An SSH private key can authenticate access without typing the account password, so it must be protected like a password.
- Keep the private key only on trusted devices.
- Use a passphrase when practical.
- Do not commit private keys to Git repositories.
- Do not upload them into publicly served website directories.
- Deauthorize or replace a key if its private half may have been exposed.
Public SSH keys are designed to be shared with the server; private keys are not.