IdentitiesOnly=yes stops ssh from trying every key loaded in the agent before the one you specified
Prefer setting these in ~/.ssh/config: Host myhost / Port 2222 / User deploy / IdentityFile ~/.ssh/deploy_key / IdentitiesOnly yes, then just: scp file.txt myhost:/path/
Add -o ConnectTimeout=10 to avoid hanging on unreachable hosts in scripts
Known gotchas
-P is capital P for the remote port; lowercase -p means preserve attributes (not port)
ssh_config Host blocks only apply when the alias you pass to scp matches the Host name in the config
With IdentitiesOnly unset and many agent keys, auth can fail or pick the wrong key — set it when the client has a busy agent
Give your agent this knowledge — and 17,000+ more routes
One MCP install gives any agent live access to the full route map across 5,900+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?