OSH turns your iPhone into a hardware-backed approver for zero-trust SSH access.
Instead of long-lived SSH keys scattered across laptops, your team's gateway issues short-lived SSH certificates only after a human approves each request. OSH is where that approval happens — on a device you carry, protected by Face ID and the Secure Enclave.
HOW IT WORKS
• Enroll your device by scanning the gateway's QR code.
• When someone requests SSH access, OSH shows you who, what, and where.
• Approve or deny with Face ID. Your approval is signed by a key that lives only in the Secure Enclave.
• The gateway issues a short-lived certificate — no standing keys, no shared secrets.
WHY IT'S SECURE
• The signing key is generated inside the Secure Enclave and is non-exportable — it can never leave your iPhone.
• Every approval requires biometric authentication.
• OSH connects only to the gateway you configure. It has no analytics, no trackers, no ads, and no third-party SDKs.
FOR TEAMS
• Role-aware: signers, admins, and root see the controls appropriate to them.
• Review access rules, approval history, and gateway logs from the app.
OSH requires a compatible zero-trust SSH gateway to connect to. If your organization doesn't run one yet, contact us at ad@openlay.com.
Ratings & Reviews
This app has not received enough ratings or reviews to display an overview.
Client versions
- A new Client versions screen in Admin: root sets the minimum version of the OSH desktop app and the osh command line, with a deadline. Until the deadline older builds keep working and are told to update; after it they cannot get a certificate or enroll. Needs gateway 0.26.0 or newer.
- Require the latest version: one tap sets both minimums to the newest release, enforced in 7, 14 or 30 days. Needs gateway 0.27.0 or newer.
- Each machine now shows which osh build it runs, so you can see who is behind before you set a minimum. Needs gateway 0.25.0 or newer.
Device keys
- An approval request, and every screen that describes a machine, now says what holds its device key: a TPM, a Secure Enclave, or a file. Needs gateway 0.24.0 or newer.
Fixes
- The app no longer crashes on Connect when the gateway address has a stray space or a mistyped port. Before, it crashed again on every launch until it was deleted.
- A phone promoted to admin now shows pending approvals right away, without reopening the app.
- A rule stays on screen when its machine has a long name.
On an older gateway the new screens say so; everything else works as before.
Version 1.0.7
The developer, Open layer technologies L.L.C S.O.C, indicated that the app’s privacy practices may include handling of data as described below. For more information, see the developer’s privacy policy .
Data Not Collected
The developer does not collect any data from this app.
Privacy practices may vary based, for example, on the features you use or your age. Learn More
Accessibility
The developer has not yet indicated which accessibility features this app supports. Learn More
Information
Provider
Open layer technologies L.L.C S.O.C
Size
4 MB
Category
Developer Tools
Compatibility
Requires iOS 18.0 or later.
iPhone Requires iOS 18.0 or later.
Mac Requires macOS 15.0 or later and a Mac with Apple M1 chip or later.