Work

Vault

Check your SSH keys in the Keychain, keep snippets, read and export the audit log, and learn how saved secrets are stored.

The Vault group in the left rail holds what you keep across sessions: your keys, your saved commands and the record of what happened. This page also covers how Gatesys SSH stores passwords and API keys.

Keychain

The Keychain lists every key in ~/.ssh plus whatever your SSH agent holds, cross-referenced with the hosts that use each one.

ColumnShows
NameThe key file, or the agent’s comment for an agent-only key
TypeThe key algorithm
FingerprintClick to copy
Used byThe hosts configured with this key
StatusSee below
StatusMeaning
InsecureA DSA key, or an RSA key shorter than 3072 bits. Replace it
RotateOlder than three years. Consider a new one
In agentLoaded in the running agent
On diskA key file that is not loaded in the agent

If the list is empty, there are no keys in ~/.ssh and no agent is running. See Authentication.

Snippets

Snippets are saved commands you can run in any session in one click.

  1. Open Snippets and add one with a Name, a Command and an optional Description.
  2. Drag snippets to reorder them. That order is the custom sort in the terminal’s Snippets menu.
  3. Run one from the terminal header’s Snippets menu. It is sent to the focused pane followed by a newline.

Snippets also appear in the command palette. A command Farabi suggested can be saved as a snippet with one click.

Audit log

The audit log records what happened, each entry tied to the host it happened on. It updates live while open and is kept for 90 days, stored on this computer.

It records, among other things:

  • Sessions opened and closed, and refused connections with Hop Doctor’s diagnosis and any fix applied
  • File transfers and remote file changes: save, rename, permissions and delete
  • Tunnels started and stopped
  • Hosts added from a sentence or a pasted command
  • Watches started, fired and ended
  • Snippet runs, and Farabi commands you inserted or ran, with the runtime and model that suggested them
  • Every host-facts read, and config changes applied, kept, reverted or restored through Safe Change

Filter by kind: All, Session, Snippet, SFTP, Tunnel, Host, Change, AI and Denied.

Export CSV saves the log as a spreadsheet file. No cell can run as a spreadsheet formula when you open it. Clear empties the log after asking.

What the audit log leaves out

The log keeps what an action led to, not its content. It never holds file contents or diffs, a watch’s output, a model’s words or your questions to Farabi one by one. Sentences are stored with secrets masked.

Credential storage

Passwords, key passphrases, cloud API keys, your Gatesys sign-in and hooks’ signing secrets are sealed with AES-256-GCM under a random vault key. The key is kept in a file next to the app’s config, readable only by you (mode 0600), and never inside the config itself.

  • Updates keep your secrets. The key is the app’s own, so a new version or a re-signed build never asks for them again.
  • What it protects against: a casual read of the config file, and backups that copy the config JSON alone.
  • What it does not protect against: someone who already has access to your files as you.

Secrets saved by earlier versions in the operating system’s keychain move into the vault at the next launch where the keychain lets the app read them.

Settings › Safety › Vault and keys › Local vault shows Encrypted when all is well. If it shows Unavailable, secrets are not saved and you are asked for them each time.

The facts Gatesys SSH keeps about your hosts and the service map are sealed under the same key. See Host facts.

Forget a secret

  • A host’s password or passphrase: host editor › Authentication › Forget.
  • A cloud API key: Settings › Farabi › Model, next to the key, Forget.
  • Deleting a host forgets its secrets too.

Something unclear or wrong? Tell us.