SSH and vault

SSH connections, host key verification and an encrypted vault for your secrets.

Connecting

Create an SSH profile (host, port, user, authentication method) or use quick connect (the bolt in the tab bar, or type user@host:port in the palette). Once connected, Termlo offers to save the quick connection as a profile.

Authentication:

  • password, asked when connecting (or read from the vault);
  • private key: OpenSSH and PEM formats, ed25519, ECDSA and RSA keys, passphrase asked when needed;
  • jump host: a profile can go through another one, like ProxyJump.

When the connection drops, a Reconnect banner appears above the pane; Termlo never reconnects on its own.

Host keys

An unknown host key shows its type and fingerprint: accept and save, accept once, or refuse. A host key that differs from the saved one blocks the connection with an explicit warning; refusing is the default, as it may signal an attack.

The vault

The vault encrypts your passwords and private keys with a master password (Argon2id key derivation, AES-GCM encryption). It is created with your first saved secret, from the Identités et vault (Identities and vault) tab.

  • An identity holds a user name and a password or key; an SSH profile references an identity, never the secret itself.
  • The vault locks automatically after 5, 15 (default), 30 or 60 minutes of inactivity, or never. The padlock in the tab bar locks it manually.
  • No secret is ever written in plain text: not in the database, not in logs, not in the restored session.

The master password cannot be recovered: without it, the vault’s secrets are lost.