Servonaut Vault
Solo & TeamsA built-in, end-to-end encrypted home for your SSH keys and secrets. Your keys are locked on your own computer before they are uploaded, and only your Servonaut (and, for a team vault, your teammates' Servonaut) can open them. New teammates get access without anyone handing out key files, and when someone leaves, Servonaut shows you exactly which keys to replace.
Our servers keep encrypted data, public keys and signatures. Every key that could open your secrets stays on your devices, and the website never decrypts anything: it shows status and lets you record decisions, while everything that needs a key happens in Servonaut on your computer.
What you get
- Personal vault (Solo and Teams) — your own SSH keys and secrets, available on every computer you approve.
- Team vault (Teams) — one vault per team. Owners and admins import keys and link each one to the shared servers it opens; members connect with them automatically.
- No key files to pass around — Servonaut loads a key into a private, short-lived SSH agent when you connect. Nothing is written to
~/.ssh. - Clean offboarding — removing someone revokes their access at once, re-keys the vault and lists every secret they could have read.
- An activity trail — who added, changed or downloaded what, and who approved whom, in the team's Activity tab.
Your vault identity, devices and recovery key
In the Servonaut app, the Vault screen is under Tools in the sidebar. It appears once you're signed in.
The first time you set up your vault (open Vault → Setup in the Servonaut
app, or run servonaut vault setup), Servonaut creates your
vault identity on your computer: a pair of keys whose public half is
uploaded and whose private half never leaves your devices unencrypted. Each computer you
use is a device.
-
Recovery key. Setup shows a recovery key once, starting with
SVRK1-. Write it down and keep it offline. Servonaut keeps a backup of your identity that only this recovery key can open, so the backup alone is useless to anyone, including us. -
Adding a computer. On the new computer, open Vault → Add device
in the Servonaut app, or run
servonaut vault devices add. Then approve it from a computer you already use: open Vault → Devices, select the waiting device and choose Approve device, or runservonaut vault devices approve. Both screens show the same six-digit code; approve only if they match. The code is never shown on the website. No other computer at hand? Use the recovery key: Vault → Recover in the app, orservonaut vault recover. - Safety number. Every identity has a safety number: 12 groups of five digits. When a teammate joins, or resets their identity, read your safety numbers to each other by phone or in person. If they match, nobody swapped a key in between.
-
Confirming a new identity. A new identity is trusted once you confirm
it: sign in with two-factor authentication before you set it up, or open the link we
e-mail you. If you sign in with two-factor later, choose Confirm identity
on the Vault screen, or run
servonaut vault identity confirm. Until then nobody can give it access to a vault.
Your identity, devices and recovery key status are listed under Account → Security, where you can also revoke a device.
The team vault
-
Set up your vault on your computer: open Vault → Setup in
the Servonaut app, or run
servonaut vault setup. -
Create the team vault (owner or admin): choose Create vault
on the Vault screen and pick the team, or run
servonaut vault create --team <team>, using the team's URL name. -
Import your SSH keys: select the vault and choose Import SSH,
which lists the keys in
~/.sshand can also import from Bitwarden. Or runservonaut vault import sshfor~/.ssh, orservonaut vault import bitwardento move them out of Bitwarden. -
Link each key to the servers it opens: in Instances, select
the server and choose Use Vault Key, or run
servonaut vault bind <server> <item>(add--login deployto choose the user it signs in as). The link is signed by your device, so a server that changed its address is flagged instead of trusted. -
Teammates sign in and set up their vault once: in the Servonaut app,
Account / Login → Login with servonaut.dev, then Vault → Setup;
or run
servonaut loginandservonaut vault setup. Access arrives automatically.
The team's Vault tab shows who can read the vault, each person's safety number, the items (type, fingerprint, servers, downloads; never the contents), whether the vault needs a new key, and its exposures. Viewers cannot read a team vault.
How new members get access
Only someone who holds the vault key can share it, so access is granted by an owner's or
admin's Servonaut, not by our servers. It happens automatically whenever one of them has
Servonaut open, unless they turned off Process eligible grants automatically
under Settings → Team Vault. To grant access now, select the vault and choose
Grants, or run servonaut vault grants process. To grant access
around the clock, keep the Servonaut app open, or servonaut connect running, on
an always-on machine. The Vault tab shows whether an owner's or admin's
Servonaut is online right now.
| Setting | What happens when someone joins |
|---|---|
| Automatic (default) | Once they have set up their vault and confirmed their identity, an owner's or admin's Servonaut grants access. |
| Approval | They wait until an owner or admin approves them, on the Vault tab or in Servonaut. Then access is granted as above. |
Someone who reset their vault identity always needs an approval, whatever the setting.
