Create your SSH keypair
An SSH keypair lets you sign in using a key kept on your computer. For a new key-first Node Haven VPS, you provide a public key during creation, then sign in as nodehaven and use sudo for administration.
This guide describes key-first VPS access. Connect after your service is provisioned, running, and its public network access is ready. Existing password-based services are not automatically converted.
1. Generate a key on your own computer
Use the computer you will administer the VPS from. Use Ed25519 (spelled ed25519 in commands). If you already have a protected Ed25519 key, you may use its public half instead. The examples use a separate Node Haven filename so they do not replace your default SSH key.
If that filename already exists, stop. Do not agree to overwrite it. Reuse its public key or choose a different filename consistently throughout the guide.
Windows: PowerShell
Open PowerShell on your PC. Check that the OpenSSH client is available:
ssh -V
ssh-keygen -?
ssh-keygen -? prints usage and may return a nonzero exit status; that is expected. If either command is missing, enable OpenSSH Client in Windows Optional features, or ask your computer administrator. You do not need OpenSSH Server on your PC. See Microsoft's OpenSSH installation instructions.
Create the folder if needed and check for an existing key:
New-Item -ItemType Directory -Force -Path "$env:USERPROFILE\.ssh" | Out-Null
((Test-Path "$env:USERPROFILE\.ssh\node_haven_ed25519") -or (Test-Path "$env:USERPROFILE\.ssh\node_haven_ed25519.pub"))
If the result is False, generate the key:
ssh-keygen -t ed25519 -a 64 -f "$env:USERPROFILE\.ssh\node_haven_ed25519" -C "node-haven"
Enter a strong, unique passphrase when prompted, then enter it again. No characters appear while typing; that is normal. Do not put your passphrase into the command itself.
Display only the public key:
Get-Content "$env:USERPROFILE\.ssh\node_haven_ed25519.pub"
macOS or Linux: Terminal
Open Terminal on your computer. Run ssh -V to check for OpenSSH. If it is missing, install your operating system's OpenSSH client package using its official instructions.
Create the folder if needed, then check for an existing key:
mkdir -p "$HOME/.ssh"
ls -l "$HOME/.ssh/node_haven_ed25519" "$HOME/.ssh/node_haven_ed25519.pub"
For new files, ls reports that they do not exist. If either exists, stop and choose another filename or reuse your existing public key. Otherwise generate:
ssh-keygen -t ed25519 -a 64 -f "$HOME/.ssh/node_haven_ed25519" -C "node-haven"
Enter and confirm a strong, unique passphrase. No characters appear while typing. Then display only the public key:
cat "$HOME/.ssh/node_haven_ed25519.pub"
These commands run locally. They do not upload either key. The -a 64 setting increases the work needed to check a guessed passphrase against the encrypted private file. See the OpenSSH key-generation reference.
2. Submit only the public key
| File | Purpose |
|---|---|
node_haven_ed25519.pub | Public key. Paste its single line into the VPS SSH public key field. |
node_haven_ed25519 | Private key. Keep it on your own device; never upload it to Node Haven. |
The public line starts with ssh-ed25519, followed by a long encoded value and optionally a comment. Copy the entire line, not the fingerprint or random-art picture. Only one plain Ed25519 public key is accepted in this initial flow; other key types, SSH certificates, authorized-key options, and multiple lines are not accepted.
If you see BEGIN OPENSSH PRIVATE KEY, you opened the wrong file. Close it and use the .pub file. If you already disclosed a private key, treat it as compromised: generate a new pair and contact support to coordinate replacement.
You can compare your public key's fingerprint with the SSH key fingerprint shown on your service:
# Windows PowerShell
ssh-keygen -lf "$env:USERPROFILE\.ssh\node_haven_ed25519.pub" -E sha256
# macOS / Linux
ssh-keygen -lf "$HOME/.ssh/node_haven_ed25519.pub" -E sha256
3. Connect when your VPS is ready
Wait until the service is provisioned and its network access is ready. Replace YOUR_VPS_IP below with your service's actual public IP address; it is a placeholder, not a hostname to copy unchanged.
# Windows PowerShell
ssh -o IdentitiesOnly=yes -i "$env:USERPROFILE\.ssh\node_haven_ed25519" nodehaven@YOUR_VPS_IP
# macOS / Linux
ssh -o IdentitiesOnly=yes -i "$HOME/.ssh/node_haven_ed25519" nodehaven@YOUR_VPS_IP
Use the private filename without .pub for -i. SSH uses it locally; the private key is not sent to the server. A prompt for the key's passphrase is normal. A prompt for nodehaven@…'s password is not expected for a key-first VPS: stop and check the address, username, key, and service status.
After login, use sudo for administrative commands, for example:
whoami
sudo -n id -u
For an unchanged key-first image, these should report nodehaven and 0. Direct root SSH and SSH password login are disabled. A sudo-capable customer can deliberately change their own system; these are secure provisioning defaults, not a restriction on ownership.
4. Protect your access
- Keep an encrypted backup of your private key and securely retain its passphrase. The public key alone cannot restore the private key.
- Protect your portal account with a strong password and any available multifactor authentication. Never share your login or private key with support.
- Where available, key-first reinstall is intended to retain the authorized service key; it does not recover a lost private key. Do not rely on an unverified reinstall path for recovery. Back up data before reinstalling.
- If you lose access, contact support from your authenticated account. Self-service key replacement is not yet available. Recovery must verify ownership and the exact VPS; a browser console connection is not an automatic guest login.
For the key-file model and Windows commands, see Microsoft's OpenSSH key-management documentation.
Troubleshooting
Permission denied (publickey)
Use nodehaven, the correct VPS address, and the matching private key without .pub. Compare your public fingerprint to the service. Do not enable passwords as a workaround. If it still fails, contact support with the service ID and public fingerprint, never the private key.
Connection timed out or refused
Confirm your service has finished provisioning, the VPS is running, and you are using its assigned public IP address. Check its network and firewall status, then contact support if it is still unreachable. This error is not evidence that your key is wrong.
The private key's permissions are too open
On macOS/Linux, restrict your own key file with chmod 600 "$HOME/.ssh/node_haven_ed25519". On Windows, keep the key in your own user profile and ask your administrator to restrict its NTFS permissions to your account as appropriate. Do not make the key readable by everyone.
REMOTE HOST IDENTIFICATION HAS CHANGED
Stop and verify the new host fingerprint through a trusted channel. A legitimate reinstall can change it, but so can connecting to the wrong server. Do not blindly delete your known-host entry or turn off verification.