SSH keys are stronger than passwords, can be revoked for one person without disturbing anyone else, and suit shared service accounts.
Luumen does not generate keys. You create them on your own machine and either point Luumen at the key already there or upload the private half.
Two Ways to Use a Key
Local SSH Keychain. Luumen uses a key already on your computer through your SSH agent, and the key never leaves your machine. This is the simplest option when you are the only person who needs the access. It applies to personal credentials only, because nothing is stored that could be shared.
Upload Private Key. The key is encrypted and stored in your workspace, so it works from any machine you sign in on and can be shared with your team as a workspace credential. Use this for a service account several people rely on.
Supported Key Formats
Luumen accepts a private key in PEM or OpenSSH format, which covers the keys ssh-keygen produces on every current platform. The file may begin with any of these headers:
-----BEGIN OPENSSH PRIVATE KEY-----(the default from modernssh-keygen, including Ed25519)-----BEGIN RSA PRIVATE KEY----------BEGIN EC PRIVATE KEY----------BEGIN PRIVATE KEY-----(PKCS#8)-----BEGIN DSA PRIVATE KEY-----
Luumen rejects, and tells you which: a public key (anything starting ssh-rsa, ssh-ed25519, ecdsa-sha2-, or -----BEGIN PUBLIC KEY-----), a PGP key, a key with no END marker, and a PuTTY .ppk file. Convert a .ppk with PuTTYgen's Conversions > Export OpenSSH key before uploading.
Use a key without a passphrase for credentials you upload. Passphrase-protected keys are not fully supported for uploaded credentials, and a key that works elsewhere may fail to authenticate here. A passphrase-protected key that lives in your local SSH agent is fine through Local SSH Keychain, because the agent handles the passphrase.
Generate a Key
On macOS, Linux, or Windows PowerShell, run:
ssh-keygen -t ed25519 -C "[email protected]"
Accept the default location and press Enter twice for no passphrase if the key is going to be uploaded. This produces two files. The one without an extension is your private key, which you give to Luumen and never share. The .pub file is your public key, which goes on your servers. Ed25519 is recommended for new keys; RSA (2048 bits or more) and ECDSA also work.
Put the Public Key on Your Hosts
The host needs your public key in ~/.ssh/authorized_keys for the account you connect as. The quickest way from a machine that can already reach the host is ssh-copy-id user@host. At scale, use your configuration management tool or inject the key at instance creation.
Add the Key to Luumen
Open Credentials, click Add credential, give it a name and the username on the target host, choose Upload Private Key, then paste the key into the Private Key box or use Upload Key File. Save and click Test now.
If the Test Fails
The matching public key is not in
authorized_keyson the host.The username is not an account on that host.
Permissions are too open.
~/.sshshould be 700 andauthorized_keys600, and the account's home directory must not be group-writable.The host's
sshdhasPubkeyAuthentication no, or restricts key types.The uploaded key has a passphrase.

