Authentication
Thirteen methods, from a saved password to a key that never exists in software at all.
- Password and SSH key — The common cases, including a key with a password fallback for servers that reject it.
- Keyboard-interactive / MFA — Each prompt the server sends is surfaced as a dialog, so one-time codes work normally.
- SSH agent — Uses your running agent, including FIDO2 security keys, which prompt for a touch during the handshake.
- Hardware-backed — PKCS#11 tokens such as a YubiKey in PIV mode, or a non-exportable key generated inside your PC's TPM or a Mac's Secure Enclave. The private key never exists in software; every connection needs the physical gesture.
- External secret managers — Fetch the password at connect time from pass, Bitwarden, AWS SSM Parameter Store, Doppler or 1Password rather than storing it.
- CA-signed certificates — HashiCorp Vault SSH issues a short-lived certificate instead of trusting a static key.
Host key trust
MangoSSH trusts a host key on first use and warns loudly if it later changes. A prompt on a host you have connected to before is worth taking seriously. Certificate revocation lists are supported for fleets using a CA.
Inherited credentials
Groups can carry a credential or a bastion that every host in them inherits, so a shared jump host is configured once. A value set explicitly on a host always wins.
Step-by-step guides
How to set each of these up, one task per page.
- Keys and sign-in methods →Passwords, key files, agents, FIDO2, smartcards, Windows Hello, TOTP and password managers.
- SSH certificates →Short-lived certificates from the built-in MangoSSH CA or HashiCorp Vault.
- Identities and groups →Reusable credentials and folder-level inheritance, including jump hosts.
Full detail
Step-by-step instructions, how to check each one worked, and what to do when it did not.