Home / Docs / Servonaut Vault

Servonaut Vault

Solo & Teams

A built-in, end-to-end encrypted home for your SSH keys and secrets. Your keys are locked on your own computer before they are uploaded, and only your Servonaut (and, for a team vault, your teammates' Servonaut) can open them. New teammates get access without anyone handing out key files, and when someone leaves, Servonaut shows you exactly which keys to replace.

Servonaut never stores your keys in a form we can read

Our servers keep encrypted data, public keys and signatures. Every key that could open your secrets stays on your devices, and the website never decrypts anything: it shows status and lets you record decisions, while everything that needs a key happens in Servonaut on your computer.

What you get

  • Personal vault (Solo and Teams) — your own SSH keys and secrets, available on every computer you approve.
  • Team vault (Teams) — one vault per team. Owners and admins import keys and link each one to the shared servers it opens; members connect with them automatically.
  • No key files to pass around — Servonaut loads a key into a private, short-lived SSH agent when you connect. Nothing is written to ~/.ssh.
  • Clean offboarding — removing someone revokes their access at once, re-keys the vault and lists every secret they could have read.
  • An activity trail — who added, changed or downloaded what, and who approved whom, in the team's Activity tab.

Your vault identity, devices and recovery key

In the Servonaut app, the Vault screen is under Tools in the sidebar. It appears once you're signed in.

The first time you set up your vault (open Vault → Setup in the Servonaut app, or run servonaut vault setup), Servonaut creates your vault identity on your computer: a pair of keys whose public half is uploaded and whose private half never leaves your devices unencrypted. Each computer you use is a device.

  • Recovery key. Setup shows a recovery key once, starting with SVRK1-. Write it down and keep it offline. Servonaut keeps a backup of your identity that only this recovery key can open, so the backup alone is useless to anyone, including us.
  • Adding a computer. On the new computer, open Vault → Add device in the Servonaut app, or run servonaut vault devices add. Then approve it from a computer you already use: open Vault → Devices, select the waiting device and choose Approve device, or run servonaut vault devices approve. Both screens show the same six-digit code; approve only if they match. The code is never shown on the website. No other computer at hand? Use the recovery key: Vault → Recover in the app, or servonaut vault recover.
  • Safety number. Every identity has a safety number: 12 groups of five digits. When a teammate joins, or resets their identity, read your safety numbers to each other by phone or in person. If they match, nobody swapped a key in between.
  • Confirming a new identity. A new identity is trusted once you confirm it: sign in with two-factor authentication before you set it up, or open the link we e-mail you. If you sign in with two-factor later, choose Confirm identity on the Vault screen, or run servonaut vault identity confirm. Until then nobody can give it access to a vault.

Your identity, devices and recovery key status are listed under Account → Security, where you can also revoke a device.

The team vault

  1. Set up your vault on your computer: open Vault → Setup in the Servonaut app, or run servonaut vault setup.
  2. Create the team vault (owner or admin): choose Create vault on the Vault screen and pick the team, or run servonaut vault create --team <team>, using the team's URL name.
  3. Import your SSH keys: select the vault and choose Import SSH, which lists the keys in ~/.ssh and can also import from Bitwarden. Or run servonaut vault import ssh for ~/.ssh, or servonaut vault import bitwarden to move them out of Bitwarden.
  4. Link each key to the servers it opens: in Instances, select the server and choose Use Vault Key, or run servonaut vault bind <server> <item> (add --login deploy to choose the user it signs in as). The link is signed by your device, so a server that changed its address is flagged instead of trusted.
  5. Teammates sign in and set up their vault once: in the Servonaut app, Account / Login → Login with servonaut.dev, then Vault → Setup; or run servonaut login and servonaut vault setup. Access arrives automatically.

The team's Vault tab shows who can read the vault, each person's safety number, the items (type, fingerprint, servers, downloads; never the contents), whether the vault needs a new key, and its exposures. Viewers cannot read a team vault.

How new members get access

Only someone who holds the vault key can share it, so access is granted by an owner's or admin's Servonaut, not by our servers. It happens automatically whenever one of them has Servonaut open, unless they turned off Process eligible grants automatically under Settings → Team Vault. To grant access now, select the vault and choose Grants, or run servonaut vault grants process. To grant access around the clock, keep the Servonaut app open, or servonaut connect running, on an always-on machine. The Vault tab shows whether an owner's or admin's Servonaut is online right now.

SettingWhat happens when someone joins
Automatic (default) Once they have set up their vault and confirmed their identity, an owner's or admin's Servonaut grants access.
Approval They wait until an owner or admin approves them, on the Vault tab or in Servonaut. Then access is granted as above.

