如何将YubiKey连接至GitHub以配置双因素认证
Hey there! I’ve set up YubiKey for GitHub 2FA multiple times, so let me walk you through the exact steps to get it working smoothly:
Step 1: Prep your YubiKey
- Plug your YubiKey into your computer’s USB port (if it’s an NFC model, you can also tap it against a supported device later)
- No extra software is needed for the basic 2FA login setup—modern browsers like Chrome, Firefox, or Edge support FIDO2/U2F out of the box
Step 2: Enable YubiKey as your GitHub 2FA method
- Log into your GitHub account, click your profile avatar in the top right corner, and select Settings
- On the left sidebar, navigate to Password and authentication
- Scroll down to the Two-factor authentication section and click Enable two-factor authentication
- You’ll first be asked to enter your GitHub password to confirm it’s you—type that in and proceed
- Next, select the Security key option (this is the YubiKey-compatible FIDO2/U2F method)
- Click Add, then follow the prompts:
- Give your security key a descriptive name (like "Daily Carry YubiKey" or "Home Desktop YubiKey")
- When your browser prompts you, touch the button on your YubiKey to complete the verification
- Once done, GitHub will show you a set of recovery codes—save these somewhere super secure (like a password manager or encrypted note)! These are your backup if you ever lose your YubiKey.
Step 3: (Optional) Set up SSH authentication with YubiKey
If you want to use your YubiKey to authenticate Git commands (instead of typing tokens or passwords every time), here’s how:
- Open your terminal and run this command to generate an SSH key stored directly on your YubiKey:
Note: If your YubiKey doesn’t support ED25519-SK, usessh-keygen -t ed25519-skssh-keygen -t ecdsa-skinstead - Follow the terminal prompts: touch your YubiKey when asked, choose a save path (the default is fine), and optionally set a passphrase for extra security
- Copy your new public key to your clipboard:
(Swapcat ~/.ssh/id_ed25519-sk.pubed25519-skwithecdsa-skif you used that earlier) - Back on GitHub, go to Settings > SSH and GPG keys and click New SSH key
- Paste the public key into the text box, give it a name, and click Add SSH key
- From now on, when you run
git pullorgit push, just touch your YubiKey when prompted to authenticate
Quick Tips
- Add multiple security keys to GitHub (e.g., one for your laptop, one for your home PC) so you’re not locked out if you lose one
- When logging into GitHub via browser, as long as your YubiKey is plugged in, you’ll just need to touch the button instead of typing a code
- If your YubiKey isn’t available, use your saved recovery codes or any backup 2FA method you set up (like an authenticator app)
内容的提问来源于stack exchange,提问作者Ruby
相关产品推荐
相关产品推荐

