Keys, credentials and trusted hosts
Reuse credentials across hosts, generate SSH keys, use keys from ~/.ssh and manage trusted host keys.
The Keys page#
Open Keys in the sidebar. The page has three areas: Credentials, Local keys and Trusted hosts.
Credentials#
A credential bundles a username with a password, a private key or the SSH agent. Create one with New credential and select it under Authentication → Saved credential in any number of hosts. A group can also set a default credential for all its hosts.
Secrets are stored only in the encrypted vault. When you edit a host or credential later, Ravelon shows that a secret is stored but never shows the secret itself. Leave the field blank to keep it.
Generate a key#
Generate key creates an Ed25519 SSH key. The private key is created locally and never leaves this computer. A passphrase is recommended; leave it empty only for unattended automation. Ravelon can create an encrypted credential for the new key right away.
Local keys#
Local keys lists the private keys found in ~/.ssh and shows whether each is protected by a passphrase. Click Use to create a credential from one of them.
Trusted hosts#
When you trust a server's key on first connect, Ravelon saves exactly that key. Trusted hosts lists every saved key with its fingerprint, and Forget removes one. The next connection then asks again.
Import known_hosts takes over the keys from ~/.ssh/known_hosts, including hashed entries, for hosts saved in Ravelon. A saved key that disagrees with the file is never replaced; the import reports it instead. You also find the trusted keys under Settings → Security → Trusted host keys.
Credentials and sync#
By default, identities with their passwords, key passphrases and imported private keys do not leave this device. To take them to your other devices, turn on Sync keys & identities in Settings → Account & sync. See Account and encrypted sync.
Last updated 30 September 2026