Vautir’s command line can act as your SSH agent, signing with the SSH keys in your vault. ssh and git use it as they are. It runs on macOS and Linux.
Make a key
vautir ssh-key create --title "Laptop"
That makes an Ed25519 key, keeps it in your vault, and prints its public key, for GitHub or a server’s authorized_keys. Keys you’ve imported, or saved as SSH key items, work too. vautir ssh-key list shows each key’s fingerprint and public key.
Start the agent
vautir ssh-agent
It prints SSH_AUTH_SOCK=…, and signs until you stop it with Ctrl-C. Point SSH at it in that shell:
export SSH_AUTH_SOCK=…
ssh git@github.com
Or name the socket as IdentityAgent in ~/.ssh/config, for some hosts or all.
Ask before each signature
vautir ssh-agent --confirm
asks before every signature, with the program named in SSH_ASKPASS, as ssh-agent -c does.
What to know
- Ed25519 and ECDSA P-256 keys. RSA keys are left out, and the agent says which keys it left out.
- It lists keys and signs, and nothing else. Adding or removing keys through the agent is refused: the vault is where keys are kept.
- It holds the keys while it runs, decrypted, as any agent does. Stop it to forget them.
- Its socket is yours alone.
- In an organization, a key in a fill-only vault signs without ever being shown, and each use goes in the audit log.
- The agent runs on macOS and Linux.
Last updated October 4, 2026