SSH Certificate Management: Replace Keys with SSO + MFA | Smallstep

Extend SSO & device identity to SSH

Short-lived SSH certificates provide stronger security with less operational overhead. Smallstep SSH secures remote access across cloud, on-prem, and hybrid environments for developers, automation, and modern AI and MCP-driven workflows.

No more static keys

Easy onboarding & offboarding

API for ephemeral container spin-ups

Daily renewals & automated rotation

SCIM integrations

No SSH bastion overhead

Bridge the gap between your IdPs and your servers

Automate SSH key management

Replace long-lived SSH keys with ephemeral certificates that regenerate each day. Static SSH keys often linger in servers and laptops for months or years, creating a ticking time bomb for unauthorized access. They’re easy to lose track of, hard to rotate, and seldom rekeyed.

Secure GitHub access and commit signing

Developers authenticate to GitHub with the same SSH keys that sit unrotated on their laptops for years. Smallstep replaces them with short-lived certificates issued to keys generated in the device's own secure hardware, so push access follows the device and the person rather than a file. The same hardware key can also sign commits, a separate control that gives you cryptographic proof of authorship. Requires GitHub Enterprise.

Add MFA with your IdP

Connect to popular IdPs like Okta, Google Workspace, or Microsoft Entra ID with just a few clicks, and map existing identity provider groups directly to server roles. Assign granular access based on familiar group structures and user roles, no separate password or SSH key needed. Add or remove a user in your IdP, and that change propagates to all SSH access immediately.

Short-lived certificates for strong security

(Try saying that 10x fast.) Smallstep SSH replaces static keys with ephemeral certificates that renew daily to lower risk exposure. Think of it like a backstage pass that automatically expires every day. Each certificate is valid for hours, not months, preventing unintentional long-term access. Certificates also automatically rotate without manual intervention or downtime.

Break-glass emergency and offline access

Worried about losing SSH access if your SSO provider is offline? Smallstep SSH supports hardware-backed offline certificates. In an emergency, create a short-lived backup certificate stored on a secure device. This ensures you always have a fallback plan for critical infrastructure—even during an identity provider outage.

Centralize your SSH auditing

Get a single source of truth for SSH connections across your fleet. Track all SSH activities and sessions from a single dashboard for compliance and troubleshooting. From one dashboard, use simple rules to let developers connect only to which servers they need, exactly when they need it. View active sessions, manage user groups, and generate usage reports to keep stakeholders informed.

Lower operational overhead

No one likes toil. Reduce the time spent adding, removing, and rotating static keys. By removing manual key handling, you can reclaim engineering hours and limit downtime. New employees can be up and running in minutes, without specialized key setup required.

Get the data sheet

Smallstep SSH Device Identity ensures that only trusted, company-owned devices can access your critical infrastructure. This solution seamlessly integrates with SSH clients to manage hardware-bound SSH certificates, each containing a unique, hardware-attested identifier for the device.

Enforce device identity everywhere

Whether you’re working towards a compliance standard, closing gaps in policy enforcement, or preventing nation-state attacks, our team is here to show you how Smallstep can help.

FAQs SSH

How does Smallstep SSH differ from traditional SSH key–based authentication?

How does Smallstep SSH enforce user identity?

How does Smallstep SSH enforce device identity?

Does Smallstep SSH replace OpenSSH or require protocol changes?

How does Smallstep SSH eliminate SSH key management at scale?

How does Smallstep SSH support just-in-time (JIT) privileged access?

Can Smallstep SSH enforce fine-grained authorization or RBAC?

How does Smallstep manage account lifecycle for SSH?

How does Smallstep SSH prevent lateral movement attacks?

How does Smallstep provide auditing for SSH access?

How does Smallstep SSH integrate with broader Zero Trust architectures?

Does Smallstep support multi-cloud and hybrid infrastructure?

What happens if a user’s laptop is lost, stolen, or compromised?

Can Smallstep SSH replace bastion hosts or SSH gateways?