Guides · Connecting
Keys and sign-in methods
Every way MangoSSH can prove who you are to an SSH server: passwords, key files, your SSH agent, FIDO2 security keys, smartcards, Windows Hello or the Mac Secure Enclave, and server-driven MFA prompts. Pick the one that matches how the server is set up and where you want the private key to live.
- SSH hosts
- Windows · macOS · Linux
- About 15 minutes
Where you choose it
Open a host with Edit (or add one). Sign-in settings live in two places in the host form:
- General tab. Username, Password, Save password to OS keychain, and the Stored in an external secret manager instead? list. A host with nothing else chosen signs in with this password.
- Authentication tab. The How do you sign in? row: SSH Key, SSH Agent, FIDO2, Passkey, PKCS#11 and Interactive. The Add SSH Key, Certificate, or FIDO2 button at the bottom of the General tab jumps here.
The same tab has Use an Identity at the top. Picking an identity hides the method row, because the identity supplies it. See Identities and groups. For signing in with short-lived certificates, see SSH certificates.
Which method should I use?
| Method | Good for | Where the private secret lives | Unattended runs (Scripts) |
|---|---|---|---|
| Password | Quick access, appliances, servers you do not control | OS keychain, or typed at each connect | Yes, if saved |
| Key file | Most Linux servers. The usual default | A file on disk, optionally passphrase-protected | Yes |
| SSH Agent | Keys you already manage with ssh-add | Your agent process. MangoSSH never sees it | Yes, while the agent is running |
| FIDO2 | Phishing-resistant login with a YubiKey or similar | The security key. Needs a touch | Only with someone there to touch the key |
| PKCS#11 | Smartcards, CAC/PIV cards, YubiKey PIV | The token. Never leaves the hardware | Yes (PIN saved in the keychain) |
| Passkey | A hardware-backed key with no extra device | Your PC's TPM or your Mac's Secure Enclave | Prompts for Hello or Touch ID every connect |
| Interactive | Servers that ask their own questions: PAM, OTP codes, Duo | Nothing stored, except an optional TOTP secret | No |
If you are unsure: generate an Ed25519 key in MangoSSH, put its public half on the server, and use SSH Key → Key Only. Move to FIDO2, PKCS#11 or Passkey when you want the key to be impossible to copy off the machine.
Password
On the General tab, fill in Username and Password.
Tick Save password to OS keychain to keep it in Windows Credential Manager, the macOS Keychain or the Linux Secret Service. Leave it unticked and the password is discarded on save; MangoSSH asks for it every time you connect.
Leaving the password blank is fine. The connect dialog asks for it, and offers to remember it then.
Key files
On the Authentication tab, click SSH Key.
Under Which kind of key auth?, choose one:
- Key Only: the key alone logs you in. Pick this unless the server wants more.
- Key + Password: MangoSSH offers the key first and, if that does not complete the login, sends the password from the General tab. Use it for servers that require both (
AuthenticationMethods publickey,password). - Key + Interactive Login: the key, then the server's own prompts (an OTP code, a Duo push). For servers set to
AuthenticationMethods publickey,keyboard-interactive. See Keyboard-interactive and TOTP codes.
Set Private key file path, or click Browse…. A relative path is resolved from your home folder, so
.ssh/id_ed25519works.If the key is encrypted, enter Passphrase (if encrypted) and tick Save passphrase, or leave it blank to be asked on connect. MangoSSH checks the file first and only asks when the key really is encrypted.
Keys must be in OpenSSH or PEM format (the file starts with -----BEGIN). If you only have a PuTTY .ppk file, export it from PuTTYgen with Conversions → Export OpenSSH key.
For RSA keys, MangoSSH tries the modern rsa-sha2-512 and rsa-sha2-256 signatures first and falls back to legacy ssh-rsa only for servers too old to accept anything else.
Generate and manage keys
Open SSH Keys from the sidebar. The page lists every key MangoSSH has generated or imported, with its type, fingerprint and age. The private halves are kept encrypted with a key held in your OS keychain.
Generate a key
Click Generate. Give the key a name and pick Ed25519 (recommended) or RSA 4096. Use RSA only for servers that do not accept Ed25519. The passphrase is optional.
Click Generate. Copy the public key (Copy Public Key or Save .pub File) and add it to the server's
~/.ssh/authorized_keys.Click Save Private Key File and save it somewhere stable, such as your
.sshfolder. A host needs a real file path, so paste that path into the host's Private key file path.
