Free

Rating summary

Details

  • Released
  • Updated
  • July 11, 2026
  • July 29, 2026

Features

OSH - Zero Trust SSH screenshot #1 for iPhone
OSH - Zero Trust SSH screenshot #2 for iPhone
OSH - Zero Trust SSH screenshot #3 for iPhone
OSH - Zero Trust SSH screenshot #4 for iPhone
OSH - Zero Trust SSH screenshot #5 for iPhone
OSH - Zero Trust SSH screenshot #6 for iPhone
🖼️Get Icon
Icons↘︎

About

OSH turns your iPhone into a hardware-backed approver for zero-trust SSH access. Instead of long-lived SSH keys scattered across laptops, your team's gateway issues short-lived SSH certificates only after a human approves each request. OSH is where that approval happens — on a device you carry, protected by Face ID and the Secure Enclave. HOW IT WORKS • Enroll your device by scanning the gateway's QR code. • When someone requests SSH access, OSH shows you who, what, and where. • Approve or deny with Face ID. Your approval is signed by a key that lives only in the Secure Enclave. • The gateway issues a short-lived certificate — no standing keys, no shared secrets. WHY IT'S SECURE • The signing key is generated inside the Secure Enclave and is non-exportable — it can never leave your iPhone. • Every approval requires biometric authentication. • OSH connects only to the gateway you configure. It has no analytics, no trackers, no ads, and no third-party SDKs. FOR TEAMS • Role-aware: signers, admins, and root see the controls appropriate to them. • Review access rules, approval history, and gateway logs from the app. OSH requires a compatible zero-trust SSH gateway to connect to. If your organization doesn't run one yet, contact us at ad@openlay.com.
Show more

What's New in OSH

1.0.4

July 29, 2026

• Open network access from your phone. A super admin can now let a single IP address reach the gateway for a limited time — type the address, read exactly what the gateway will do, and approve with Face ID. The access expires on its own. • Your device's Approval tab shows who approved this device and when, instead of an empty screen. • Rules no longer offer signers that cannot approve, so a rule you create will not be rejected later. • An approval row now shows both the machine asking and the destination it wants to reach. Previously the machine name appeared twice and the destination was cut short. • The gateway address placeholder is no longer styled as if it were a real saved value.

More