Linux ssh-copy-id Command: Install a Public Key on a Remote Account
ssh-copy-id prepares public key login by adding the local SSH public key to the authorized_keys of the remote account. It is not a command to copy the private key to the server.
What is the ssh-copy-id command?
First, you must be able to access the target account via password login or another authentication method. By specifying the public key file to register with -i, the chance of selecting the wrong key among multiple local keys is reduced. The tool attempts an SSH connection to check whether the key is already registered, and its behavior may vary depending on server policies.
Basic syntax
ssh-copy-id [options] [user@]host
Installed implementations and options may vary by distribution. Check the description on your current system with man ssh-copy-id.
Examples
Checking the public key to register
Check the.pub at the end of the file and review the fingerprint.
ssh-keygen -lf ~/.ssh/id_ed25519_work.pub
Preview before actual registration
Verify the key to be copied in supported implementations. No changes are made to the remote server.
ssh-copy-id -n -i ~/.ssh/id_ed25519_work.pub alice@server.example.com
Public Key Registration
After verifying the remote host key, add the public key to the corresponding account.
ssh-copy-id -i ~/.ssh/id_ed25519_work.pub alice@server.example.com
Check after registering the public key
ssh-copy-id adds your local public key to the list of authorized keys on the remote account. You must be able to connect to the remote account first and have the necessary permissions for that account.
ssh-copy-id -i ~/.ssh/id_ed25519_work.pub user@server.example.test
Output that may appear when registration succeeds:
Number of key(s) added: 1
After registration, check whether the actual public key authentication works with ssh -i ~/.ssh/id_ed25519_work user@server.example.test. Do not assume it is safe to disable password login based solely on a success message. You should first confirm other administrator accounts and emergency access routes.
Main Options and Format
| Options/Format | Description |
|---|---|
-i public_key_file |
Explicitly select the public key to register. |
-n |
Show the operations to be performed without actually registering. |
-p port |
Specify the port of the remote SSH server. |
-s |
Use the SFTP transfer method on supported implementations. |
-f |
You can forcibly add without checking for already registered keys, so be careful about duplicates. |
Precautions when using
Do not ignore host key warnings. Do not disable existing password authentication until you verify that you can log in from a new terminal with ssh -i ~/.ssh/id_ed25519_work alice@server.example.com after registration. To remove a registered public key, back up and delete exactly the corresponding line in ~/.ssh/authorized_keys of the remote account, preserving other keys.
Frequently Asked Questions
Why does it ask for a password even after running ssh-copy-id?
Existing authentication may be required during the first registration. If it continues to ask even after registration, check the selected private key, the permissions of the server's authorized_keys, and the SSH server settings.
Official Documentation
You can check the exact behavior of the options and implementation differences in the official ssh-copy-id documentation.









