OUT-OF-BAND SSH VERIFICATION

Know the host
before you trust it.

Your server submits only its public SSH host keys during first boot. We derive the fingerprints and deliver them to your already-verified inbox.

first-contact.shUTC 14:03:17
$ ssh root@edge-01.example.net
The authenticity of host 'edge-01' can't be established.

ED25519 key fingerprint is
SHA256:W6jFzQh4Yk2m0L7/Jc3v8aK9pNx5uRb1tEeDgHs4iOo

✓ MATCHES VERIFIED EMAIL
Are you sure you want to continue? yes

THE BOOT SEQUENCE

One trust path.
Three deliberate steps.

  1. 01

    Verify the inbox

    Passwordless sign-in proves where reports may be delivered before any server can send one.

  2. 02

    Provision the token

    Generate a named, revocable API token and copy the ready-to-run cloud-init block once.

  3. 03

    Compare out of band

    At first boot, public host keys become OpenSSH SHA256 fingerprints in your email. Compare before accepting.

PUBLIC KEYS INSHA256 FINGERPRINTS OUTNO PRIVATE KEYS30-DAY ENCRYPTED HISTORY

CREDITS, NOT SUBSCRIPTIONS

Pay for first contacts,
not another seat.

Credits remain valid for 365 days. One accepted fingerprint email consumes one credit.

OPERATOR ACCESS

No password to store.
No password to leak.

We send a single-use, 15-minute link. Your email must be confirmed before it can receive fingerprint reports.