List Your GitHub SSH Keys with gh ssh-key list

An unfamiliar SSH key sitting on your GitHub account is a security question waiting to be asked: gh ssh-key list answers it in five minutes. This is an inspection-only task: gh ssh-key list does not add, edit or remove a key, and it does not need root privileges.

You need GitHub CLI installed and an account authenticated in the environment where you run the command. The examples below use GitHub CLI 2.87.3, the version installed on the machine used for this guide; the command syntax is also present in the current upstream manual. Allow a few minutes if you already have a working gh login, or longer if you need to authenticate in a terminal without opening a browser.

Before you start

Run this as your normal user:

gh --version
gh auth status

Expected output from the first command begins like this:

gh version 2.87.3

The authentication check should identify a logged-in GitHub host and account. Never paste tokens or other credential material into a ticket or terminal transcript. No command in this guide needs sudo.

1. List the account keys

Run the command without extra options:

gh ssh-key list

GitHub CLI asks GitHub for the SSH keys in the authenticated account and prints the result. The installed gh-ssh-key-list(1) manpage deliberately documents no command-specific flags, so do not add output-format or filtering options from a different gh subcommand. The shorter alias is equivalent:

gh ssh-key ls

Use the full spelling in scripts and runbooks: it is easier to recognise when somebody is scanning a shell history. The alias is fine when typing interactively, but it is not a different operation.

2. Compare the result with your inventory

Read the list as an account-level access inventory. Compare each entry with the keys you expect to use, such as a workstation key or a key held by an approved automation account. Check the displayed name and other identifying details against your records. If a key is unfamiliar, pause and investigate its owner and last intended use before changing anything.

This command does not show every SSH key that can reach a repository. Keep three inventories separate:

3. Make the check repeatable

For a quick audit, record the command and the date in your normal change or security log, not in a file containing secrets. To make a shell script stop when the check cannot be completed, inspect its exit status:

if gh ssh-key list; then
    echo "GitHub SSH key listing completed"
else
    rc=$?
    echo "GitHub SSH key listing failed with exit code $rc" >&2
    exit "$rc"
fi

A successful command exits with status 0. The manpage also records status 1 for an error, status 2 when the command is cancelled, and status 4 when authentication is required. Treat a non-zero status as an incomplete audit, and never turn a failed listing into an empty approved-key list.

When the command fails

Authentication is required

If gh auth status shows no usable login, authenticate with GitHub CLI using the method approved for your organisation, then run the status check and listing again. The precise login flow can depend on whether your account uses a browser, a token, SSO, or an enterprise host. Verify the selected host and account before trusting the result.

The account or host is wrong

GitHub CLI can work with more than one host or account. A clean-looking list is still the wrong answer if it came from a different identity. Re-run gh auth status and check the account and hostname it reports. If your organisation uses GitHub Enterprise Server, make sure you are authenticated to that server rather than only to github.com.

The list is empty or unexpected

First confirm the identity and host, then check that you are looking at account keys rather than deploy keys or local files. Do not immediately add a replacement key to make the list look right: that changes account access and can leave an untracked credential behind. If a key is suspected to be compromised, follow your organisation's incident process and remove or rotate it through the approved GitHub administration path. Removal is a security-sensitive change and is not reversible through this listing command.

Done means