Skip to content
Triwarden

Guide · SSH agent

Your SSH keys,
in your vault.

Triwarden can answer ssh and git the way ssh-agent does, from SSH Key items in your vault. The private key never leaves the app, and every signature asks you first.

ssh · gitagent socketTriwardenYou approvesignature
ssh asks the agent to sign. Triwarden asks you — Touch ID or your Mac password — signs inside the app, and sends back only the signature.

Set up

Four steps,
about two minutes.

  1. 01

    Turn on the agent

    Open Triwarden › Settings › Developer and switch on Use Triwarden as SSH agent. It runs while the app is open and offers keys only while your vault is unlocked.

    Triwarden Settings › Developer: Use Triwarden as SSH agent, Ask before signing, and SSH setup with Copy buttonsTriwarden Settings › Developer: Use Triwarden as SSH agent, Ask before signing, and SSH setup with Copy buttons
  2. 02

    Add a key

    Make a new SSH Key item. Press Generate Ed25519 Key for a fresh one, or paste a private key you already have — an unencrypted OpenSSH key (-----BEGIN OPENSSH PRIVATE KEY-----). Ed25519, ECDSA (P-256, P-384, P-521) and RSA all work, and SSH keys saved by other Bitwarden apps show up too.

    Key has a passphrase? The agent can’t use encrypted keys. Make an unencrypted copy, paste it into the item, then delete the copy — the vault keeps it encrypted from then on.

    New SSH Key in the detail panel: name, folder, private key with Generate Ed25519 Key, public key and fingerprintNew SSH Key in the detail panel: name, folder, private key with Generate Ed25519 Key, public key and fingerprint
    Remove a passphrase (on a copy)
    cp ~/.ssh/id_ed25519 /tmp/key
    ssh-keygen -p -N "" -f /tmp/key
    # paste /tmp/key into the item, then:
    rm /tmp/key
    
  3. 03

    Point ssh at it

    Add the agent to ~/.ssh/config — Settings › Developer › SSH setup has a Copy button with your own path filled in. Or set it for a single shell.

    Prefer the config file: apps opened from the Dock (VS Code, Tower, Fork, Xcode) don’t see your shell’s variables, but every ssh reads the config.

    ~/.ssh/config
    Host *
      IdentityAgent "~/Library/Group Containers/…/agent.sock"
    
    zsh
    export SSH_AUTH_SOCK="$HOME/Library/Group Containers/…/agent.sock"
    
  4. 04

    Check it works

    ssh-add -L lists the public keys the agent offers. Nothing there? See the fixes below.

    Terminal
    ssh-add -L
    ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKx…Qx9 GitHub
    ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIM2…7mK homelab
    

Everyday use

Every place
ssh shows up.

GitHub and GitLab

Copy the item’s public key into GitHub › Settings › SSH and GPG keys as an Authentication key (GitLab: User settings › SSH keys). Then test it:

Terminal
ssh -T git@github.com
# Triwarden asks: allow “ssh” to sign with “GitHub”
Hi alexchen! You've successfully authenticated, but GitHub does not provide shell access.

Your servers

Put the public key in ~/.ssh/authorized_keys on the server, then ssh in as usual. Only signatures go over the wire.

Terminal
ssh alex@nas.home.arpa 'cat >> ~/.ssh/authorized_keys' < homelab.pub
ssh alex@nas.home.arpa

Signed git commits

On the key’s page, Git signing › Copy Setup gives you these three lines. Add the same public key to GitHub as a Signing key and your commits show Verified.

Git signing › Copy Setup
git config --global gpg.format ssh
git config --global user.signingkey "key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKx…Qx9 GitHub"
git config --global commit.gpgsign true

To check signatures locally too, list the keys you trust:

Terminal
echo "alex@example.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKx…Qx9" >> ~/.ssh/allowed_signers
git config --global gpg.ssh.allowedSignersFile ~/.ssh/allowed_signers
git log --show-signature -1
Good "git" signature for alex@example.com with ED25519 key SHA256:…

Several keys

With many keys, a server can stop at “Too many authentication failures” before it reaches the right one. Save that key’s public half to a file and pin it to the host:

~/.ssh/config
Host github.com
  IdentityFile ~/.ssh/github.pub
  IdentitiesOnly yes

Only some hosts

Rather keep another agent for everything else? Use Triwarden for named hosts only:

~/.ssh/config
Host github.com gitlab.com nas.home.arpa
  IdentityAgent "~/Library/Group Containers/…/agent.sock"

Git apps and editors

VS Code, Tower, Fork, Xcode and anything else that runs the system’s ssh pick up ~/.ssh/config, so they work once step 3 is done. The approval appears for them the same way.

Approvals

Nothing signs
without you.

Each request names the program and the key — “allow ssh to sign with the SSH key GitHub”. Choose how often to be asked in Settings › Developer › Ask before signing:

Every time
the default: one prompt per signature
Once per minute, per app
handy for a burst of git fetches
Once per 10 minutes, per app
for long sessions; locking forgets it

No Touch ID — a Mac mini, a Mac Studio, a closed lid? macOS asks for your Mac password instead, and Deny refuses. Settings › Developer lists the last few requests, allowed or denied.

Fixes

When it
doesn’t work.

“The agent has no identities.”

The vault is locked, the agent is off, there are no SSH Key items, or the key in the item has a passphrase (encrypted keys aren’t offered).

“Could not open a connection to your authentication agent”

This shell doesn’t know where the agent is. Add the IdentityAgent line to ~/.ssh/config, or run the export from step 3 in that shell.

“agent refused operation”

The request was denied, or the prompt was left until it timed out. Run the command again and approve.

“Too many authentication failures”

The server gave up before reaching the right key. Pin the key to the host (Several keys, above).

Ready when you are.

Free to try with every feature, the SSH agent included.

Download for Mac