To use SSH key authentication on your first connection to a new DigitalOcean Droplet, add your public key to the team and select it during Droplet creation. Keep the matching private key on your own computer; it is what your SSH client uses to prove it has access.
The key must be attached as part of the new Droplet’s creation flow. If the Droplet already exists, the Control Panel does not provide a way to add the key through that same flow; you will need an existing login route or a separate recovery procedure.
Create or locate an SSH key pair
An SSH key pair consists of two related files: a public key that can be installed on the server and a private key that stays with you. If you already have a key pair that you use for servers, you may be able to use it. Before reusing it, make sure you can locate the private key and know whether it is protected by a passphrase.
If you need a pair and have Linux, macOS, or Windows Subsystem for Linux, OpenSSH includes the ssh-keygen utility. DigitalOcean’s OpenSSH guide documents generating a key and describes the default filenames: id_ed25519 for the private key and id_ed25519.pub for its public counterpart, normally under ~/.ssh. The tool may ask you to choose a filename and an optional passphrase. A passphrase adds protection if someone obtains a copy of the private-key file, though you will need to enter it or use an agent that unlocks the key when connecting.
Do not accept a prompt to overwrite a key unless you have checked what depends on the existing file. Replacing a private key can leave you unable to authenticate to machines that recognise only its matching public key. If you want a separate key for a new purpose, give it a distinct name and keep a note of which server or account it is intended for.
For Windows users who are not using Bash or WSL, DigitalOcean documents PuTTY and PuTTYgen as an alternative route. Follow the PuTTY key guide for the version and file format expected by your tools. The important outcome is still a matching public and private key: you will register the public part with DigitalOcean, and keep the private part available to your local client.
Before you move on, check that key generation completed without an error and that you know where both files were saved. A key in a downloads folder that gets cleaned up, or a private key on a computer you no longer use, can turn an otherwise successful Droplet setup into an access problem.
Identify the public and private key
The filename is a useful clue, but the .pub ending is the practical distinction in the OpenSSH default pair: id_ed25519.pub is the public key, while id_ed25519 without .pub is the private key. Open the public file with a text editor if you need to copy its contents. It is normally a single long line beginning with a key type such as ssh-ed25519, followed by encoded text and sometimes a comment.
Do not paste the file without .pub into DigitalOcean’s public-key field. It contains secret credential material, not the value the control panel is asking for. Do not send it to someone offering to “install” the key for you, or include it in a screenshot or support message. The matching public key is the part intended to be placed on the server.
If you have several keys, comments and filenames can help distinguish them, but the key’s correspondence matters more than its label. When connecting later, SSH must use the private key that matches the public key you selected for this Droplet. If you select one team key during provisioning and try a different private key from your computer, authentication will fail even if both files are valid keys.
A practical way to avoid confusion is to record a neutral description such as “home laptop, Droplet administration” alongside the filename, without copying the private-key contents into the note. You can also choose a descriptive key name when adding the public key to the team. That label is for your own identification; it does not change the key’s permissions or make a mismatched key work.
Upload the public key to your DigitalOcean team
DigitalOcean’s team key list is the place to register a public key for later selection. First switch to the team that will own the Droplet. In the Control Panel, the documented route is Settings → Security → SSH Keys → Add SSH Key. Paste the public-key text into the Public Key field, add a recognisable Key Name, and save it. DigitalOcean’s team SSH-key instructions cover this account-level step.
This registration makes the key available to choose when creating future Droplets in that team. It does not put a key on every existing Droplet, and adding it to a team does not itself grant access to machines that were already provisioned. Treat team registration and Droplet attachment as two distinct stages: register the key, then select it for the particular new Droplet.
Check that you are in the intended team before saving. A key added to a different team may not appear in the creation flow where you expect it. If your organisation has several administrators, agree on a naming convention that identifies the person or device without exposing private material. If an old device is retired, review whether its key should remain available to the team.
You can also prepare keys with doctl if you prefer a terminal workflow. DigitalOcean documents the command doctl compute ssh-key import <key-name> --public-key-file <path-to-public-key> for importing a local public-key file to the account. This is useful if you already manage Droplets from the command line, but it is still an account import, not a repair to an existing server. The Control Panel may be easier if this is your first Droplet and you want to confirm each setting visually.
| Preparation route | Where you work | What it accomplishes | Best fit |
|---|---|---|---|
| Control Panel | Browser, in the intended team | Registers a public key for selection on new Droplets | First-time or occasional setup |
doctl import |
Terminal, using a local public-key file | Registers a key in the account for creation workflows | Existing command-line workflow |
| Existing Droplet recovery | The server or a recovery environment | Updates an existing machine separately | A Droplet already created without the needed key |
The distinction in the last row matters. Neither team upload nor account import is a substitute for installing the key on an already running Droplet.
Select an SSH key during Droplet creation
Open the Droplet creation page and work through the normal image, region, and size choices for your workload. When you reach Choose Authentication Method, select SSH key. The creation page should then let you choose a key already registered to the team, or use Add SSH Key to add a public key in that flow. Attach at least one key before creating the Droplet.
DigitalOcean recommends SSH keys for Droplet login rather than password-based authentication; its recommended Droplet setup documentation explains the choice. For this guide, the important operational point is not merely selecting the SSH-key option. You must also select or add the actual public key that corresponds to the private key you hold. Check the displayed key name before proceeding, especially if the team list contains multiple keys.
If you have just uploaded a team key and cannot find it, confirm the active team and whether the upload was saved. You can use the creation page’s add-key option to provide the public-key text, but do not respond to a missing key by pasting in a private-key file. If you are unsure which of several entries matches your computer, pause and verify the key pair rather than creating a server whose first login you cannot make.
Once the Droplet is created, DigitalOcean places the selected public key in the setup for that new machine. This is why the creation step is the useful moment to attach it: you can then attempt key authentication as soon as the machine is ready, without first relying on a password login to install a key. The selected identity must still match the private key on the computer from which you connect.
Keep the private key on your computer
The private key is a credential. Keep it on a device and in a location you control, restrict access to the account that needs it, and do not upload it to the team, send it to another person, or paste it into a web form. The server needs the public half; your SSH client uses the private half locally.
A passphrase can add a further barrier if the private-key file is copied or exposed. DigitalOcean recommends considering a passphrase in its OpenSSH guidance. The trade-off is that you may be asked to unlock the key during use. If you use a password manager or an SSH agent to make that easier, understand how it stores or holds the unlocked credential and protect that account as well.
Think about recovery before the original computer fails. Keep a protected backup only if your own security process supports it, and know how you would remove or replace the corresponding public key if the device is lost. A backup is not a reason to leave an unencrypted private key in shared storage. For a small business or a devotional channel team, separate keys for people who need access can make it easier to remove one person’s access later without changing everyone else’s setup.
Do not assume that the key filename alone is a backup. If the only copy of the private key is lost, the public key on the Droplet cannot recreate it. Likewise, generating a new pair on another computer does not make that new private key equivalent to the one attached at creation. Plan to install the new public key through a working access route before retiring the old one.
Connect to the new Droplet
Wait until the Droplet is ready and note its public IP address from the Control Panel. From a terminal with OpenSSH, a basic connection has this form: ssh username@droplet_ip. Replace the placeholders with the login user appropriate to the image and the Droplet’s address. If your private key is not at the client’s default location, specify it with -i, for example ssh -i ~/.ssh/my_droplet_key username@droplet_ip.
The first connection may ask you to confirm the server’s host key. This is separate from your own SSH key pair: the server host key helps your client recognise the server on later connections. Read the prompt and follow your organisation’s process for verifying the host identity rather than treating every prompt as an obstacle to dismiss. If the connection reports that the server refused your key, check the login username, the private-key path, and whether the selected public key is the one paired with that private key.
On Windows, use the SSH client and key format corresponding to the method you chose. A Windows installation with OpenSSH can use the same terminal pattern; PuTTY users should follow DigitalOcean’s PuTTY instructions for loading the private key and connecting. Avoid converting or moving keys casually while troubleshooting. First establish which public key was attached, then confirm you are presenting its matching private half.
If you are setting up this machine to support a YouTube channel, SSH setup is only server access; it does not configure the broadcast itself. Keep the operational questions separate: for instance, a guide to running a 24/7 YouTube stream without keeping a laptop open covers a different decision from securing a Droplet login. If the plan is a video loop rather than a general-purpose server, compare the workflow with software for rotating videos on a 24/7 YouTube stream before building unrelated server tasks into the SSH setup.
If you created the Droplet without a key
A public key added to the team after creation does not attach itself to an existing Droplet. DigitalOcean states that the Control Panel cannot add or modify a Droplet’s SSH keys after creation. Do not go back to the create page expecting it to amend the already provisioned machine; that page applies when making a new Droplet.
If you still have a working login to the machine, use that access to install the new public key for the relevant user in ~/.ssh/authorized_keys. DigitalOcean’s existing Droplet key guide explains the server-side method, including the restrictive permissions expected for the .ssh directory and authorized_keys file. The public-key line belongs in that file, not the private-key contents. Verify that key login works in a second session before closing the original session, so a mistake does not remove your only route back in.
If there is no working SSH session, check whether another administrator still has access, whether you have a suitable console or recovery route, and whether the provider’s current recovery guidance fits the Droplet’s state. Recovery differs from attaching a key at creation: it may involve console access, boot or recovery procedures, or rebuilding the machine, and should be chosen with data and service interruption in mind. Consult DigitalOcean’s current instructions rather than assuming a particular recovery option is available for every configuration.
For a disposable test machine with no important data, recreating it with the key selected at provisioning may be simpler than recovering access. For a production service or a machine holding data, do not delete it merely to repeat setup. First establish whether you can restore access or preserve the data, then decide whether a rebuild is acceptable. A server used as part of a YouTube workflow may also have service-specific recovery concerns; the playlist-change guide for a running 24/7 stream illustrates why changing a live operation and changing its underlying access are separate tasks.
The main lesson is to treat team registration, Droplet creation, and existing-server recovery as separate operations. A key added to the team is ready to select on a new Droplet; a key omitted during creation must be installed through a working server-side or recovery route.
Before committing, compare the operating options on the pricing page. When the file and channel are ready, start free — 24-hour trial, no card.
FAQ
Can I add an SSH key after creating a Droplet?
Not through the Droplet creation page or by merely adding the key to your DigitalOcean team. If you can log in already, install the public key on the server; otherwise use an appropriate recovery route and check DigitalOcean’s current instructions.
Which key do I paste into DigitalOcean?
Paste the public key, usually the text in the .pub file for an OpenSSH pair. Keep the corresponding private key on your computer and never put its contents in the public-key field.
Can I use one key for several Droplets?
A registered team key can be selected for more than one new Droplet, if that is appropriate for your access practices. Separate keys can make it easier to revoke access for a particular person or device without changing every user’s credentials.
Does importing a key with doctl add it to an existing Droplet?
No. DigitalOcean’s doctl import workflow registers the key for account use when creating Droplets. An existing machine requires a separate server-side update or recovery procedure.