Home / Alt manpages / gh-ssh-key-delete(1)

  • gh-ssh-key-delete(1)
  • User command
  • linux

Remove the Right GitHub SSH Key with gh ssh-key delete

You will finish with a controlled way to remove one SSH key from your GitHub account, using its numeric ID and checking the result afterwards. The deletion is account-wide, not repository-specific.

Allow about ten minutes, including the verification. You need GitHub CLI installed, an authenticated gh session for the account that owns the key, and permission to manage that account's SSH keys. The examples use GitHub CLI 2.87.3, installed here in the gh package. Your version may present slightly different diagnostics, so check its help before relying on automation.

1. Check the installed command

Start with a read-only help query. This is an ordinary user command and does not need elevated privileges:

$ gh --version
gh version 2.87.3 (2026-02-23)
$ gh ssh-key delete --help
Delete an SSH key from your GitHub account

USAGE
  gh ssh-key delete <id> [flags]

FLAGS
  -y, --yes   Skip the confirmation prompt

The subcommand accepts an ID and one option, --yes (or -y) to skip its confirmation prompt. There is no filename, public-key text, title or repository flag here. Do not paste a fingerprint or the contents of an .pub file where an ID is required.

Checkpoint

If the help output does not resemble this syntax, stop and use the syntax shown by your installed version.

2. Confirm the account and list its keys

Before choosing an ID, confirm which account and host your current credentials address:

$ gh auth status

Read the account name and hostname in the result. If they are wrong, do not continue. Switch or authenticate the intended account first. An SSH key deletion succeeds against the account selected by your gh authentication, not necessarily the account you had in mind.

Now list the account's registered SSH keys:

$ gh ssh-key list
TITLE                 TYPE            ID
work-laptop           authentication  123456789
old-desktop           authentication  234567890

The displayed columns are host-specific. Match the exact title and type, then copy only the numeric value in the ID column. A title is not a stable command argument, and a key fingerprint is not the ID expected by gh ssh-key delete.

If the list is empty, there is nothing to delete in that account. If a key you expect is missing, resolve the account, hostname and authentication problem before trying a different command.

3. Inspect the deletion before accepting it

Deletion is irreversible through this command. Removing a key can immediately stop a laptop, server or automation job from authenticating to GitHub with that key. Keep another working sign-in method available before proceeding.

Use the ID you just checked, without --yes, so the command can ask for confirmation:

$ gh ssh-key delete 234567890
? Are you sure you want to delete this SSH key? Yes

The exact prompt wording can vary by CLI release. Read it carefully. If the ID or account is not the one you intended, answer No or press Ctrl-C. A declined prompt leaves the key in place.

There is no undo command in gh ssh-key delete. If you removed the wrong key, create or register a replacement through the GitHub account settings or gh ssh-key add, then update the affected machine or service to use it. That restores access with a new key; it does not restore the deleted credential itself.

4. Delete the confirmed ID

After checking the prompt, confirm the deletion. This is still an ordinary user command, but it changes remote account state and should not be run casually from a script:

$ gh ssh-key delete 234567890
? Are you sure you want to delete this SSH key? Yes
$ printf 'exit status: %s\n' "$?"
exit status: 0

A zero status means the command completed successfully. It does not mean that every other key was checked, nor does it revoke an SSH private key file stored on a computer. Anyone who has a copy of that private key can still possess the credential, but GitHub will no longer accept it for the deleted account key.

For a deliberate non-interactive operation, add --yes only after the ID has been obtained and checked by a trustworthy process:

$ key_id='234567890'
$ gh ssh-key delete "$key_id" --yes
$ printf 'exit status: %s\n' "$?"
exit status: 0

Do not build this value from an unreviewed title match or from arbitrary user input. A mistaken ID can remove a different key, and --yes removes the last human checkpoint.

5. Verify that the key is gone

List the keys again and check that the deleted ID no longer appears:

$ gh ssh-key list
TITLE                 TYPE            ID
work-laptop           authentication  123456789

For a script or a change record, capture the list and search for the exact ID rather than relying on the table's order:

$ gh ssh-key list | awk '$NF == "234567890" { found=1 } END { exit found }'
$ printf 'verification status: %s\n' "$?"
verification status: 0

The command above exits zero when the ID is still present, so it is a useful presence test but a poor success message by itself. To make absence explicit in a shell check:

if gh ssh-key list | awk '$NF == "234567890" { found=1 } END { exit found }'; then
    printf '%s\n' 'key is absent'
else
    printf '%s\n' 'key is still listed, or the list command failed' >&2
    exit 1
fi

In a real script, distinguish a failed list request from an empty match rather than treating every non-zero status as proof of deletion.

6. Handle the common boundary cases

This command deletes an SSH key associated with the authenticated GitHub account. It does not remove a local private key, edit ~/.ssh/config, delete a repository deploy key, or alter an organisation's policy. A repository deploy key needs the repository deploy-key commands instead.

Be careful with the TYPE column. Current GitHub CLI releases can display authentication and signing keys together, while this delete command takes only an ID and does not offer a type selector. If a signing-key ID returns an HTTP 404, do not retry with another ID at random. Confirm the installed CLI's current behaviour and use GitHub's account settings or an appropriate API operation for that key type.

Do not use sudo for this operation. Elevated local privileges do not grant GitHub account permission and may select different local credentials or configuration. Fix authentication with gh auth status and gh auth login instead.

Done means

  • The installed gh ssh-key delete syntax was checked.
  • The authenticated account and host were confirmed with gh auth status.
  • The ID was copied from gh ssh-key list, not guessed from a title or fingerprint.
  • The destructive prompt was reviewed, or --yes was used only in a controlled operation.
  • A second key listing confirmed that the intended ID is absent.
  • You know that the command does not delete local private-key files and has no undo operation.