Agentic Research

Private key

Also: 私鑰 · 私密金鑰 · private key · 金鑰對 · key pair

The half of a key pair that must never leave you: it stays on your machine to prove "I am who I claim", while the matching public key can be shared openly.

When you will meet it

Passwordless SSH login, git pushes and transaction signing all rely on it. The core rule is "the private key never leaves": what you hand over or upload to a server is always the matching public key. If the private key leaks, someone can fully impersonate you, and it cannot be undone after the fact.

An analogy

The public key is a padlock you hang outside — anyone can use it to lock something and send it to you. The private key is the one key you hold that opens it. You can plaster photos of the lock all over the internet, but if the key is copied, every one of those locks becomes worthless.

Minimal example

ssh-keygen -t ed25519 -C "you@example.com"
# 產生一對金鑰:
#   ~/.ssh/id_ed25519       私鑰,留在本機、絕不外傳,權限要設 600
#   ~/.ssh/id_ed25519.pub   公鑰,這個才可以貼到 GitHub/伺服器

cat ~/.ssh/id_ed25519.pub   # 看公鑰(可公開)
# 千萬別 cat 私鑰再貼給別人或截圖

Remember the extension: the file ending in .pub is the public key (shareable); the one without .pub is the private key (never share). When handing a key to GitHub or a remote server, you always paste the .pub one. If the private key's permissions are too loose (e.g. 644), ssh refuses to use it — and the error rarely says so clearly.

What people get wrong

  • Pasting the private key to someone, uploading it to a site, or committing it to git. You always give the public key. Once a private key leaves your machine it counts as leaked: you must revoke the whole pair and regenerate — there is no "just change a password" recovery.
  • Assuming "a passphrase on the private key means you can store it anywhere". A passphrase is only an extra layer; the private key file itself must still never leak. If someone takes the file and guesses the passphrase, it is game over.

Related terms

Next