SSH BridgeSSH Bridge
Security

Vault, Known Hosts, and Device Security

SSH Bridge keeps sensitive SSH data behind account authentication, encrypted vault storage, host-key verification, and device session controls.

How SSH Bridge Access Works

Users first authenticate to SSH Bridge with email, SSO, and optional 2FA. Project roles determine which resources they may access. The remote system then authenticates the SSH, RDP, VNC, or database connection using an approved account, managed key, password, domain, or database user. Connection material remains encrypted according to the SSH Bridge security model and is used only for authorized workflows.

Encrypted Vault

The vault protects private SSH material and other sensitive connection data. When vault protection is enabled, the app asks you to unlock the vault before using protected credentials.

SSH Keys

Managed SSH keys can be stored in the Keys panel and then selected when creating or editing a host. Team-managed keys are visible with a team badge and remain managed by the team owner or admin. For routine server administration, prefer individual user accounts, SSH public-key authentication, and sudo for privileged operations.

Known Hosts

When SSH Bridge sees an unknown or changed host key, it shows a warning before continuing. This helps protect you from connecting to the wrong machine.

Device Sessions

Account devices and active sessions can be reviewed and revoked from the app. Use this when you lose a device, change phones, or want to clear old logins.