# SSH keys and SSH access

> Add organization SSH keys that Falak syncs to the falak user on your servers, attach keys to individual servers, and connect with falak ssh.

Source: https://falak.sh/docs/servers/ssh-keys/

Falak does not need SSH to manage servers (the agent dials out), but you may want it. Falak keeps authorized keys for the `falak` user in sync on every server.

## Add an organization key

1. Open **Settings → SSH keys** (or **⌘K → SSH keys**).
2. Paste your public key (for example the contents of `~/.ssh/id_ed25519.pub`) and name it.
3. Choose it when creating servers, or attach it to existing servers from the server page → **SSH keys**.

Keys are installed for the `falak` user once the server is provisioned. Managing keys needs `ssh_keys.manage` (owners, admins, developers).

![Settings → SSH keys: organization keys with their fingerprints.](./_images/ssh-keys.png)

## Connect

```bash
ssh falak@203.0.113.20
# or, with the CLI, by server name:
falak ssh app-1
falak ssh app-1 --user root
falak ssh app-1 -- -L 5432:127.0.0.1:5432   # extra ssh arguments after --
```

`falak ssh` looks the server up by id or unique name and runs `ssh falak@<ipv4>` (with `-p` when the server uses another SSH port; `--private` uses its private IPv4). See [CLI commands](/docs/cli/commands/#falak-ssh).

## What the falak user can do

| | |
|---|---|
| Home | `/home/falak`, shell `/bin/bash` |
| Groups | `www-data` (and `docker` when Docker is installed) |
| sudo | **None** |
| Owns | Non-isolated sites in `/srv/falak/sites` |

For root access, use your provider's root key (root login with keys stays allowed: `PermitRootLogin prohibit-password`), or the [web terminal](/docs/guides/terminal/).

Password authentication is disabled during provisioning. Add a key before you connect a server you currently reach with a password.

## Next steps