Someone who reset their vault identity always needs an approval, whatever the setting. Approving in the browser records your decision; it cannot detect a server that swaps someone's key, so compare safety numbers first. For the strongest check, approve with the CLI: run servonaut vault verify-member <email> in a terminal. Nobody can approve their own identity, and changing the setting or approving asks you to confirm it's you.

When someone leaves

Removing a member, a member leaving, or making them a viewer takes their vault access away in the same moment. Then:

  1. The vault gets a new key. The next time an owner's or admin's Servonaut is open, it re-keys the vault for everyone who still has access. To do it on demand, select the vault and choose Rotate vault key, or run servonaut vault rotate. Members keep working meanwhile.
  2. Exposures are opened. Every secret the person could read is listed under Vault → Exposures, marked when they actually downloaded it, with the servers that use it.
  3. You replace the keys. Servonaut's rotation assistant puts a new SSH key on each server, removes the old one, and closes the exposure once the old key is gone from every server. To start it, select the vault in the Servonaut app and choose Items, then Exposures; select the exposure and choose Rotate exposed SSH key. Or run servonaut vault exposures --rotate-ssh. If a server could not be updated, the exposure stays open and the assistant names that server. Saving a new key in the vault by itself does not close an exposure. For a secret you changed elsewhere, or decided to keep, resolve the exposure on the Vault tab with a reason, or with Resolve exposure in the Servonaut app.
Why replace keys at all?

Encryption can stop someone opening the vault tomorrow, but it cannot make them forget a key they downloaded yesterday. Exposures tell you which ones matter.

A lost or stolen computer

Revoke the device under Account → Security (or, from another computer, with the CLI: servonaut vault devices revoke) and choose lost or compromised. Every vault you can open is re-keyed and its items are listed as exposures. Then reset your identity with the CLI, servonaut vault reset-identity --reason compromised (the app's Reset identity records a routine rotation instead), and confirm it from the e-mail we send; teammates approve your new identity after comparing safety numbers.

Losing access

Keep your recovery key

If you lose every device and your recovery key, the items in your personal vault are gone for good: nobody, including Servonaut, can open them. A team vault survives, because your teammates can give you access again once you reset your identity. A team with a single owner can register an offline recovery key for the team vault with the CLI (servonaut vault escrow setup), so the team is never locked out.

A password reset does not restore vault access. Your Servonaut password signs you in to the website, the Servonaut app and the CLI; it is not part of your vault keys. After a password reset your devices keep their vault keys (sign in again and they work as before), and a new computer still needs approval from an existing device or your recovery key.

The personal vault

On Solo and Teams, Servonaut keeps a personal vault for your own servers. Import and link keys the same way, from Servonaut. Account → Vault lists the items (never their contents), the servers they are linked to, and whether the vault needs a new key. If your plan changes, you can still read and export your items.

Using an external vault instead

Bitwarden remains available as an external vault, for teams that already keep their keys there. Set it up under Servers & Access → Share SSH access → Advanced: use an external vault (see Secrets & Integrations). Membership is not synced with an external vault: when someone leaves the team, also remove them from your Bitwarden collection and rotate the keys they could read. If a server has both, Servonaut uses the team vault key.

Commands

Most of these steps are also on the Vault screen of the Servonaut app. The last column shows where; steps marked "CLI only" run in a terminal.

CommandWhat it doesIn the Servonaut app
servonaut vault setupCreate your vault identity on this computerVault → Setup
servonaut vault statusYour identity, safety number, devices and recovery key stateVault
servonaut vault devices addAdd this computer to your vault identity and wait for approvalVault → Add device
servonaut vault devices approveApprove a new computer from this one (compare the six-digit code)Vault → Devices → Approve device
servonaut vault devices revoke <id> --reason lostRevoke a deviceCLI only (or Account → Security on the website)
servonaut vault recoverActivate this computer with your recovery keyVault → Recover
servonaut vault recovery-key rotateReplace your recovery keyVault → Rotate recovery key
servonaut vault reset-identity --reason …Start over with a new identity (confirmed by e-mail)Vault → Reset identity (routine rotation only)
servonaut vault create --team <team>Create the team vaultVault → Create vault
servonaut vault import ssh / import bitwardenImport SSH keysVault → select the vault → Import SSH
servonaut vault bind <server> <item>Link a key to a serverInstances → select the server → Use Vault Key
servonaut vault verify-member <email>Show a teammate's safety number to compare, and approve themCLI only
servonaut vault grants processGrant access to waiting members nowVault → select the vault → Grants
servonaut vault rotateRe-key a vault after someone lost accessVault → select the vault → Rotate vault key
servonaut vault exposuresList secrets to replaceVault → select the vault → Items → Exposures
Documentation