How it works
One enroll command installs a tiny, readable connector on your Mac. It only ever touches ~/.ssh/authorized_keys.
An agent sends its SSH public key with a plain-language purpose and a time limit. You get a request you can read in five seconds.
Tap approve from any device. Your machine installs the key itself - scoped, time-boxed, and logged. Revoke anytime.
Machine setup is one line - read the connector first if you like, it's short:
# connector installed - polls for your approvals, installs keys, removes them on expiry
$ # that's it. your machine handles the rest.
Why not just paste keys around?
Scoped to one thing
Every grant binds one agent, one key, one purpose, one machine. No standing access, no shared keys.
Expires on its own
Grants live 15-60 minutes. The connector removes the key when time is up or when you revoke.
Full audit trail
Every request, approval, install and removal is logged against the agent that asked.
Nothing hides from you
The connector is a short readable script. Keys are tagged in authorized_keys. We never see private keys.