Lost the file? The key's row in the list has a save private key file button that exports it again. Import adds a key you already have: paste the PEM text or use Browse File…, and add the public key if you want to deploy it later.
Deploy, rotate and remove keys on servers
Manage on Hosts… edits ~/.ssh/authorized_keys on servers you are currently connected to. Connect to the targets first, then open it and tick the hosts.
| Button | What it does |
|---|---|
| Deploy | Appends the key to authorized_keys. A key that is already there, even under another comment, is not added twice. |
| Deauthorize | Removes the key's line. Make sure you keep another way in. |
| Preview rotation | Reads each host's authorized_keys and reports what a rotation would add and remove. Changes nothing. |
| Rotate… | Generates a new key of the same type, deploys it, logs in with it on a fresh connection, and only then removes the old key. If the check fails on a host, the old key stays there. |
Rotation warns you if the old key's line carries restrictions (such as from= or command=) that the new key would not inherit. When it finishes, it asks you to save the new private key. Point your hosts' Private key file path at that file; rotation does not edit saved hosts for you.
Age badges help you decide when to rotate: green under 90 days, amber under a year, red after.
SSH agent
With SSH Agent, MangoSSH asks your running agent to sign the login. The private key never touches MangoSSH, which offers each key the agent holds until the server accepts one. The accepted key's algorithm and fingerprint go into the audit log.
- Windows: MangoSSH talks to the Windows OpenSSH agent on
\\.\pipe\openssh-ssh-agent. Pageant is not supported. Start the service once, as administrator:Get-Service ssh-agent | Set-Service -StartupType Automatic Start-Service ssh-agent ssh-add $HOME\.ssh\id_ed25519 - macOS and Linux:
SSH_AUTH_SOCKmust be set in the environment MangoSSH starts from. Desktop sessions usually set it for you.
Run ssh-add -l before connecting to check the agent actually holds your key. To use your agent from inside the remote shell as well, turn on agent forwarding on the host's Session tab.
FIDO2 security keys
FIDO2 keys (sk-ssh-ed25519, sk-ecdsa) are used through your SSH agent. Click FIDO2 on the Authentication tab; the host is saved with the agent method, and the touch prompt happens on the physical key when the server asks for a signature.
Create a key on the security key, if you do not have one. A resident key can be loaded again on any machine:
ssh-keygen -t ed25519-sk -O residentAdd the
.publine to the server's~/.ssh/authorized_keys. The server needs OpenSSH 8.2 or later.Load it into your agent:
ssh-add -Kloads resident keys from the device;ssh-add ~/.ssh/id_ed25519_skloads a key file.Connect, and touch the key when it blinks.
Smartcards and YubiKey PIV (PKCS#11)
PKCS#11 signs the login directly on a smartcard, CAC/PIV card or a YubiKey in PIV mode, with no agent in between. The private key never leaves the token.
MangoSSH currently finds and uses RSA keys on the token. An ECDSA key on the same card is not listed. There is also no PIN prompt yet: the PIN must be saved in the keychain.
Install a PKCS#11 module. MangoSSH does not bundle one. OpenSC (
opensc-pkcs11.dll/.so) works with most cards; Yubico shipsykcs11.Click PKCS#11. Fill in PKCS#11 module path (or Browse…) and the token PIN, and tick Save PIN to OS keychain.
Insert the token and click Detect Keys. Pick the key from the Key list; each entry shows its label and slot.
Put the token's public key on the server. OpenSSH can read it straight from the module:
ssh-keygen -D /path/to/opensc-pkcs11.so # prints one line per key; add the right one to authorized_keys
Windows Hello and the Mac Secure Enclave
Passkey creates an SSH key inside your computer's own security hardware: the TPM through Windows Hello on Windows (RSA 2048), or the Secure Enclave on a Mac (ECDSA P-256). The key cannot be exported, and every connect asks for your Hello PIN, face or fingerprint, or Touch ID. It is not available on Linux.
Click Passkey. The status line says whether the hardware is available and whether a key already exists.
Click Generate Key and approve the prompt.
Click Copy next to Public key and add the line to each server's
~/.ssh/authorized_keys.
There is one such key per computer, shared by every host that uses this method. Generating again replaces it, so every server then needs the new public line.
