# Git SSH Authentication: Set Up Keys Instead of Passwords

> Set up SSH key authentication for Git remotes on GitHub, BitBucket, and GitLab, with passphrase management and sshpass for non-interactive scripts

**URL:** https://sentry.io/answers/provide-a-username-and-password-for-git-operation-over-ssh/

---

## The Problem

When cloning, pulling, or fetching from an HTTPS Git remote, I can provide a username and password in the URL as follows:

```
https://username:password@host.com/owner/repository.git
```

This prevents Git from prompting for the username and password, which is useful for scripts.

However, I do not know how to do this for Git SSH remotes, i.e. remotes with URLs like this:

```
git@host.com:owner/repository.git
```

How can I include authentication details in a remote URL of this type?

## The Solution

The username and authentication method used for an SSH Git remote will depend on the remote system's SSH configuration. The username is already specified in the URL, before the `@` sign. In many cases, password authentication will be disabled in favor of public-private key authentication. This is the case with most cloud Git hosts such as GitHub, BitBucket, and GitLab. It is not possible to use your account's username and password over SSH with these services. Instead, you must use SSH keys for authentication. Platform-specific instructions are linked below:

* [Add an SSH key on GitHub](https://docs.github.com/en/authentication/connecting-to-github-with-ssh/adding-a-new-ssh-key-to-your-github-account).
* [Add an SSH key on BitBucket](https://support.atlassian.com/bitbucket-cloud/docs/set-up-personal-ssh-keys-on-linux/).
* [Add an SSH key on GitLab](https://docs.gitlab.com/user/ssh/).

Once you've configured SSH authentication, you will be able to clone, pull, and fetch from any Git repositories you have access to over SSH URLs, without specifying a username or password.

When setting up an SSH key, it is possible to specify a passphrase, which is used to encrypt the private key on the local system. If a passphrase is configured, it will need to be entered whenever SSH is used. To avoid this, we can remove the passphrase by entering the following command:

```bash
ssh-keygen -p
```

When prompted, leave the keyfile location as the default setting, enter the old passphrase, and leave the new passphrase blank.

Alternatively, [`sshpass`](https://www.redhat.com/en/blog/ssh-automation-sshpass) can be used to submit the passphrase to SSH non-interactively. It is available from the software repositories of Linux distributions.

`sshpass` can be used with a `git clone` command as follows:

```bash
sshpass -p passphrase git clone git@host.com:owner/repository.git
```

The same will work for `git pull` and `git fetch`.

In the event that the host of the Git remote supports password authentication, `sshpass` can be used in the same way, but specifying the system password instead of the SSH key passphrase. Note that this is considered highly insecure and SSH key authentication should be used instead wherever possible.

---

*Source: [sentry.io/answers/provide-a-username-and-password-for-git-operation-over-ssh/](https://sentry.io/answers/provide-a-username-and-password-for-git-operation-over-ssh/)*
