Vault
Check your SSH keys in the Keychain, keep snippets, read and export the audit log, and learn how saved secrets are stored.
The Vault group in the left rail holds what you keep across sessions: your keys, your saved commands and the record of what happened. This page also covers how Gatesys SSH stores passwords and API keys.
Keychain
The Keychain lists every key in ~/.ssh plus whatever your SSH agent holds, cross-referenced with the hosts that use each one.
| Column | Shows |
|---|---|
| Name | The key file, or the agent’s comment for an agent-only key |
| Type | The key algorithm |
| Fingerprint | Click to copy |
| Used by | The hosts configured with this key |
| Status | See below |
| Status | Meaning |
|---|---|
| Insecure | A DSA key, or an RSA key shorter than 3072 bits. Replace it |
| Rotate | Older than three years. Consider a new one |
| In agent | Loaded in the running agent |
| On disk | A key file that is not loaded in the agent |
If the list is empty, there are no keys in ~/.ssh and no agent is running. See Authentication.
Snippets
Snippets are saved commands you can run in any session in one click.
- Open Snippets and add one with a Name, a Command and an optional Description.
- Drag snippets to reorder them. That order is the custom sort in the terminal’s Snippets menu.
- Run one from the terminal header’s Snippets menu. It is sent to the focused pane followed by a newline.
Snippets also appear in the command palette. A command Farabi suggested can be saved as a snippet with one click.
Audit log
The audit log records what happened, each entry tied to the host it happened on. It updates live while open and is kept for 90 days, stored on this computer.
It records, among other things:
- Sessions opened and closed, and refused connections with Hop Doctor’s diagnosis and any fix applied
- File transfers and remote file changes: save, rename, permissions and delete
- Tunnels started and stopped
- Hosts added from a sentence or a pasted command
- Watches started, fired and ended
- Snippet runs, and Farabi commands you inserted or ran, with the runtime and model that suggested them
- Every host-facts read, and config changes applied, kept, reverted or restored through Safe Change
Filter by kind: All, Session, Snippet, SFTP, Tunnel, Host, Change, AI and Denied.
Export CSV saves the log as a spreadsheet file. No cell can run as a spreadsheet formula when you open it. Clear empties the log after asking.
What the audit log leaves out
The log keeps what an action led to, not its content. It never holds file contents or diffs, a watch’s output, a model’s words or your questions to Farabi one by one. Sentences are stored with secrets masked.
Credential storage
Passwords, key passphrases, cloud API keys, your Gatesys sign-in and hooks’ signing secrets are sealed with AES-256-GCM under a random vault key. The key is kept in a file next to the app’s config, readable only by you (mode 0600), and never inside the config itself.
- Updates keep your secrets. The key is the app’s own, so a new version or a re-signed build never asks for them again.
- What it protects against: a casual read of the config file, and backups that copy the config JSON alone.
- What it does not protect against: someone who already has access to your files as you.
Secrets saved by earlier versions in the operating system’s keychain move into the vault at the next launch where the keychain lets the app read them.
Settings › Safety › Vault and keys › Local vault shows Encrypted when all is well. If it shows Unavailable, secrets are not saved and you are asked for them each time.
The facts Gatesys SSH keeps about your hosts and the service map are sealed under the same key. See Host facts.
Forget a secret
- A host’s password or passphrase: host editor › Authentication › Forget.
- A cloud API key: Settings › Farabi › Model, next to the key, Forget.
- Deleting a host forgets its secrets too.
Something unclear or wrong? Tell us.