SSH could not parse the private key file. The key material is intact in the secret but got mangled on the way to disk - a stripped trailing newline, CRLF line endings, or lost formatting all make OpenSSH reject it as invalid.
What this error means
An SSH operation fails with Load key "/path/id_ed25519": invalid format (sometimes error in libcrypto), then Permission denied (publickey). The key works on a developer machine but not after being injected via a CI secret.
git clone output
Load key "/home/runner/.ssh/id_ed25519": invalid format
git@github.com: Permission denied (publickey).
fatal: Could not read from remote repository.
Diagnose it: depth, refs, or credentials?
Terminal
git rev-parse --is-shallow-repository
git rev-parse --abbrev-ref HEAD # prints HEAD when detached
git log --oneline -3
git remote -v
Common causes
Missing trailing newline
OpenSSH requires the private key file to end with a newline. A secret that dropped the final newline makes the key fail to parse.
CRLF line endings
A key pasted on Windows or through a tool that rewrote line endings has \r\n, which OpenSSH does not accept.
Echo/quoting mangled the key
Writing the key with echo or shell interpolation can collapse newlines or expand characters, corrupting the PEM structure.
How to fix it
Write the key verbatim with a trailing newline
Use a heredoc or printf that preserves newlines, and ensure a final newline.
Store the full PEM key including its trailing newline in the secret.
Use the checkout action’s ssh-key input, which writes the key correctly.
Avoid echo/interpolation for key material; prefer printf/heredoc.
Frequently asked questions
What causes Git SSH "Load key: invalid format" in CI?
There are 3 common causes: missing trailing newline, crlf line endings, and echo/quoting mangled the key. OpenSSH requires the private key file to end with a newline.
How do I fix Git SSH "Load key: invalid format" in CI?
There are 2 fixes depending on which cause you have: write the key verbatim with a trailing newline and strip crlf if present. Work through them in order, since the first is the most common.
What does Git SSH "Load key: invalid format" in CI actually mean?
An SSH operation fails with Load key "/path/id_ed25519": invalid format (sometimes error in libcrypto), then Permission denied (publickey).
How do I stop Git SSH "Load key: invalid format" in CI happening again?
Store the full PEM key including its trailing newline in the secret. The prevention section lists 3 changes that keep it from recurring.