Account → Account Security → My SSH public keys
Register the SSH public keys you sign in to the SSH gateway with.
- Add SSH public key — give the key a name (for example the device it lives on) and paste one public key line, such as the content of
~/.ssh/id_ed25519.pub. Accepted: Ed25519, ECDSA (P-256, P-384, P-521), their security-key (sk-) variants, and RSA of 3072 bits or more. Never paste a private key; it is refused. Choose an expiration date within your administrator’s maximum lifetime. A positive limit makes expiration required and prefills the latest permitted date; without a limit you may leave it empty. The key expires at 00:00 UTC on the selected date. - Delete — the key stops signing in at once, and a direct connection opened with it loses access to the platform.
- The list shows each key’s fingerprint (
SHA256:…), type, and when it was created and last used — never the key itself.
Adding or deleting a key needs a signed-in browser session; an API key cannot change your SSH keys.
Lifetime policy
Administrators configure max_ssh_key_lifetime under Advanced Settings. It is a whole number of days from registration (0–3650); 0 means unlimited and is the default. The limit applies to newly registered public keys. Existing keys keep their saved expiration when the setting changes.
The form loads the policy when opened and checks it again before saving. If settings cannot be loaded, use Retry; registration stays disabled. If a limit changes, your key and date remain in the form so you can correct the expiration. Direct API requests are subject to the same limit.
How the key signs you in
- Text UI (
ssh alice@company.com@shell.company.com): the key replaces your password. When your account requires a verification code, it is asked next; directory and single sign-on accounts complete with browser sign-in. See Native SSH access. - Direct connection to a resource (
alice@company.com/<location>/<resource>): on a resource whose owner turned on Allow personal SSH keys for native SSH automation, the key alone signs you in — no password, no verification code. See Connecting directly to a resource.
Deactivating or deleting your account ends every key’s access.