Keyboard-interactive and TOTP codes
Some servers run their own login conversation (PAM with an OTP module, Duo, RADIUS). Click Interactive for that, or use Key + Interactive Login when the server wants a key first. MangoSSH shows a dialog for each round of questions and stores nothing. An unanswered dialog cancels the connection after three minutes.
Let MangoSSH answer the code
Both interactive modes show TOTP auto-fill (optional). Paste the Base32 secret your authenticator app was set up with (the text usually shown under the QR code) into Secret (Base32), and tick Save secret to OS keychain. MangoSSH then generates the 6-digit code itself.
It only answers a round that asks exactly one hidden question worded like a code prompt ("Verification code", "OTP", "authenticator", "one-time" and similar). A round that asks for a password, or several things at once, still opens the dialog. Leave the secret blank to keep typing codes yourself.
Scripts refuse to run against hosts on Interactive or Key + Interactive Login, because there is nobody to answer. Use a key for hosts you automate.
Passwords from a secret manager
If the password already lives in a secret manager, MangoSSH can fetch it at connect time instead of storing a copy. On the General tab, choose the source under Stored in an external secret manager instead?. MangoSSH runs that tool's command line, so the CLI must be installed, on your PATH and signed in.
| Source | You fill in | What MangoSSH runs | Before first use |
|---|---|---|---|
| pass | Pass entry name | pass show <entry> (first line) | gpg-agent unlocked |
| Bitwarden | Bitwarden item ID or name | bw get password <id> | bw login. MangoSSH asks for the master password if the vault is locked |
| AWS SSM | Parameter name, optional profile and region | aws ssm get-parameter --with-decryption | Any working AWS CLI credentials |
| Doppler | Secret name, optional project and config | doppler secrets get --plain | doppler login |
| 1Password | Secret reference (op://…) | op read <ref> | op signin, or the desktop app's CLI integration |
To go back to a stored password, pick None — use the password above. For passwords kept inside MangoSSH itself, see the Password manager.
Host key verification
Before any credential is sent, MangoSSH checks the server's host key, so you know you are talking to the machine you think you are.
- First connect. An Unknown Host Key dialog shows the key type and SHA256 fingerprint. Compare it with the server's own (
ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pubon the server), then click Yes, Trust & Connect or No, Cancel. MangoSSH also looks at your OpenSSH~/.ssh/known_hosts, and PuTTY's saved keys on Windows. If either holds a different key for this host, or marks this key@revoked, the dialog says so. - Changed key. If the server later presents a different key, a Host key has changed dialog shows the old and new fingerprints. That can be a reinstalled server or a recycled IP, or it can be an attack. Only click Replace & Connect when you know why it changed.
- Nobody answers. An unanswered prompt counts as No after two minutes.
- Scripts and jump-host hops cannot show a dialog. They trust a brand-new key silently, but refuse a changed one, and refuse a new key that your OpenSSH or PuTTY records contradict.
On the host's Advanced tab, Trusted host key (TOFU) shows the stored fingerprint, and Forget Host Key clears it so the next connect asks again. The same tab has Strict mode (modern algorithms only — no ssh-rsa / SHA-1 / CBC) for servers where you want to rule out legacy algorithms. Revocation lists for certificates are covered in SSH certificates.
Troubleshooting
| Symptom | Likely cause |
|---|---|
| “No password available for this host” | The keychain entry is missing on this machine (common after moving the app). Edit the host and enter the password again. |
| “Key parse error” | Wrong passphrase, or a format MangoSSH cannot read (such as .ppk). Convert the key to OpenSSH format. |
| “SSH agent unreachable” (Windows) | The OpenSSH agent service is not running. Start-Service ssh-agent, then ssh-add. |
| “SSH_AUTH_SOCK is not set” | MangoSSH was started without an agent in its environment. Start it from a session where ssh-add -l works. |
| “SSH agent has no keys loaded” | Run ssh-add (or ssh-add -K for a FIDO2 key). |
| PKCS#11: “No keys found” | Wrong PIN, token not inserted, or the key on it is not RSA. |
| PKCS#11: “No PKCS#11 PIN available” | Enter the PIN and tick Save PIN to OS keychain, then save the host. |
| Passkey status says it is not available | Windows Hello is not set up on this PC, or you are on Linux. The status line gives the reason. |
| Authentication rejected with a hardware key | The key's public line is not in ~/.ssh/authorized_keys for this username. |
| Codes are never auto-filled | The server's prompt wording does not look like a code prompt, or it asks for the password and the code in one round. |