Using PuTTY's Pageant for SSH Agent Forwarding to Avoid Repeated Passphrase Entry
Learn how to configure Pageant to hold decrypted SSH keys and enable agent forwarding in PuTTY, reducing passphrase prompts while keeping keys encrypted on disk.
25 Sept 2025, 09:17 UTC

The Problem: Repeated Passphrase Prompts
When you manage multiple SSH private keys, each protected by a passphrase, you must type that passphrase every time you open a new session. This interrupts workflow, encourages the habit of storing keys without protection, and increases the chance that an unencrypted key ends up on disk or in a backup.
How Pageant Addresses the Problem
Pageant is the PuTTY authentication agent. It loads your private key into memory, decrypts it once with the passphrase you provide, and then supplies the decrypted key to any PuTTY, PSCP, or PSFTP process that requests authentication. Because the key stays encrypted on disk, the only exposed copy resides in Pageant’s protected memory space.
Loading a Key into Pageant
- Start Pageant by running
pageant.exe(requires no administrative rights; it runs in the user session). - Right‑click the Pageant icon in the system tray and choose Add Key.
- Browse to your
.ppkfile, select it, and enter the passphrase when prompted. - The tray icon now shows a key fingerprint; the decrypted key resides in memory until Pageant exits or the key is removed.
Enabling Agent Forwarding in a PuTTY Session
- Open PuTTY and either create a new session or load an existing one.
- In the left pane navigate to Connection → SSH → Auth.
- Check the box labelled Allow agent forwarding.
- Return to the Session page, give the session a name, and click Save.
- When you open this session, PuTTY will forward any credentials held by Pageant to the remote SSH daemon.
Worked Example: Two‑Hop SSH Connection
Suppose you have a bastion host bastion.example.com that you must jump through to reach an internal host internal.example.com. Both hosts run OpenSSH and accept agent forwarding.
- Start Pageant, load your SSH private key (enter passphrase once).
- Open a PuTTY session to
bastion.example.comwith agent forwarding enabled, authenticate, and obtain a shell. - On the bastion, run
ssh-add -l. You should see a line similar to2048 SHA256:xxxxxx user@hostname (RSA), indicating the forwarded key is present. - From the bastion shell, execute
ssh internal.example.com. You are logged in without being asked for the passphrase again. - To confirm that forwarding is under your control, return to the bastion, disable agent forwarding in the same PuTTY session (or close and reopen the session with the option unchecked), then run
ssh-add -lagain; the output should be empty.
Trade‑off and Limitation
Agent forwarding only works when the remote SSH server permits it (AllowAgentForwarding yes in sshd_config). If you connect to a host that has forwarding disabled or is compromised, the forwarded agent could be misused, potentially exposing your decrypted keys. Because Pageant keeps the decrypted key in RAM, a workstation that suffers a memory dump, cold‑boot attack, or malware infection could leak those keys. Therefore the machine running Pageant must be trusted, kept up to date, and preferably locked when unattended.
Practical Verification Steps
- On the client workstation, hover over the Pageant tray icon; the tooltip lists the loaded key fingerprints.
- After establishing a PuTTY session with forwarding enabled, run
ssh-add -lon the remote host. Expect to see the same fingerprint that Pageant shows. - To test the limitation, disable forwarding, reconnect, and run
ssh-add -lagain; the command should returnThe agent has no identities.or produce no output. - Optionally, on the remote host check
sshd_configforAllowAgentForwarding yesto confirm the server allows the feature.
Actionable Closing
If you frequently hop between servers, enabling Pageant agent forwarding reduces the number of times you must type a passphrase while keeping your private key encrypted on disk. Apply the feature only to trusted hosts, keep the workstation running Pageant secured with up‑to‑date patches and screen locking, and verify forwarding state with ssh-add -l before and after each hop. When forwarding is not needed or the destination is untrusted, leave the option disabled to limit exposure.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.