Skip to main content
You can use 1Password to generate an SSH key and autofill your public key to your favorite Git platform. Then, set up the 1Password SSH Agent and configure your SSH or Git client so you can use the SSH agent to authenticate your Git and SSH workflow. The following examples use GitHub to illustrate the SSH workflow from start to finish, but you can modify the steps to use with your favorite Git or cloud platform.

Requirements

For the best experience when using the 1Password SSH Agent, you can configure Touch ID, Apple Watch, Windows Hello, or system authentication to unlock 1Password and authenticate SSH key requests.

Step 1: Generate an SSH key

  1. Open and unlock the 1Password app, then navigate to your Personal, Private, or Employee vault. The name of this vault varies depending on your account type.
  2. Select New Item > SSH Key.
  3. Select Add Private Key > Generate New Key.
  4. Select an SSH key type: Ed25519 or RSA, then select Generate.
  5. When you’re done, select Save.
1Password will generate your SSH key, which includes the private key, public key, and its fingerprint.
Learn more about generating or importing SSH keys and which SSH keys you can use with the 1Password SSH Agent.

Step 2: Upload your public key

After you generate your SSH key, you can add the public key to your GitHub account. Visit the GitHub SSH key settings page upload your public key using the 1Password browser extension or desktop app.
  1. Select the Title or Key field on the GitHub settings page. If 1Password doesn’t show a list of suggested items, select the 1Password icon in the field.
  2. Select the GitHub SSH key you just created. 1Password will automatically fill the public key and title in the corresponding fields.
  3. Select Add SSH Key on the settings page to save the key in your GitHub account.

Your SSH key can now be used to authenticate with GitHub.

For examples using other Git or cloud platforms, see Autofill public keys.

Step 3: Turn on the 1Password SSH Agent

The 1Password desktop app includes an SSH agent that, when turned on, runs in the background to handle authentication for your SSH clients. Follow these steps to turn on the SSH agent:
  1. Open the 1Password app and select 1Password > Settings from the menu bar, then select Developer.
  2. Select Use the SSH Agent, then choose whether you want to display SSH key names when you authorize connections.
  3. (Optional) Adjust your authorization settings for when and how often the SSH agent will ask you to approve SSH requests.
If you previously turned off the SSH agent and would like to turn it back on, select the checkbox to Use the SSH agent.When you choose to display SSH key names when authorizing connections, it’s easier for you to identify which key 1Password is requesting access to when authenticating a request from an SSH client. To display key names in authorization prompts, 1Password needs to save the titles of your SSH Key items in local storage. To turn off this feature, deselect the checkbox to Display key names when authorizing connections in the Security section.To make sure the SSH agent keeps running, even when the 1Password app is closed:
  1. Open the 1Password app and select 1Password > Settings from the menu bar, then select General.
  2. Select the checkboxes to Keep 1Password in the menu bar and Start at login.

Step 4: Configure your SSH or Git client

After you turn on the SSH agent in 1Password, you’ll need to configure your SSH client to use the agent for authentication.
Add the IdentityAgent snippet to your ~/.ssh/config file:
If your ~/.ssh folder or config file doesn’t exist yet, create it first.You can also set the SSH_AUTH_SOCK environment variable in the shell where your SSH command runs:
For an agent path that’s easier to type, you can optionally run the following command to create a symlink for ~/.1password/agent.sock:
Now your SSH clients will use the 1Password SSH Agent for all hosts.If you prefer to migrate to the 1Password SSH Agent gradually, you can configure your SSH clients to only use the SSH agent for one or more specific hosts, instead of all hosts. Learn more about gradual migration.Some SSH clients don’t support every configuration option that the ~/.ssh/config file has to offer. Learn more about SSH client compatibility.By default, OpenSSH servers are configured to limit the amount of authentication attempts for an incoming SSH connection. Learn more about how to avoid the SSH server six-key limit.

Step 5: Run a command

Now you’re ready to start using the 1Password SSH Agent with GitHub. From your project directory, run:
If you don’t have a project available on GitHub where you can run git pull now, you can run this command instead to quickly test your GitHub SSH setup:

Step 6: Authorize the SSH request

1Password will ask you to allow your terminal or other SSH client to use your SSH key. You can approve this request using the authentication option indicated on the prompt (for example, Touch ID, Windows Hello, or your account password). If 1Password is locked, you’ll also be prompted to unlock the app so the SSH agent can access your private keys.
After approving the request, you can continue using the same SSH key for that application without being prompted again until 1Password locks or quits. You can also adjust your authorization settings to prompt more or less frequently. To learn more about the authorization process and how to adjust when 1Password asks you to approve SSH requests, see Authorize SSH requests with 1Password.

Learn more