SSH signing
Adopt keys into Authsia, then let Git and SSH use the local agent. Headless signing uses a separate SSH-only credential; shell integration and authsia exec obtain Bridge-issued, process- or terminal-bound leases without writing the bearer into the runtime grant file.
The SSH agent consumes an automation credential use before signing. If signing fails, that use remains spent.
Adopt SSH keys in the app
On macOS, open Vault → New Item dropdown → Import from Files → Adopt SSH Keys. Preview the keys in ~/.ssh, choose a destination folder, and select keys. One vault approval stores and verifies each key before its local private key becomes an Authsia stub; SSH config annotations recognize equivalent symlinked key paths. Clear Replace originals after saving to store keys without changing local files. An existing SSH key in the destination folder is replaced only when you select Overwrite existing value, and its host restrictions are kept. See Import from files for the full flow.
Scoped approvals
Verified host-bound SSH authentication can be approved once or for the configured SSH session duration, locally or from an opted-in paired iPhone. Reusable grants bind the key, trusted destination, SSH user, and live caller. Review and revoke them in Access Center.
authsia lock revokes matching SSH JIT grants for the current terminal or observed caller, in addition to clearing the legacy terminal approval-session status.