Approving in the browser records your decision; it cannot detect a server that swaps
someone's key, so compare safety numbers first. For the strongest check, approve with the
CLI: run servonaut vault verify-member <email> in a terminal. Nobody can approve
their own identity, and changing the setting or approving asks you to confirm it's you.
When someone leaves
Removing a member, a member leaving, or making them a viewer takes their vault access away in the same moment. Then:
-
The vault gets a new key. The next time an owner's or admin's Servonaut
is open, it re-keys the vault for everyone who still has access. To do it on demand,
select the vault and choose Rotate vault key, or run
servonaut vault rotate. Members keep working meanwhile. - Exposures are opened. Every secret the person could read is listed under Vault → Exposures, marked when they actually downloaded it, with the servers that use it.
-
You replace the keys. Servonaut's rotation assistant puts a new SSH key on
each server, removes the old one, and closes the exposure once the old key is gone from
every server. To start it, select the vault in the Servonaut app and choose
Items, then Exposures; select the exposure and choose
Rotate exposed SSH key. Or run
servonaut vault exposures --rotate-ssh. If a server could not be updated, the exposure stays open and the assistant names that server. Saving a new key in the vault by itself does not close an exposure. For a secret you changed elsewhere, or decided to keep, resolve the exposure on the Vault tab with a reason, or with Resolve exposure in the Servonaut app.
Encryption can stop someone opening the vault tomorrow, but it cannot make them forget a key they downloaded yesterday. Exposures tell you which ones matter.
A lost or stolen computer
Revoke the device under Account → Security
(or, from another computer, with the CLI: servonaut vault devices revoke) and choose
lost or compromised. Every vault you can open is re-keyed and its items
are listed as exposures. Then reset your identity with the CLI,
servonaut vault reset-identity --reason compromised (the app's Reset identity records a
routine rotation instead), and
confirm it from the e-mail we send; teammates approve your new identity after comparing
safety numbers.
Losing access
If you lose every device and your recovery key, the items in your
personal vault are gone for good: nobody, including Servonaut, can open them. A team
vault survives, because your teammates can give you access again once you reset your
identity. A team with a single owner can register an offline recovery key for the team
vault with the CLI (servonaut vault escrow setup), so the team is never locked out.
A password reset does not restore vault access. Your Servonaut password signs you in to the website, the Servonaut app and the CLI; it is not part of your vault keys. After a password reset your devices keep their vault keys (sign in again and they work as before), and a new computer still needs approval from an existing device or your recovery key.
The personal vault
On Solo and Teams, Servonaut keeps a personal vault for your own servers. Import and link keys the same way, from Servonaut. Account → Vault lists the items (never their contents), the servers they are linked to, and whether the vault needs a new key. If your plan changes, you can still read and export your items.
Using an external vault instead
Bitwarden remains available as an external vault, for teams that already keep their keys there. Set it up under Servers & Access → Share SSH access → Advanced: use an external vault (see Secrets & Integrations). Membership is not synced with an external vault: when someone leaves the team, also remove them from your Bitwarden collection and rotate the keys they could read. If a server has both, Servonaut uses the team vault key.
Commands
Most of these steps are also on the Vault screen of the Servonaut app. The last column shows where; steps marked "CLI only" run in a terminal.
| Command | What it does | In the Servonaut app |
|---|---|---|
servonaut vault setup | Create your vault identity on this computer | Vault → Setup |
servonaut vault status | Your identity, safety number, devices and recovery key state | Vault |
servonaut vault devices add | Add this computer to your vault identity and wait for approval | Vault → Add device |
servonaut vault devices approve | Approve a new computer from this one (compare the six-digit code) | Vault → Devices → Approve device |
servonaut vault devices revoke <id> --reason lost | Revoke a device | CLI only (or Account → Security on the website) |
servonaut vault recover | Activate this computer with your recovery key | Vault → Recover |
servonaut vault recovery-key rotate | Replace your recovery key | Vault → Rotate recovery key |
servonaut vault reset-identity --reason … | Start over with a new identity (confirmed by e-mail) | Vault → Reset identity (routine rotation only) |
servonaut vault create --team <team> | Create the team vault | Vault → Create vault |
servonaut vault import ssh / import bitwarden | Import SSH keys | Vault → select the vault → Import SSH |
servonaut vault bind <server> <item> | Link a key to a server | Instances → select the server → Use Vault Key |
servonaut vault verify-member <email> | Show a teammate's safety number to compare, and approve them | CLI only |
servonaut vault grants process | Grant access to waiting members now | Vault → select the vault → Grants |
servonaut vault rotate | Re-key a vault after someone lost access | Vault → select the vault → Rotate vault key |
servonaut vault exposures | List secrets to replace | Vault → select the vault → Items → Exposures |