NoKey — SSH without static keys.

Reach a production machine with no static key and no bastion. Engineers connect by device identity, root is a signed grant that expires in minutes, and every session lands in a ledger — from a laptop, or from the phone in your pocket.

A static SSH key is a mechanical key cut in dozens of copies and handed out over the years. Nobody remembers who holds which copy, to which door. The copies don't expire, and they don't leave when the person does.

Key sprawl nobody can map.
No key to sprawl. Engineers reach machines by device identity — there is nothing to copy, store, or lose track of.
EvidenceThe average organization holds ~23,000 SSH keys and 90% are unmanaged (Ponemon / Venafi — magnitudes hold across surveys).
Keys never rotate, and never leave.
Offboarding a person is revoking one identity. No key hunt, no orphans left behind on the fleet.
Evidence46% of organizations never rotate keys; on average every server carries one orphan root key of someone already gone (Venafi).
The bastion is a public door.
The SSH server binds inside the overlay — no port on the internet, no bastion, and it never touches your existing sshd.
EvidenceA jump host listening on the internet is one more appliance to patch and one more thing to scan.

Does this sound like your fleet?

Tick what's true. No sign-up, nothing sent — just for you.

That's the door. Try it on one machine in five minutes — free, no account beyond GitHub sign-in.

Download free

How it works, in one paragraph

NoKey swaps the static key for a door that opens on the person plus a badge that expires. Engineers reach machines by device identity — the enrolled device is the credential, not a file on disk. A normal user account is provisioned for you automatically; root is a signed grant that lives at most fifteen minutes and falls away on its own, each elevation logged per operation. Every session start lands in your ledger. The SSH server binds inside the overlay, so there's no port on the internet and no bastion to run — and it never touches your existing sshd. Fifteen minutes isn't an exotic number: the industry's short-lived credentials already speak in minutes — Cloudflare mints 3-minute SSH certificates, EC2 Instance Connect keys live 60 seconds. And because the client is an engine rather than a wrapper around system SSH, it runs where a static key never could — including an iPhone.

Is NoKey the right choice for you?

Reach for us when you run your own machines — VPS, on-prem, mixed cloud — and want engineers on them without a bastion, a public port, or a key file to manage; when mobile access matters; and when you'd rather the connection go straight between you and the box than route through a vendor.

Reach for someone else when your requirement is full session recording as a first-class, tamper-evident audit product — that's a different tool's home turf, and we won't pretend a ledger of session starts is the same thing. Same if a funded PAM program already covers privileged access across your estate. We list what NoKey doesn't do yet on honest limits.

One choice among several — this page exists so you can tell which one you're looking at.

In the same mesh

The other public door most teams keep open is the VPN — internal apps behind a gateway attackers scan for. NoVPN gives those apps private names instead. And the machine that deploys to prod carries its own static secret; NoSecret removes that one. Same mesh, same shape.