October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Cloudflare

Cloudflare Open-Sources OpenPubkey SSH (OPKSSH): OIDC Login for Ordinary SSH

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare announced on March 25, 2025 that it had open-sourced OpenPubkey SSH (OPKSSH) under the Apache 2.0 license and donated the code to the OpenPubkey project. OPKSSH lets people authenticate to standard OpenSSH with an identity from an OpenID Connect (OIDC) provider such as Google, Microsoft, or GitLab, instead of manually distributing long-lived public keys. It still uses SSH keys, but generates an ephemeral key bound to an OIDC identity and verifies it through OpenSSH’s existing AuthorizedKeysCommand hook.

The project is maintained at openpubkey/opkssh. Cloudflare described the release as a code donation and said it was not endorsing OPKSSH as a Cloudflare commercial product.

What Cloudflare actually open-sourced

OpenPubkey is the underlying protocol. It adds a public key to an OIDC ID token, producing a cryptographically bound OpenPubkey (PK) Token. OPKSSH is the SSH implementation that uses those tokens for ordinary SSH authentication.

The OpenPubkey project was already open source; the significant March 2025 change was releasing the more complete SSH implementation under Apache 2.0. Cloudflare inherited the code through BastionZero and donated it to the community project rather than launching a proprietary SSH product. Details of the announcement are in Cloudflare’s release post.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Which SSH problem does OPKSSH solve?

Traditional key-based access works well technically, but administration becomes difficult as teams and servers multiply. Operators must create keys, copy public keys to hosts, identify the person behind an unfamiliar fingerprint, remove keys during offboarding, and protect private keys on laptops, jump hosts, and build systems.

OPKSSH moves the primary administrative decision from “does this fingerprint exist in authorized_keys?” to “does this authenticated OIDC identity, issuer, and claim satisfy the server policy?” Keys are created when needed, have a finite lifetime (24 hours by default), and can be regenerated after expiry. This reduces key sprawl; it does not make a compromised account or endpoint harmless.

How the trust and login flow works

  1. The user runs opkssh login.
  2. OPKSSH creates an ephemeral SSH key pair.
  3. A browser opens an OIDC login with the configured identity provider.
  4. The provider authenticates the user and returns an ID token.
  5. OpenPubkey binds the user’s public key to that identity in a PK Token.
  6. OPKSSH stores the generated key and token material in the user’s .ssh directory (the documented default private key is ~/.ssh/id_ecdsa).
  7. The user runs an ordinary command such as ssh [email protected].
  8. The server’s sshd invokes OPKSSH through AuthorizedKeysCommand.
  9. OPKSSH verifies the token, issuer, audience, expiration, and configured identity or claim policy before SSH creates the Unix session.
User → OIDC provider → OpenPubkey-bound ephemeral key → normal SSH client → sshd AuthorizedKeysCommand → OPKSSH verification → Unix account

No SSH protocol, client, or server implementation change is required. The server does need the OPKSSH verifier and a correct sshd configuration. OPKSSH uses the standard OpenSSH extension points described in the installation documentation.

Providers and platforms

The repository currently lists compatibility with Google, Microsoft/Azure, GitLab, hello.dev, Authelia, Authentik, Keycloak, Zitadel, PocketID, AWS Cognito, and Kanidm. Custom OIDC providers are also possible when issuer, client ID, client secret, scopes, claims, and redirect URI are configured correctly. “Supported” here means repository-documented compatibility, not a guarantee that every provider deployment works without adjustment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The repository lists these client and server targets:

Target Repository status
Linux client Supported and tested on Ubuntu 24.04.1 LTS
macOS client Supported and tested on macOS 15.3.2
Windows 11 client Supported and tested
Android client Experimental; tested with Termux
Linux server Supported and tested
Windows server Installation scripts are provided

Those versions describe the repository’s stated test coverage at the time of writing, not every distribution, CPU architecture, OpenSSH build, or future operating-system release.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Install an OPKSSH client

Use the repository’s current release artifacts and check their signatures or checksums according to your organization’s normal software-supply-chain policy.

macOS

brew tap openpubkey/opkssh
brew install opkssh
opkssh login

Linux x86_64

curl -L https://github.com/openpubkey/opkssh/releases/latest/download/opkssh-linux-amd64 
  -o opkssh
chmod +x opkssh
./opkssh login

Linux ARM64

curl -L https://github.com/openpubkey/opkssh/releases/latest/download/opkssh-linux-arm64 
  -o opkssh
chmod +x opkssh
./opkssh login

Windows

winget install openpubkey.opkssh

Alternatively:

curl https://github.com/openpubkey/opkssh/releases/latest/download/opkssh-windows-amd64.exe -o opkssh.exe

After the browser login completes, use normal SSH syntax:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
ssh [email protected]

The generated credential’s default validity is 24 hours, although the expiration policy can be configured.

Configure a Linux server

Install the verifier

wget -qO- "https://raw.githubusercontent.com/openpubkey/opkssh/main/scripts/install-linux.sh" | sudo bash

The script installs OPKSSH and configures SSH to use it as an additional authentication mechanism. The documented configuration is:

AuthorizedKeysCommand /usr/local/bin/opkssh verify %u %k %t
AuthorizedKeysCommandUser opksshuser

Check the effective configuration rather than relying only on the file you edited:

sudo sshd -T | grep authorizedkeyscommand

Files in /etc/ssh/sshd_config.d/ are processed in an order that can affect precedence. If another fragment wins, give the OPKSSH fragment an appropriate lower numeric prefix, then validate and reload SSH using your distribution’s normal procedure. Keep an existing administrative access path available while testing so a configuration mistake does not lock you out.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Register a dedicated OIDC client

Create a new client ID specifically for OPKSSH. Do not reuse the client ID assigned to another OIDC service: sharing an audience can create token-replay opportunities between services. Register one of the redirect URIs documented by the project:

http://localhost:3000/login-callback
http://localhost:10001/login-callback
http://localhost:11110/login-callback

Match the issuer, audience, scopes, and redirect URI exactly. Enforce MFA and sensible session controls in the identity provider.

