1diff --git a/plugins/ssh-agent/README.md b/plugins/ssh-agent/README.md
2index d1a504b1ece2cf58b92dcdb1124c386d13bc1ba9..1d6914ec6ba4ef08560f3328c51d883a296b843d 100644
3--- a/plugins/ssh-agent/README.md
4+++ b/plugins/ssh-agent/README.md
5@@ -21,7 +21,23 @@ zstyle :omz:plugins:ssh-agent agent-forwarding on
6 7 ----
8 9-To **load multiple identities** use the `identities` style, For example:
10+To **NOT load any identities on start** use the `lazy` setting. This is particularly
11+useful when combined with the `AddKeysToAgent` setting (available since OpenSSH 7.2),
12+since it allows to enter the password only on first use. _NOTE: you can know your
13+OpenSSH version with `ssh -V`._
14+
15+```zsh
16+zstyle :omz:plugins:ssh-agent lazy yes
17+```
18+
19+You can enable `AddKeysToAgent` by passing `-o AddKeysToAgent=yes` to the `ssh` command,
20+or by adding `AddKeysToAgent yes` to your `~/.ssh/config` file [1].
21+See the [OpenSSH 7.2 Release Notes](http://www.openssh.com/txt/release-7.2).
22+
23+----
24+
25+To **load multiple identities** use the `identities` style (**this has no effect
26+if the `lazy` setting is enabled**). For example:
2728 ```zsh
29 zstyle :omz:plugins:ssh-agent identities id_rsa id_rsa2 id_github
30diff --git a/plugins/ssh-agent/ssh-agent.plugin.zsh b/plugins/ssh-agent/ssh-agent.plugin.zsh
31index 2d7d8a2a00febe4f6743e57a19f0ae57708652d0..4bd2dedcc32cd774fb8d605bbbd626bb40985f72 100644
32--- a/plugins/ssh-agent/ssh-agent.plugin.zsh
33+++ b/plugins/ssh-agent/ssh-agent.plugin.zsh
34@@ -96,7 +96,10 @@ else
35 _start_agent
36 fi
3738-_add_identities
39+# Don't add identities if lazy-loading is enabled
40+if ! zstyle -b :omz:plugins:ssh-agent lazy; then
41+ _add_identities
42+fi
4344 unset agent_forwarding ssh_env_cache
45 unfunction _start_agent _add_identities