An unfamiliar SSH key sitting on your GitHub account is a security question waiting to be asked: gh ssh-key list answers it in five minutes. This is an inspection-only task: gh ssh-key list does not add, edit or remove a key, and it does not need root privileges.
You need GitHub CLI installed and an account authenticated in the environment where you run the command. The examples below use GitHub CLI 2.87.3, the version installed on the machine used for this guide; the command syntax is also present in the current upstream manual. Allow a few minutes if you already have a working gh login, or longer if you need to authenticate in a terminal without opening a browser.
Run this as your normal user:
gh --version
gh auth status
Expected output from the first command begins like this:
gh version 2.87.3
The authentication check should identify a logged-in GitHub host and account. Never paste tokens or other credential material into a ticket or terminal transcript. No command in this guide needs sudo.
Run the command without extra options:
gh ssh-key list
GitHub CLI asks GitHub for the SSH keys in the authenticated account and prints the result. The installed gh-ssh-key-list(1) manpage deliberately documents no command-specific flags, so do not add output-format or filtering options from a different gh subcommand. The shorter alias is equivalent:
gh ssh-key ls
Use the full spelling in scripts and runbooks: it is easier to recognise when somebody is scanning a shell history. The alias is fine when typing interactively, but it is not a different operation.
Read the list as an account-level access inventory. Compare each entry with the keys you expect to use, such as a workstation key or a key held by an approved automation account. Check the displayed name and other identifying details against your records. If a key is unfamiliar, pause and investigate its owner and last intended use before changing anything.
This command does not show every SSH key that can reach a repository. Keep three inventories separate:
gh ssh-key list.~/.ssh is only a credential file on your machine; its presence does not prove GitHub has registered the matching public key.For a quick audit, record the command and the date in your normal change or security log, not in a file containing secrets. To make a shell script stop when the check cannot be completed, inspect its exit status:
if gh ssh-key list; then
echo "GitHub SSH key listing completed"
else
rc=$?
echo "GitHub SSH key listing failed with exit code $rc" >&2
exit "$rc"
fi
A successful command exits with status 0. The manpage also records status 1 for an error, status 2 when the command is cancelled, and status 4 when authentication is required. Treat a non-zero status as an incomplete audit, and never turn a failed listing into an empty approved-key list.
If gh auth status shows no usable login, authenticate with GitHub CLI using the method approved for your organisation, then run the status check and listing again. The precise login flow can depend on whether your account uses a browser, a token, SSO, or an enterprise host. Verify the selected host and account before trusting the result.
GitHub CLI can work with more than one host or account. A clean-looking list is still the wrong answer if it came from a different identity. Re-run gh auth status and check the account and hostname it reports. If your organisation uses GitHub Enterprise Server, make sure you are authenticated to that server rather than only to github.com.
First confirm the identity and host, then check that you are looking at account keys rather than deploy keys or local files. Do not immediately add a replacement key to make the list look right: that changes account access and can leave an untracked credential behind. If a key is suspected to be compromised, follow your organisation's incident process and remove or rotate it through the approved GitHub administration path. Removal is a security-sensitive change and is not reversible through this listing command.
gh --version identified the installed CLI version.gh auth status confirmed the intended GitHub account and host.gh ssh-key list completed with exit status 0.