What this error means and why it happens
The message "Could not open a connection to your authentication agent" appears when your computer tries to use a saved password or security key but cannot reach the system that stores it. This usually happens on Linux and macOS machines, and the most common cause is that the SSH agent — the background service that holds your login credentials — has stopped running or was never started.
You will see this error most often when you are trying to connect to a remote server using SSH (Secure Shell), push code to GitHub or another repository, or access a service that requires stored credentials. The error does not mean your password is wrong or your account is locked. It means the authentication agent itself is not available.
Key Takeaways
- The SSH agent is a background service that stores your login keys; if it is not running, you cannot use stored credentials to connect to remote servers.
- On macOS, the SSH agent usually starts automatically, but on Linux you may need to start it manually or add it to your shell startup file.
- The fastest fix is to run eval $(ssh-agent) in your terminal, which starts the agent in your current session.
- If you want the agent to start every time you open a terminal, add the startup command to your shell configuration file (.bashrc, .zshrc, or equivalent).
- On Windows with WSL (Windows Subsystem for Linux), you may need to use a third-party SSH agent or configure the built-in agent differently.
Starting the SSH agent in your current terminal session
The quickest way to fix this error is to start the SSH agent right now, in the terminal window where you got the error. Open your terminal and type this command exactly:
eval $(ssh-agent)
Press Enter. The agent will start and print output that looks like this:
Agent pid 12345
After this command runs, you should be able to use your stored SSH keys in that terminal window. However, this fix only lasts for the current session. When you close the terminal and open a new one, the agent will not be running again, and you will see the error once more.
Making the SSH agent start automatically on Linux
On Linux, the SSH agent does not start by default. To make it start every time you open a terminal, you need to add the startup command to your shell configuration file. Which file you edit depends on which shell you use.
If you use Bash, edit the file ~/.bashrc. If you use Zsh, edit ~/.zshrc. If you use a different shell, the file name will be different — ask your system administrator or check your shell's documentation. Open the file in a text editor (nano, vim, or any editor you prefer) and add these lines at the end:
if [ -z "$SSH_AUTH_SOCK" ]; then eval $(ssh-agent) fi
Save the file and close the editor. The next time you open a new terminal window, the SSH agent will start automatically. The if statement checks whether the agent is already running, so it will not start a duplicate agent if you open multiple terminal windows.
What to do on macOS
On macOS, the SSH agent usually starts automatically when you first use an SSH key. However, if you are still seeing the error, the agent may have crashed or your key may not be loaded into the agent's memory.
First, try the quick fix: run eval $(ssh-agent) in your terminal. If that works, the agent had simply stopped. If you want to prevent this from happening again, add the command to your shell configuration file using the same steps as Linux above.
On newer versions of macOS (10.12 and later), you can also add your SSH key to the system keychain so it persists across restarts. After you have started the agent, run this command:
ssh-add --apple-use-keychain ~/.ssh/id_rsa
Replace id_rsa with the name of your actual key file if it is different. This tells macOS to remember your key passphrase, so you will not have to type it every time.
Fixing the error on Windows with WSL
If you are using Windows Subsystem for Linux (WSL), the SSH agent setup is more complicated because Windows and Linux do not share the same authentication system. You have two main options.
The first option is to use the SSH agent built into Windows itself. This requires configuring WSL to connect to the Windows agent, which involves setting environment variables and is beyond the scope of a quick fix. Check the WSL documentation or your Linux distribution's documentation for the exact steps.
The second option is to start the Linux SSH agent inside WSL the same way you would on any Linux machine — run eval $(ssh-agent) and add it to your shell configuration file. This agent will only work inside WSL, not in Windows PowerShell or Command Prompt, but it is simpler to set up.
Checking whether your SSH key is loaded into the agent
Once the SSH agent is running, you need to make sure your SSH key is actually loaded into it. Run this command to see which keys the agent knows about:
ssh-add -l
If you see a list of keys with long strings of characters, your keys are loaded and ready to use. If you see the message "The agent has no identities", your key is not loaded yet.
To load a key, run this command (replace id_rsa with your actual key file name if it is different):
ssh-add ~/.ssh/id_rsa
The agent will ask for your key's passphrase if it has one. Type it and press Enter. After that, the key is loaded and you should be able to connect to remote servers.
When the error appears even though the agent is running
If you have started the SSH agent and loaded your key, but you still see the error, the problem may be that the agent is running in a different terminal session than the one you are using now.
This can happen if you started the agent in one terminal window and then opened a new terminal window without closing the first one. Each terminal window has its own environment, and the new window does not know about the agent running in the old window.
The fix is to run eval $(ssh-agent) in the terminal window where you are getting the error. Alternatively, you can add the startup command to your shell configuration file so the agent starts automatically in every new terminal window.
Frequently Asked Questions
Why does this error happen on Linux but not on macOS?
macOS includes built-in support for starting the SSH agent automatically when you first use an SSH key. Linux does not have this built-in support, so you have to start the agent manually or configure it to start when you open a terminal. Different Linux distributions may handle this differently, so check your distribution's documentation if the steps above do not work.
Is it safe to add the SSH agent startup command to my shell configuration file?
Yes. The command checks whether the agent is already running before starting a new one, so it will not create duplicate agents. The agent itself is a standard part of SSH and is designed to be secure. Your keys are encrypted and protected by your passphrase.
What if I do not remember my SSH key's passphrase?
If you have forgotten your passphrase, you cannot recover it — passphrases are not stored anywhere. You will need to generate a new SSH key pair. Delete or rename your old key file and run ssh-keygen to create a new one. Then add the new public key to any services that need it (GitHub, your server, etc.).
Can I use the SSH agent with passwords instead of keys?
The SSH agent is designed to work with SSH keys, not passwords. However, you can configure SSH to ask for your password instead of using a key by editing your SSH configuration file. This is less secure than using keys and is not recommended for remote servers you access regularly.
Do I need to restart my computer after adding the agent to my shell configuration file?
No. You only need to close your current terminal window and open a new one. The new terminal will read your updated shell configuration file and start the agent automatically.