
Free
About
OSH turns your iPhone into a hardware-backed approver for zero-trust SSH access.
Instead of long-lived SSH keys scattered across laptops, your team's gateway issues short-lived SSH certificates only after a human approves each request. OSH is where that approval happens — on a device you carry, protected by Face ID and the Secure Enclave.
HOW IT WORKS
• Enroll your device by scanning the gateway's QR code.
• When someone requests SSH access, OSH shows you who, what, and where.
• Approve or deny with Face ID. Your approval is signed by a key that lives only in the Secure Enclave.
• The gateway issues a short-lived certificate — no standing keys, no shared secrets.
WHY IT'S SECURE
• The signing key is generated inside the Secure Enclave and is non-exportable — it can never leave your iPhone.
• Every approval requires biometric authentication.
• OSH connects only to the gateway you configure. It has no analytics, no trackers, no ads, and no third-party SDKs.
FOR TEAMS
• Role-aware: signers, admins, and root see the controls appropriate to them.
• Review access rules, approval history, and gateway logs from the app.
OSH requires a compatible zero-trust SSH gateway to connect to. If your organization doesn't run one yet, contact us at ad@openlay.com.
Show more
What's New in OSH
1.0.4
July 29, 2026
• Open network access from your phone. A super admin can now let a single IP address reach the gateway for a limited time — type the address, read exactly what the gateway will do, and approve with Face ID. The access expires on its own. • Your device's Approval tab shows who approved this device and when, instead of an empty screen. • Rules no longer offer signers that cannot approve, so a rule you create will not be rejected later. • An approval row now shows both the machine asking and the destination it wants to reach. Previously the machine name appeared twice and the destination was cut short. • The gateway address placeholder is no longer styled as if it were a real saved value.
More




