{"repo":"rado0x54/ShellWatch","free":true,"listed":false,"github":"https://github.com/rado0x54/ShellWatch","clone":"git clone https://github.com/rado0x54/ShellWatch.git","description":"Passkey-backed SSH for humans and AI agents","language":"TypeScript","stars":12,"topics":["audit","human-in-the-loop","mcp","passkeys","ssh","webauthn"],"license":null,"category":"mcp-servers","readme_excerpt":"Passkey-Backed SSH for Humans and Agents Website · App · Docs ShellWatch is a Human-in-the-Loop platform for agent-driven SSH. Passkey-first and passkey-only — no passwords anywhere — with an SSH-agent proxy that delivers end-to-end secure SSH authentication to your local client. Every agent action surfaces in realtime notifications, persists in a tamper-evident audit log, and can be gated behind explicit human approval before it touches the remote host. - Passkey-only auth — WebAuthn for UI login, agent enrollment, and SSH authentication via OpenSSH's webauthn-sk-ecdsa-sha2-nistp256@openssh.com signature algorithm - OAuth2 delegated to Ory Hydra — the OAuth2/OIDC layer is owned entirely by Ory Hydra. Every client (web UI, MCP, agent) authenticates through it via mediated DCR + authorization code + PKCE, with passkey login + consent; ShellWatch is Hydra's passkey-gated login/consent provider and the access token's subject is the human. No passwords, no API keys. - End-to-end SSH-agent proxy — local ssh / scp / git reach a passkey via ShellWatch with explicit browser approval per signature - Agent forwarding into sessions — your passkey-backed SSH agent is forwarded into ShellWatch sessions (per-endpoint toggle), so you can hop to additional hosts and enable SSH-agent-based PAM integration - PAM integration — pair with pam-ssh-agent-webauthn to gate sudo (or any PAM-aware step) behind a passkey approval surfaced through ShellWatch - Human-in-the-loop for agents — MCP agents re","default_branch":null,"files":null,"tree":[],"storefront":"/r/rado0x54","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/rado0x54/ShellWatch/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}