Skip to content

Key Pair CLI Reference

Reference · Updated Sep 2026

Coming from another cloud?

▸AWS·EC2 Key Pairs

EC2 Key Pairshigh

  • Public key auto-injected to authorized_keys at boot.
  • Up to 5000 per region; AWS stores public key.
  • Supports import of external keys (RSA/ED25519).
  • No post-launch addition without userdata/SSM.
AWS docs ↗
▸Azure·SSH public keys

SSH public keyshigh

  • Managed as ARM resources (Microsoft.Compute/sshPublicKeys), reusable across VMs, vs OpenStack's keypairs injected only at boot.
  • API /providers/Microsoft.Compute/sshPublicKeys, supports ED25519/RSA, no private key storage.
  • Keys provided during VM create or via portal/CLI, not listed/injected separately post-boot like OpenStack.
  • No deletion/re-import of injected keys; new VM for changes.
Azure docs ↗
▸DigitalOcean·SSH keys (Account/Team SSH keys)

SSH keys (Account/Team SSH keys)high

  • SSH keys are managed at the account/team level via /v2/account/keys and then referenced by ID/fingerprint when creating Droplets, whereas OpenStack Nova keypairs are typically created per project/tenant and managed via the Nova API.
  • DigitalOcean explicitly notes that including a key during Droplet creation embeds it into the root user’s authorized_keys, whereas OpenStack’s keypair injection mechanism is generally cloud-init/metadata-service driven and may vary by image/cloud config.
  • DigitalOcean tokens/scopes model for API authorization (bearer tokens with scopes like ssh_key:read) differs from OpenStack Keystone’s token + role-based policy model.
  • DigitalOcean documentation emphasizes that post-creation SSH key changes are performed inside the guest OS (not via control panel), whereas OpenStack users may rely more heavily on metadata/cloud-init or config management patterns post-boot.
DigitalOcean docs ↗
▸Google Cloud·SSH keys

SSH keyshigh

  • Managed in project/instance metadata or OS Login (IAM); no central 'keypairs' resource like Nova.
  • Auto-generates ephemeral keys for CLI/console; manual upload only in OpenStack.
  • Public key includes username suffix; injected differently.
Google Cloud docs ↗
▸Hetzner·SSH Keys

SSH Keyshigh

  • API /v1/ssh_keys; POST public_key, name; inject array of ssh_keys on server create.
  • No private key management; user provides public keys only.
  • Fingerprint-based listing/filtering; labels support.
  • Injected via cloud-init on boot.
Hetzner docs ↗

Key pair CLI reference

See the OpenStackClient keypair command reference for subcommands, arguments, and examples.

Use these commands to create, list, show, and delete key pairs in your cloud projects. Replace KEYPAIR_NAME with the name of your key pair. When you create a key pair without a public key, the command prints the private key to stdout. Save it before the command exits.

List key pairs#

bash
openstack keypair list

Show key pair details#

bash
openstack keypair show KEYPAIR_NAME

Create a key pair (generate on server)#

bash
openstack keypair create KEYPAIR_NAME

The server generates a new key pair and prints the private key to stdout. The server does not store the private key, so save it before the command exits. Use --private-key PRIVATE_KEY_FILE to write the private key to a file instead of stdout (see "Generate a key pair and save the private key" below).

Import an existing key pair#

bash
openstack keypair create --public-key PUBLIC_KEY_FILE KEYPAIR_NAME
  • PUBLIC_KEY_FILE: Path to the file containing the public key (for example, ~/.ssh/id_ed25519.pub).

The CLI uploads only the public key; the private key stays on your machine.

Delete a key pair#

bash
openstack keypair delete KEYPAIR_NAME

Generate a key pair and save the private key#

bash
openstack keypair create --private-key PRIVATE_KEY_FILE KEYPAIR_NAME
  • PRIVATE_KEY_FILE: Path to save the generated private key file.

Output columns#

Select specific columns with --column COL1 --column COL2 or change the output format with -f json, -f csv, or -f table (default).

openstack keypair list#

ColumnDescription
NameKey pair name
FingerprintSSH key fingerprint
TypeKey type (ssh or x509)

openstack keypair show#

ColumnDescription
created_atTimestamp when you registered the key pair
fingerprintSSH key fingerprint
idSame as name; key pairs use the name as their identifier rather than a UUID
is_deletedSoft-delete flag; False for live records
nameKey pair name
private_keyNone on show; the server populates it only in the response of keypair create
typeKey type (ssh or x509)
user_idKeystone user UUID that owns the key pair
Was this page helpful?