Your data
Hosts and connections
Everything about saving a server in Synapse: connection details, how you sign in, trusting its key, and organising a long host list.
Adding a host
Open Manage hosts from the header's ··· menu, or the command palette (Ctrl K), then Add host. Under Connection, choose a protocol and fill in:
| Field | Notes |
|---|---|
| Hostname | Required. An address or hostname. |
| Port | Defaults to 22 for SSH, 23 for Telnet. |
| Name | Optional. Shown in the host list instead of the address. |
| Group | Optional. Pick an existing group or create a new one. |
Synapse supports SSH, Telnet and Serial connections. Telnet and Serial log in inside the terminal itself, so the Authentication section below only applies to SSH.
Authentication
For an SSH host, enter a Username and choose how to sign in:
- Password - stored in the vault if you've set a master password, otherwise unencrypted on disk.
- Private key - paste or generate a key, kept in the vault the same way.
- SSH agent - uses the keys already loaded in your local SSH agent or Pageant; nothing is stored.
See Vault and master password for what encrypts your saved passwords and keys, and why setting a master password matters.
Trusting a server
The first time you connect to a host, Synapse shows the server's key type and fingerprint and asks
Trust this host? before saving it to known_hosts. Check the fingerprint
against what your server administrator gave you before accepting.
If a host presents a different key than the one saved, Synapse refuses to connect and warns you -
someone could be intercepting the connection. If the server was rebuilt or its key was reissued on
purpose, remove the old line from known_hosts (Synapse tells you which one) and connect
again.
Groups
Give a host a Group to keep a long list tidy; the host list and the jump-host picker both show hosts grouped together. A host without a group sits ungrouped at the top.
Advanced connection options
Expand Advanced in the host editor for a starting directory, a startup command (for example tmux attach -t main), and the Connection engine:
- Built-in (recommended) - one connection handles the terminal, files, tunnels and tmux detection. Doesn't read
~/.ssh/config. - System OpenSSH - runs the
sshcommand and your~/.ssh/config. Choose this forProxyCommand, hardware security keys or Kerberos.
Advanced SSH
Switch on the Advanced SSH service (in Services) for options aimed at more complex networks:
- Jump hosts - connect through other saved hosts in order (like
ProxyJump); each hop's key is checked. - Proxy - an HTTP or SOCKS5 proxy for reaching the first hop.
- Agent forwarding - lets the server use your local SSH agent's keys.
- Identities - one saved username, password and key shared across many hosts or a whole group.
- Environment variables and login scripts - variables sent when a session starts, or a wait-then-type script for after the shell comes up.
- SSH certificates - a
-cert.pubsigned for a key, used automatically when saved alongside it.
Anyone with root access on a server you forward your agent to can use your keys while you're connected. Only turn it on for servers you trust.
Importing and exporting
The Import and export menu next to Add host covers moving hosts in and out of Synapse:
- Import from
~/.ssh/config, Termius, PuTTY, MobaXterm, or a CSV or JSON file. - Import from cloud providers (AWS EC2, DigitalOcean, Hetzner Cloud, Linode, Vultr) if that service is switched on.
- Export hosts - addresses, usernames, groups and tags as JSON or CSV. Passwords and keys are never included.
For copies that do include the vault, and for automatic local backups, see Backups and restore.