Map identities to Unix accounts

For a single identity, the repository gives this form:

sudo opkssh add root [email protected] google

For a group claim:

sudo opkssh add root oidc:groups:ssh-users google

For a custom claim:

sudo opkssh add root oidc:"https://acme.com/groups":ssh-users google

These commands express identity-to-account authorization; they do not create least privilege automatically. Granting root grants root. Prefer named Unix accounts, narrowly scoped groups, sudo rules, and SSH restrictions. Review how your provider formats email, group, and custom claims before relying on them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Renewal, logout, and ordinary SSH protocols

When a generated key expires, authenticate again and retry SSH:

opkssh login
ssh [email protected]

Remove OPKSSH-generated keys with:

opkssh logout

Or remove one selected key:

opkssh logout -i ~/.ssh/opkssh_server_group1

Because the resulting key is used by normal SSH authentication, the same identity can be used with SFTP and tunnels:

Rank #4
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
sftp [email protected]
ssh -L 8080:internal.example:80 [email protected]

OPKSSH does not add application-layer authorization to those protocols. The Unix account, filesystem permissions, forwarding settings, and other SSH controls still decide what the session can do.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Security review before production use

  • Protect the identity provider. A stolen OIDC session or compromised endpoint can obtain SSH access until the relevant credential and account are contained.
  • Keep the audience separate. Use an OPKSSH-specific client ID and verify redirect URIs.
  • Use claims deliberately. Group claims can simplify administration, but stale membership or an overly broad group can authorize too much.
  • Do not assume installation revokes old keys. Existing authorized_keys entries and other authentication methods remain active until you remove or disable them.
  • Plan emergency access. Preserve a separately protected break-glass credential, console path, or administrator account for an identity-provider outage.
  • Separate people from machines. Browser-based login is convenient for human operators; CI jobs, scheduled tasks, and headless recovery systems need a separately designed noninteractive identity pattern.
  • Audit the Unix boundary. OPKSSH decides who may authenticate; Unix accounts, sudo, chroots, forwarding policy, and file permissions determine effective privilege.

Troubleshooting common failures

The key has expired

The default 24-hour window can produce an ordinary SSH authentication failure. Run opkssh login again and retry.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The provider login succeeds but authorization fails

Check the configured provider alias, issuer URL, client ID and audience, email or group claim, OPKSSH policy, and the Unix account named in the SSH command. Authentication by the IdP does not imply that the server policy accepts that identity.

The server is not using OPKSSH

Run:

sudo sshd -T | grep authorizedkeyscommand

Inspect included configuration fragments and their numeric ordering if the command is empty or points to a different verifier.

The client offers too many keys

Limit the attempt to the generated key:

ssh -o "IdentitiesOnly=yes" -i ~/.ssh/opkssh_server_group1 [email protected]

This avoids unrelated keys consuming the server’s MaxAuthTries allowance.

The browser or identity provider is unavailable

OPKSSH cannot mint a fresh credential without the configured OIDC flow. Use the preplanned break-glass path; do not assume the tool provides offline recovery.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who should use OPKSSH?

Good fit

  • Teams that already operate an OIDC provider.
  • Human-centered SSH operations where browser login and periodic renewal are acceptable.
  • Organizations seeking to stop copying long-lived keys while retaining ordinary OpenSSH clients and servers.
  • Homelabs and small infrastructure teams that prefer a lightweight, self-hosted component.

Use caution

  • Air-gapped or disconnected environments that cannot depend on live issuer metadata or key validation.
  • Large automation estates requiring noninteractive credentials and outage-independent operation.
  • Regulated environments requiring a formal independent audit, SLA, vendor support, centralized session recording, or command-level controls.
  • Deployments needing resource-level authorization beyond identity, claims, and Unix-account policy.

OPKSSH compared with other approaches

Option What it adds Best fit Main trade-off
OPKSSH OIDC-bound ephemeral keys through standard OpenSSH OIDC-first teams wanting a small SSH-only bridge IdP dependency; limited platform and session-management scope
Native OpenSSH CA Short-lived SSH certificates issued by your own CA Teams comfortable operating certificate enrollment and identity lifecycle You must build or run the CA and authorization workflow
Smallstep SSH SSH certificates, IdP integration, lifecycle controls, logging, and reporting Teams wanting managed certificate operations Professional features and OIDC SSO require the appropriate commercial plan
Cloudflare Access for Infrastructure Managed short-lived certificates, policies, logging, and Cloudflare Tunnel integration Organizations already using Cloudflare One Cloudflare network and service dependency
Teleport SSH plus Kubernetes, databases, Windows, web apps, and centralized audit Broad infrastructure-access programs More components and usage-based commercial pricing
HashiCorp Boundary Central brokering, time-bound credentials, dynamic targets, and Vault integration Multi-protocol or dynamic infrastructure access Controllers, workers, and a broader access plane exceed a simple SSH add-on

Verdict

OPKSSH is compelling when the requirement is precise: use existing OIDC identities with ordinary SSH while replacing manually managed, long-lived keys with short-lived, identity-bound credentials. It is not a replacement for SSH, an automatic least-privilege system, or a complete privileged-access platform. Evaluate the identity-provider dependency, headless automation, emergency access, Unix-account privilege, and operational support requirements before deploying it broadly.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.