Skip to content
Bastyx
Developers

Built for people who SSH for a living.

Security tools usually add steps. Bastyx is designed to remove them: no passwords to type, no keys to copy, no tickets for temporary access. Here’s what a day is meant to feel like.

Terminal session where ssh production is verified by device, identity, security key and policy before connecting.

Illustrative. Planned SSH flow.

A day with Bastyx

Fewer rituals. Same security.

Planned Describes the planned experience.

  1. 09:02

    Unlock the laptop

    Fingerprint on the built-in sensor. No password.

  2. 09:15

    ssh staging

    Same command as always. One touch of the security key.

  3. 11:40

    Need production for an hour

    Request access to prod-db. A lead approves it in the flow.

  4. 12:40

    Access ends

    The window closes on its own. Nobody has to remember.

  5. 17:30

    Log off

    Nothing to rotate, nothing to clean up, nothing left behind.

Under the hood

Open standards, nothing proprietary to learn.

Bastyx is designed around the protocols your tools already speak.

FIDO2 / WebAuthn
Public-key authentication bound to the origin. The basis of passkeys.
CTAP2
How laptops and phones talk to external security keys over USB, NFC and Bluetooth.
OpenSSH
The standard client and server. Bastyx is designed not to replace either.
Your IdP
Directory and SSO stay where they are. Bastyx is designed to work alongside them.

Documentation

Docs are being written.

We’d rather publish accurate documentation late than speculative documentation early. Until then, the security page describes the planned architecture and the SSH guide is useful whether or not you use Bastyx.

Coming with early access

  • QuickstartEnroll a person, a device and a first server group.
  • SSH setup guideServer-side configuration and supported topologies.
  • Policy referenceEvery condition and response, with examples.
  • ArchitectureComponents, trust boundaries and data flows.

Want to know when they’re published? Follow the changelog.

Try it on your own servers first.

Early-access teams start with one team and one server group.