Log inGet Vallkey

Search the help center, features, guides and more.

Developers

The SSH agent

Keep SSH keys in your Vallkey vault and sign with them from the terminal: making a key, starting the agent, and using it with ssh and git.

Vallkey’s command line can act as your SSH agent, signing with the SSH keys in your vault. ssh and git use it as they are. It runs on macOS and Linux.

Make a key

vallkey ssh-key create --title "Laptop"

That makes an Ed25519 key, keeps it in your vault, and prints its public key, for GitHub or a server’s authorized_keys. Keys you’ve imported, or saved as SSH key items, work too. vallkey ssh-key list shows each key’s fingerprint and public key.

Start the agent

vallkey ssh-agent

It prints SSH_AUTH_SOCK=…, and signs until you stop it with Ctrl-C. Point SSH at it in that shell:

export SSH_AUTH_SOCK=…
ssh git@github.com

Or name the socket as IdentityAgent in ~/.ssh/config, for some hosts or all.

Ask before each signature

vallkey ssh-agent --confirm

asks before every signature, with the program named in SSH_ASKPASS, as ssh-agent -c does.

What to know

  • Ed25519 and ECDSA P-256 keys. RSA keys are left out, and the agent says which keys it left out.
  • It lists keys and signs, and nothing else. Adding or removing keys through the agent is refused: the vault is where keys are kept.
  • It holds the keys while it runs, decrypted, as any agent does. Stop it to forget them.
  • Its socket is yours alone.
  • In an organization, a key in a fill-only vault signs without ever being shown, and each use goes in the audit log.
  • The agent runs on macOS and Linux.

Last updated October 4, 2026