# SSH Keys and Commit Signing — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/dev-ssh-signing

> Keep SSH private keys in 1Password and sign Git commits with them.

## Keys that never touch the disk

The 1Password SSH agent stores your private keys inside the vault and lets SSH and Git use them after you approve with biometrics. The key file never sits in `~/.ssh`, so a stolen laptop disk or a stray backup does not leak it.

## Sign commits with an SSH key

Git can sign commits with an SSH key instead of GPG. Paste your public key where `<public key>` appears and add the same key to GitHub as a signing key.

```bash
git config --global gpg.format ssh
git config --global user.signingkey "<public key>"
git config --global commit.gpgsign true
```

## Protect private keys

Never share a private key or paste it into chat. Only the public key is shared. If a private key ever leaves your control, remove it from every server and GitHub and generate a new pair.

**Quiz:** Which part of an SSH key pair may you share freely?

- [ ] The private key
- [ ] Both parts
- [ ] Neither
- [x] The public key

*Answer:* The public key. The public key only verifies; the private key proves identity and must stay secret.
