CodeBrowser

SSH Config Generator

Stop typing long ssh commands. Fill in your servers once and get a ready-to-use ~/.ssh/config file, so ssh myserver just works, with the right user, port, key and jump host every time.

Multiple hostsJump hosts & port forwardsCopy or downloadRuns in your browser

Settings for all hosts (Host *)

Then connect with ssh myserver

The basics

What is the SSH config file?

The SSH config file is a plain text file where OpenSSH looks up connection settings. Each Host block gives a server a short name and lists how to reach it. Instead of typing ssh -i ~/.ssh/id_ed25519 -p 2222 deploy@203.0.113.10, you type ssh myserver.

The same names work with scp, sftp, rsync, Git and VS Code Remote-SSH, because they all read the same file. New to SSH? Start with how to SSH into a server.

Where is the SSH config file?

  • macOS and Linux: ~/.ssh/config
  • Windows: C:\Users\YourName\.ssh\config
  • System-wide: /etc/ssh/ssh_config (your own file takes priority)

The file has no extension. If it doesn’t exist yet, create it. On macOS and Linux, make it private with chmod 600 ~/.ssh/config, or SSH may refuse to use it.

Reference

Most useful SSH config options

OptionWhat it doesExample
HostThe short name you type after ssh. Can include wildcards like *.example.com.Host web
HostNameThe real IP address or domain to connect to.HostName 203.0.113.10
UserThe username to log in as.User deploy
PortThe SSH port, if it isn’t 22.Port 2222
IdentityFileThe private key to use.IdentityFile ~/.ssh/id_ed25519
IdentitiesOnlyOnly try the key above, not every key in your agent. Avoids “Too many authentication failures.”IdentitiesOnly yes
ProxyJumpConnect through a bastion or jump host first.ProxyJump user@bastion
LocalForwardOpen an SSH tunnel every time you connect.LocalForward 5433 localhost:5432
ServerAliveIntervalSend a keep-alive every N seconds so idle sessions don’t drop.ServerAliveInterval 60
ForwardAgentLet the server use your local SSH agent. Only enable it for servers you trust.ForwardAgent yes

Examples

SSH config examples

Two GitHub accounts on one computer

Host github-personal
    HostName github.com
    User git
    IdentityFile ~/.ssh/id_ed25519_personal
    IdentitiesOnly yes

Host github-work
    HostName github.com
    User git
    IdentityFile ~/.ssh/id_ed25519_work
    IdentitiesOnly yes

Then clone with git clone git@github-work:company/repo.git, and Git uses your work key.

A private server behind a jump host

Host bastion
    HostName bastion.example.com
    User admin

Host app
    HostName 10.0.1.25
    User deploy
    ProxyJump bastion

Now ssh app hops through the bastion automatically, and scp file.txt app: works too.

Tips

How SSH reads your config

  • First match wins. For each option, SSH uses the first value it finds, reading from top to bottom. Put specific hosts first and Host * defaults last.
  • Indentation is optional. Everything after a Host line belongs to it until the next Host or Match line. Indenting just makes it easier to read.
  • Command-line options win. Anything you pass on the command line, like -p 2200, overrides the config file.

Check what SSH will actually use

Print the final settings for a host without connecting:

ssh -G myserver

If a connection still fails, add -v to see each step, including which config lines and keys were used:

ssh -v myserver

FAQ

SSH config questions, answered

Does the SSH config file work on Windows?

Yes. The OpenSSH client built into Windows 10 and 11 reads C:\Users\YourName\.ssh\config, and so do Git for Windows and VS Code Remote-SSH. PuTTY does not read it; it uses its own saved sessions instead.

Why is SSH ignoring my config file?

Check that the file is named exactly config with no .txt extension, that it is inside your .ssh folder, and on macOS or Linux that its permissions are 600. Then run ssh -G yourhost to see which values SSH is actually using.

What does Host * do?

Host * matches every server, so it is the place for defaults like keep-alive settings. Because SSH uses the first value it finds, put Host * at the bottom of the file so your specific hosts can override it.

What is the difference between Host and HostName?

Host is the nickname you type, such as ssh web. HostName is the real address SSH connects to, such as 203.0.113.10 or web.example.com.

How do I fix Too many authentication failures?

SSH tries every key in your agent and the server gives up after a few. Add IdentityFile pointing to the right key and IdentitiesOnly yes to that host, and SSH will only offer that one key.

Is it safe to use ForwardAgent?

Only on servers you trust. While you are connected, anyone with root access on that server can use your forwarded agent to log in elsewhere as you. ProxyJump is a safer way to reach servers behind a jump host.

Need a key for your IdentityFile?

Create an Ed25519 or RSA key pair in your browser and point your new config at it.

Open the SSH Key Generator