# OSH - Zero Trust SSH

> OSH - Zero Trust SSH (iPhone/iPad app by Open layer technologies L.L.C S.O.C.)

- Source: https://appshunter.io/ios/app/osh-zero-trust-ssh/id6785531354 (this page in markdown: same URL + `.md`)
- Developer: [Open layer technologies L.L.C S.O.C](https://appshunter.io/developer/6785531356)
- Category: Developer Tools, Utilities
- Price: Free
- Age rating: 4+
- Requires: iOS 18.0 · 3 MB
- Languages: American English
- Released: 2026-07-11
- Data updated: 2026-08-30
- User reviews in markdown: https://appshunter.io/ios/app/osh-zero-trust-ssh/id6785531354/reviews.md

## What is OSH?

OSH turns your iPhone into a hardware-backed approver for zero-trust SSH access.

Instead of long-lived SSH keys scattered across laptops, your team's gateway issues short-lived SSH certificates only after a human approves each request. OSH is where that approval happens — on a device you carry, protected by Face ID and the Secure Enclave.

HOW IT WORKS
• Enroll your device by scanning the gateway's QR code.
• When someone requests SSH access, OSH shows you who, what, and where.
• Approve or deny with Face ID. Your approval is signed by a key that lives only in the Secure Enclave.
• The gateway issues a short-lived certificate — no standing keys, no shared secrets.

WHY IT'S SECURE
• The signing key is generated inside the Secure Enclave and is non-exportable — it can never leave your iPhone.
• Every approval requires biometric authentication.
• OSH connects only to the gateway you configure. It has no analytics, no trackers, no ads, and no third-party SDKs.

FOR TEAMS
• Role-aware: signers, admins, and root see the controls appropriate to them.
• Review access rules, approval history, and gateway logs from the app.

OSH requires a compatible zero-trust SSH gateway to connect to. If your organization doesn't run one yet, contact us at ad@openlay.com.


## Version history (last 5 releases)

### 1.0.4 — 2026-07-29

• Open network access from your phone. A super admin can now let a single IP address reach the gateway for a limited time — type the address, read exactly what the gateway will do, and approve with Face ID. The access expires on its own.
• Your device's Approval tab shows who approved this device and when, instead of an empty screen.
• Rules no longer offer signers that cannot approve, so a rule you create will not be rejected later.
• An approval row now shows both the machine asking and the destination it wants to reach. Previously the machine name appeared twice and the destination was cut short.
• The gateway address placeholder is no longer styled as if it were a real saved value.

### 1.0.3 — 2026-07-27

• The approval screen now shows the whole approval chain — who has already signed, who is next, and how far a request has got.
• Approve and Deny are offered only when the chain is waiting on your device. When it is not your turn, the screen says what you already decided and who it is waiting on.
• Create and Edit Rule now state which role a rule grants when a server offers only one, instead of a control that looked unpressed.
• Editing a rule onto a server that does not offer its role no longer leaves the role unset.
• You can paste an enrollment link when scanning the QR code is not possible.
• Server records no longer carry an unused IP field.

### 1.0.2 — 2026-07-21

• Scan a web-admin login QR right inside the app — no need to switch to the Camera app.
• The Signers list now updates in real time, shows each device's specific model, and lets you remove expired registrations.
• New admin approval history to review promote and revoke actions.
• Clearer messages when an access request is denied.
• Support for SSH servers on custom ports.
• Stability and interface improvements.

### 1.0.1 — 2026-07-15

• New app icon.
• Approvals now appear in real time — no need to reopen the app.
• Pending requests show a live countdown instead of a frozen timestamp.
• Role changes take effect immediately after a promotion — no relaunch.
• Admins can remove pending devices, and the Admin badge no longer sticks.
• Clearer step-by-step guidance on the approval waiting screen.
• Fixed entering "." in the IP Address field.

### 1.0 — 2026-07-11

No release notes.

## Related topics

[zero trust](https://appshunter.io/ios/topics/zero-trust) · [ssh free](https://appshunter.io/ios/topics/ssh-free)

---

*Data collected daily from the US App Store and indexed by [AppsHunter](https://appshunter.io/). User reviews are verbatim App Store reviews. Ratings, prices and chart positions refresh continuously; this snapshot is from 2026-08-30.*
