# Connecting over SSH

Your VPS Pro opens with your **SSH key**: a pair of files created on your computer, whose **public** part you add in your client area. The **private** part stays on your computer and is shared with no one, our team included.

## Creating your key

On macOS, Linux and Windows 10 or 11 (PowerShell or the Terminal), a single command:

```
ssh-keygen -t ed25519
```

Accept the suggested location, and choose a passphrase to protect the key. Two files appear in the `.ssh` folder of your account:

* `id_ed25519`: your **private** key, which stays with you;
* `id_ed25519.pub`: your **public** key, the one you add. It fits on one line that starts with `ssh-ed25519`.

To display the public key and copy it:

```
cat ~/.ssh/id_ed25519.pub
```

## Adding your key in the client area

1. Open [my.simafri.com](https://my.simafri.com/), **VPS** section.
2. In your server's card, paste your public key into **Your public keys, one per line**.
3. Click **Save the keys**.

Your key is installed on the server within a minute, and the card shows it: **Keys installed on the server on** followed by the date, with the fingerprint of each key (`SHA256:...`, the same one that `ssh-keygen -lf ~/.ssh/id_ed25519.pub` displays). Added while the server is being prepared, the key is installed when it is created.

Good to know:

* up to **10 keys** per server, one per person or per computer;
* accepted types: **ed25519**, **RSA** of at least 2048 bits, **ECDSA**, and hardware security keys (`sk-ssh-ed25519`, `sk-ecdsa`); the PuTTYgen format is accepted too;
* each save **replaces** the whole set of keys added: paste all the ones you want to keep;
* the account owner and **managers** add the keys; an **operator** views them (see [Members and roles](https://docs.simafri.com/en/espace-client/membres-et-roles/)).

The keys added from the client area occupy their own block of the `/root/.ssh/authorized_keys` file, between two `my.simafri.com` marker lines. The rest of the file belongs to you: a key you add there yourself, outside this block, stays in place.

## Connecting

Your server's card shows the **SSH connection** command, ready to copy:

```
ssh -p 22101 root@203.0.113.10
```

The port, between 22100 and 22999, is specific to your server: use the one from your card. Your server's name also works in place of the address:

```
ssh -p 22101 root@app.my-company.com
```

For a server whose name is under your own domain, this name answers as soon as your DNS record points to your server (see [Putting a site or an application online](/en/vps-pro/mettre-en-ligne.md)).

### Over IPv6

If your Internet connection has IPv6, you can also reach your server directly at its IPv6 address, shown in the card, on the usual SSH port:

```
ssh root@2001:db8::101
```

### A shortcut: the \~/.ssh/config file

So that you no longer retype the port and the address, add a block to your `~/.ssh/config` file:

```
Host myvps

    HostName app.my-company.com

    Port 22101

    User root

    IdentityFile ~/.ssh/id_ed25519
```

Then `ssh myvps` is enough, and the same shortcut works for `scp`, `rsync`, `git` and your editor.

## From Windows

Windows 10 and 11 include the OpenSSH client: open PowerShell or the Terminal and paste the command from your card. Your shortcuts file is at `C:\Users\<your name>\.ssh\config`.

With **PuTTY**, enter the address and the port from your card in **Session**, the user `root` in **Connection > Data**, and your private key in `.ppk` format in **Connection > SSH > Auth > Credentials**. The public key shown by PuTTYgen is added as it is in your client area.

## Transferring files

With the same port and the same key:

```
# a file, to the server

scp -P 22101 archive.tar.gz root@app.my-company.com:/srv/



# a folder, synchronised

rsync -avz -e "ssh -p 22101" ./build/ root@app.my-company.com:/var/www/app/
```

`scp` takes the port with a **capital P**. SFTP software such as FileZilla or WinSCP connects over **SFTP**, with the address, the port and the private key on your computer.

## Working from your editor

The **Remote - SSH** extension for Visual Studio Code opens your server's folders as if they were on your computer: it reads your `~/.ssh/config` file, so you simply choose `myvps`. JetBrains editors offer the same connection through **Remote Development**.

## Giving a colleague access

Two ways to do it, depending on what you want to entrust to them:

* **administrator access**: add their public key next to yours in **Your public keys, one per line**, then **Save the keys**;
* **limited access**: create an account for them on the server, with their own key:

```
adduser camille

mkdir -p /home/camille/.ssh

nano /home/camille/.ssh/authorized_keys   # paste their public key

chown -R camille:camille /home/camille/.ssh

chmod 700 /home/camille/.ssh && chmod 600 /home/camille/.ssh/authorized_keys
```

To remove an access, save the list of keys without theirs, or delete their account with `deluser camille`.

## Replacing a lost key

Your computer has changed or your private key has gone: create a new key with `ssh-keygen -t ed25519`, then add the new public key in your card, removing the old one. It is installed within a minute, and you regain access to your server.

## Your AI assistant

An AI assistant connected to your Simafri client area (MCP server `https://mcp.simafri.com/v1/mcp`) reads your servers, their status, their addresses and their connection command, and adds your **public** keys for you, with the rights of the person signed in. A private key is refused there, just as in the client area.

## Frequently asked questions

### "Permission denied (publickey)": what should I check?[​](#permission-denied-publickey-what-should-i-check "Direct link to \"Permission denied (publickey)\": what should I check?")

1. Your server's card shows **Keys installed on the server on** followed by a date.
2. The fingerprint shown in the card is that of your key: `ssh-keygen -lf ~/.ssh/id_ed25519.pub`.
3. Your command uses the port from your card, and the user `root`.
4. If your key has another name, specify it: `ssh -i ~/.ssh/my_key -p 22101 root@...`.

Then describe the situation to support, with the command you ran and the message you got: Full-Stack Assistance helps you restore access.

### My connection drops when I stay idle.

Add `ServerAliveInterval 60` to your block in `~/.ssh/config`: your computer keeps the connection alive. For a long command, run it in `tmux` or `screen`, which keep it alive even when you are disconnected.

### The client area says "This text contains a PRIVATE key".[​](#the-client-area-says-this-text-contains-a-private-key "Direct link to The client area says \"This text contains a PRIVATE key\".")

You pasted the file without `.pub`. Paste the content of the file ending in `.pub`. If your private key was sent to someone by mistake, create a new one and add its public key.

### Can I connect with a password?

Your server opens with an SSH key, the safest method: a key cannot be guessed and never travels. Add one key per person, and each person keeps their own access.
