Passwordless SSH authentication with Entra ID

EZSSH removes the need to create, rotate, and remove SSH keys. Instead, short-lived SSH certificates provide just-in-time access to your hosts and repos.

1,200+

Global organizations
trust Keytos

Zero

SSH keys for your engineers to create or store

Zero

Agents to install or manage on your endpoints

99.95%

Premium-tier service availability

Why are organizations moving to EZSSH?

Zero trust access to every SSH endpoint and repo, without a single SSH key for your team to issue, manage, store, or rotate.

Authenticate with Entra ID

No more juggling separate credentials for every endpoint. Authenticate with Entra ID instead and get a user and endpoint-scoped short-lived SSH certificate automatically.

Control access to each endpoint

Control who gets access to each SSH endpoint, with manual approval workflows or auto approval based on Entra ID group membership.

GitHub access without SSH keys

Developers authenticate with their corporate Entra ID identity and get a short-lived certificate. No more manual onboarding or stale SSH keys on your repos.

No Linux agents to install or manage

EZSSH uses platform-native SSH certificate support in GitHub and Linux so you don't have to install or manage any additional agents. Just use the built-in capabilities already there.

Easy to audit access

All access requests and approvals are logged and can be exported for your security team to analyze or to simplify compliance audits.

HSM backed certificate authorities

Every EZSSH certificate authority is backed by a hardware security module (HSM) to ensure the highest level of security for your SSH keys.

Up and running in 3 easy steps

No SSH key inventory to clean up first and no PKI expertise required.

01

Create an access policy

Register your tenant and create your first access policy. EZSSH generates a dedicated, HSM backed certificate authority and manages it for you, so you don't have to worry about key management.

02

Trust the CA on your hosts

Run the policy's downloadable script on your endpoints to add its CA key to the allowed SSH CAs (no agent required), or connect an Azure subscription and let EZSSH deploy the policy to its VMs for you.

03

Sign in with Entra ID

Engineers request access via the EZSSH CLI, authenticate with their corporate identity, and connect. Certificates expire on their own, so there is nothing to rotate or revoke.

Where teams use EZSSH

The same short-lived certificates protect all your SSH endpoints. Explore how EZSSH works in different environments.

SSH into your Azure VMs using your Entra ID identity

EZSSH integrates natively with Azure VMs so your certificate authority is automatically trusted on the hosts. Simply authenticate with your Entra ID identity and start using SSH without managing keys.

  • Auto-deploy policies to every Azure VM in your subscription

  • Reuses your subscription permissions, so there is no second access list to maintain

  • No agent on the host, just the policy's CA key in the allowed SSH CAs

Give developers GitHub access without a single SSH key

GitHub removed password access for Git operations, and SSH keys took its place. EZSSH is the first SSH certificate authority for GitHub, so your developers authenticate with the identity they already have.

  • No key registration during onboarding, which saves hours of engineering time per hire

  • Nothing to leak: no private key to share, email, or commit by mistake

  • Time-bound certificates replace credentials that would otherwise never expire

Works on any SSH enabled host, cloud or on premises

Authentication happens through the native Linux cryptographic libraries already on the machine, which keeps the attack surface small even for users with privileged access to critical servers.

  • One downloadable script per policy trusts its CA on the endpoints you choose

  • Native Linux cryptography rather than a custom agent, so brute force surface stays minimal

  • Many hosts at once from the desktop tool, interactively or from a CSV of endpoints

See EZSSH in action

Built by ex-Microsoft engineers, trusted by industry leaders

Secure your SSH endpoints and GitHub repos in minutes

No key inventory to clean up and no infrastructure to buy. Talk to one of our identity experts about how EZSSH can reduce your IT cost while improving user productivity and security.

Transparent pricing

View pricing details

Startup

Server and GitHub access management for up to 100 endpoints

$3 / user / month

Business Critical

One-hour support response and a year of log retention

$9.99 / user / month

Frequently asked questions

No. EZSSH issues a short-lived SSH certificate behind the scenes every time someone connects, so there are no long-lived keys to create, rotate, distribute, or remove when someone leaves. All the user sees is the single sign-on experience they already know.

SSH Certificates are simpler, short-lived credentials (hours long) issued by a trusted certificate authority, while X.509 Certificates are longer-lived credentials (weeks to months long) with additional information typically used for TLS and other PKI-based authentication. You can learn more in our blog post.

Yes. EZSSH is the first SSH certificate authority for GitHub. Developers authenticate with their corporate identity and receive a short-lived certificate, so nobody has to register a personal SSH key with GitHub or keep a private key on their laptop.

Yes. EZSSH works with any SSH enabled host. Each access policy has a downloadable script that adds its certificate authority key to the allowed SSH CAs on your endpoints. Azure is simply easier: grant our service principal access to a subscription and EZSSH auto-deploys your policies to the VMs in it.

Access policies decide who reaches each SSH enabled host. You choose which users get auto-approved access and which need approval from a selected group of approvers.

Yes. A certificate authority key is created for each access policy and never leaves the hardware security modules that protect it, with FIPS 140-3 (Level 3) validated HSMs on Premium and above. You can also bring your own CA and give EZSSH access to sign certificates instead.

Yes. All access requests and approvals are logged and can be exported for your security team to analyze or to simplify compliance audits, and Premium plans can stream them to your SIEM.

EZSSH starts at $3 per user per month for Startup. Premium is $5 per user per month and adds FIPS 140-3 HSM backed CAs, unlimited endpoints, and SIEM export. Business Critical is $9.99 per user per month, and Enterprise pricing is custom.