Secure SSH & Git
Keep private keys in the vault. Git and SSH should sign through Authsia’s agent — not by exporting keys into the shell.
Adopt keys
Preview, then import existing keys into a vault folder such as Infra/SSH.
Point SSH at Authsia
Enable shell integration and confirm the agent lists identities.
Headless signing uses a separate SSH-only credential. Shell integration and authsia exec obtain Bridge-issued, process- or terminal-bound leases without writing the bearer into the runtime grant file.
Git
Use the same agent for git fetch, git push, and SSH-based remotes. Do not copy private key files into agent-readable workspace paths.
Approvals
For direct host-bound SSH authentication, a session-based key offers Allow Once, Allow for the configured SSH duration, and Deny. The reusable approval is scoped to the key, trusted server host key, SSH username, and the live terminal, IDE, or coding-agent process. The Git operation shown in the prompt is context for the decision; it does not restrict repositories, branches, or server commands.
Authsia only offers scoped or remote approval when the server key is already trusted for that host in your standard user or system known_hosts file. Unknown hosts, custom known-host files, host certificates, traditional non-host-bound authentication, and forwarded agents continue to use local per-key approval.
The existing SSH Approval Session Duration setting controls local and paired-iPhone reusable approvals. Enable Approve SSH requests on paired iPhone under remote approval settings to opt in. Pairing by itself does not enable SSH approval. The Mac remains online, keeps the private key and passphrase, verifies the signed phone decision, and issues the grant.
Access Center shows active and historical SSH approvals with their key, destination, caller identity, approval source, expiry, and use count. Revoke one there, or use Revoke all access to end every active SSH approval.
authsia lock also revokes SSH JIT grants matching the current terminal or observed caller, while clearing the legacy terminal approval-session status.
Automation
Create a separate SSH automation credential when a script needs signing without an interactive session: