Open source · End-to-end encrypted
Use your Android phone as a hardware-backed security key for your remote Linux servers.
No hardware to buy. No USB forwarding. Works where you can't plug in a YubiKey: SSH bastions, VPSes, headless servers, and admin panels.
How it works
1
Pair your phone
Scan a QR code in the Android app. Your phone is linked to the server. Only that phone can sign in from then on.
2
The server asks your phone to sign
When a website or app on your Linux server asks for a security key, the request is forwarded to your phone over an encrypted connection.
3
Sign in with your fingerprint
Your phone asks for a fingerprint or face. The secret used to sign never leaves your phone's built-in security chip.
Open sourceEnd-to-end encryptedSecrets never leave your phone