The short answer is that it doesn't. That answer is not very helpful, though.
Imagine you're an ssh server and you have just been handed a user name—which is always git at this point—and a public key.
You now look at ~git/.ssh/authorized_keys, which is a big file full of lines consisting of four space-sparated fields:
- options
- keytype
- base64-encoded-key
- comment
(though the options part can be omitted). The first important part here is the base64-encoded-key: this consists of the public key, plus some other stuff.
Now let's look at your question again:
The server's authorized_keys contains tens of thousands keys, how does the server know which public key to match the current user's private key?
It doesn't. It doesn't need to. It has two public keys in hand right now; it only needs to match the two public keys, which is easy, because they either match bit for bit, or don't. So all it has to do at this point is scan the entire authorized_keys file, line by line, checking: does this line have the same public key?
It will, of course, have to authenticate further: just having the public key doesn't mean that you are who you claim to be, yet. But this suffices for the first pass. Having found the (or "a") right line in the authorized_keys file, sshd can now use the options to decide who you are, if you pass the rest of the authentication process.