Your data
SSH agents and password managers
If your SSH keys live in 1Password, Bitwarden or another SSH agent, Synapse can sign in with them without storing anything itself.
How Synapse finds your agent
On Windows, Synapse talks to the agent on the standard OpenSSH pipe, \\.\pipe\openssh-ssh-agent.
If nothing answers there, it tries Pageant (PuTTY's agent). Whichever program serves that pipe - the Windows
OpenSSH Authentication Agent, 1Password or Bitwarden - is the agent Synapse uses.
The agent is tried for every SSH host, after the host's own saved key and password and before the default key files, as described in Hosts and connections. Choosing SSH agent as a host's sign-in method means Synapse stores no key or password for that host and relies on the agent. Synapse offers at most five keys from the agent, because servers usually stop after a handful of failed attempts.
Setting a host to use the agent
- Open the host in the host editor.
- Under Authentication, choose SSH agent ("Uses the keys loaded in your local SSH agent or Pageant").
- Save and connect. The pane's title bar shows SSH agent once you're in; click it to see which key was used.
If a host set to a password or key signs in through the agent instead, Synapse offers once to switch it to the agent, with Use SSH agent.
1Password
- Store or import your key in 1Password as an SSH Key item.
- In the 1Password app, open Settings → Developer and turn on Use the SSH agent.
- 1Password and the Windows OpenSSH Authentication Agent can't both own the pipe. If 1Password says the pipe is in use, stop and disable the Windows service (below).
- In Synapse, set the host to SSH agent and connect. 1Password asks you to approve the first use of the key; approve it there.
Bitwarden
- Save your key in Bitwarden as an SSH key item.
- In the Bitwarden desktop app, open Settings and turn on Enable SSH agent. The desktop app must be running and unlocked while you connect.
- As with 1Password, stop and disable the Windows OpenSSH Authentication Agent if Bitwarden can't start its agent.
- In Synapse, set the host to SSH agent and connect, and approve the request in Bitwarden if it asks.
Menu names in 1Password and Bitwarden change from version to version; their own help pages on the SSH agent have the current steps.
The Windows OpenSSH agent
To use Windows' own agent instead, start the OpenSSH Authentication Agent service and add your key. In PowerShell as administrator:
Get-Service ssh-agent | Set-Service -StartupType Automatic
Start-Service ssh-agent
ssh-add $env:USERPROFILE\.ssh\id_ed25519
To make way for 1Password or Bitwarden, stop it instead:
Stop-Service ssh-agent
Set-Service ssh-agent -StartupType Disabled
Agent forwarding
With the Advanced SSH service on, a host's Agent forwarding option lets that
server use the keys in your local agent while you're connected - for example to git pull from a
private repository. Anyone with root access on the server can use your keys meanwhile, so only turn it on for
servers you trust. 1Password and Bitwarden can still ask you to approve the key's use.
If it doesn't work
- Authentication failed, and the agent isn't in the list of methods tried: Synapse found no agent or no keys in it. Check that 1Password or Bitwarden is running and unlocked with its SSH agent turned on, or that the Windows service is running and
ssh-add -llists your key. - The agent is listed but the server refused it: the server doesn't have the public key in
~/.ssh/authorized_keys, or the right key isn't among the first five the agent offers. Most password managers let you limit which keys they offer. - 1Password or Bitwarden can't start its agent: the Windows OpenSSH Authentication Agent is holding the pipe. Stop and disable it as above, then restart the password manager.
See also Troubleshooting.