it in each workspace where you deploy VMs.

## Before you begin

* A workspace in an active organization ([Create an organization](/docs/getting-started/account-setup/create-an-organization))
* Write access to the workspace — members with read-only access can view keys but cannot add or delete them

## Open SSH Keys

In the portal sidebar, click **SSH Keys** under **Tools**. The page lists the keys saved in the current workspace.

You have two ways to add a key:

| Option              | Use it when                                                                                         |
| ------------------- | --------------------------------------------------------------------------------------------------- |
| **Create Key Pair** | You don't have a key yet. IBEE generates a new key pair and your browser downloads the private key. |
| **Import Key**      | You already have a key pair on your computer and want to add its public key.                        |

## Create a key pair

### Start

On **SSH Keys**, click **Create Key Pair**.

### Name the key

Enter a **Key Pair Name** (for example `my-laptop-key`) and, optionally, a **Description**. Names must be unique within the workspace.

### Create and download

Click **Create & Download**. Your browser downloads the private key as a `.pem` file named after the key.

> **Warning**
>
> The private key is downloaded **only once**. IBEE stores only the public key and cannot show or re-send the private key. Keep the `.pem` file safe — if you lose it, create a new key pair.

Before using the downloaded key, restrict its permissions:

```bash
chmod 600 ~/Downloads/my-laptop-key.pem
```

## Import an existing public key

If you don't have a key pair yet and prefer to create one locally, generate it first:

```bash
# ed25519 (recommended)
ssh-keygen -t ed25519 -C "your-email@example.com"

# or RSA
ssh-keygen -t rsa -b 4096 -C "your-email@example.com"
```

Your public key is at `~/.ssh/id_ed25519.pub` (or `~/.ssh/id_rsa.pub`).

### Start

On **SSH Keys**, click **Import Key**.

### Name the key

Enter a **Key Pair Name** and, optionally, a **Description**.

### Add the public key

Paste the key into **Public Key**, or click **Choose public key file** to upload it. The portal accepts a one-line OpenSSH public key (such as `ssh-ed25519 …`, `ssh-rsa …`, or `ecdsa-sha2-nistp256 …`) or a PEM file containing a public key. Files must be smaller than 64 KB.

### Import

Click **Import Key**. The key appears in the list.

## SSH keys list

| Column          | Description                                       |
| --------------- | ------------------------------------------------- |
| **Name**        | Key name                                          |
| **Key Type**    | Algorithm, for example `ssh-ed25519` or `ssh-rsa` |
| **Fingerprint** | Fingerprint for verifying the key                 |
| **Created At**  | Date the key was added                            |
| **Actions**     | **View** · **Delete**                             |

Click **View** to open **SSH Key Details**, where you can copy the fingerprint and the full public key.

## Delete a key

Click **Delete** in the **Actions** column, then **Delete Key** to confirm.

Deleting a key removes it from the workspace, so it can no longer be selected for new VMs. The portal warns that servers using the key will stop accepting it. To be certain access is revoked on a running VM, remove the key from the VM under **Settings → Access**, or delete it from `~/.ssh/authorized_keys` on the VM.

## Use a key when deploying a VM

In the VM deploy form, select one or more saved keys in the **SSH Keys** section, or click **Add Key** to create or import one without leaving the form. The SSH Keys section is not shown for Windows images. See [Create a VM](/docs/infrastructure/cloud-vms/create-a-vm).

To add or remove keys on a VM that is already running, open the VM and go to **Settings → Access**.

## Connect to a VM

Find the VM's IP address and login user under **Overview → Connection Details**, then connect with the matching private key:

```bash
# Key pair created in the portal
ssh -i ~/Downloads/my-laptop-key.pem <user>@<vm-ip>

# Imported key
ssh -i ~/.ssh/id_ed25519 <user>@<vm-ip>
```

## Troubleshooting

**"Private key files cannot be imported."**
You pasted or uploaded the private key. Import the **public** key instead — the `.pub` file, or a PEM file that contains `PUBLIC KEY`.

**"A key with this name already exists."**
Key names must be unique in the workspace. Choose a different name.

**I can't see my key when deploying a VM.**
Keys belong to a workspace. Check that you are deploying in the same workspace where the key is saved, or import the key into this workspace.

**Permission denied (publickey) when connecting**

* Check that you are using the private key that matches a key selected for the VM, with `-i`.
* Check the login user shown under **Overview → Connection Details**.
* If you used a downloaded `.pem` file, run `chmod 600` on it.
* Make sure the VM is running and its firewall group allows SSH (TCP 22) from your IP address.

**The `.pem` file didn't download or was lost.**
The private key can't be downloaded again. Delete the key and create a new key pair, then add the new key to your VMs under **Settings → Access**.

## Related pages

* [Create a VM](/docs/infrastructure/cloud-vms/create-a-vm)
* [Launch your first VM](/docs/infrastructure/cloud-vms/launch-your-first-vm)
* [API Tokens](/docs/tools/api-tokens)