SSH keys

Manage the SSH public keys that grant terminal access to this environment's server.

The SSH Keys panel shows every public key currently authorized on this environment's server, and lets you add or remove keys from the per-environment allow-list.

SSH Keys panel showing a list of keys

How environment keys relate to org-wide keys

StoreFrame has two levels of SSH key management:

  • Org-wide keys defined at /docs/hub/settings/organization. When you create an environment you can pick one of these keys, and it is installed at provision time. Keys added to the organization later are not pushed to running environments.
  • Per-environment keys shown on this panel. You can add keys from the org-wide pool to a specific environment, or remove keys that you don't want on this particular server.

Changes made here do not affect the org-wide pool or other environments.

Viewing active keys

Each row in the key list shows:

  • Key name — the label you gave the key when you added it to your account
  • SHA-256 fingerprint prefix — enough to identify the key without exposing the full value
  • Date added to this environment

If no keys are configured, the panel shows an empty state. If your org has keys in the pool that are not yet added to this environment, the empty state notes how many are available.

Adding and removing keys

Click Manage Keys to open the key management modal. The modal shows two columns: keys already on this environment and keys available from the org-wide pool. Toggle keys between columns and save.

Keys added here are provisioned onto the server immediately — you do not need to reprovision the environment.

Connecting via SSH

If the environment has a known server IP and SSH user, the panel footer shows the ready-to-use SSH command:

ssh <user>@<ip> -p2409

Click the copy icon to copy the full command to your clipboard.

Key management in your profile

To register a new public key with your account (so it appears in the org-wide pool), go to your profile settings. The key must exist there before it can be assigned to an environment.

On this page