Secure access
that expires by design.

Ephera replaces permanent SSH keys with short-lived certificates. Your team authenticates, connects, and every session has a hard expiry. No keys to rotate, no credentials to leak, no cleanup scripts.

terminal

SSH keys that never expire are
credentials waiting to be leaked.

Most teams rely on long-lived SSH keys: authorized_keys files spread across hundreds of servers, keys that belong to people who left months ago, access no one can audit and no one remembers granting.

Ephera is the control plane for your SSH access. Authenticate once, get a certificate valid for 8 hours, connect directly to any server you have a grant for. When the certificate expires, access stops. No cleanup, no rotation scripts, no human error.

The control plane issues certificates.
It is never in the SSH data path.

An Ephera outage means no new certificates, not loss of access to servers you already have a valid cert for.

01 AUTHENTICATE 02 CERTIFICATE 03 CONNECT CP ephera CLI user SRV server cert req cert SSH DIRECT 8h TTL control plane not in data path

Certificates expire. Sessions are logged.

Certificates are valid for 8 hours — enough for a full day without interruption. When they expire, they're gone. No credentials to leak, rotate, or forget about.

8h TTL

Certificate issued. Countdown starts.

enough for your work day, then it's gone

ONLINE
web-prod-1
ONLINE
web-prod-2
ONLINE
api-prod-1
ONLINE
db-prod-1
IDLE
staging-1
ONLINE
worker-1

Your fleet, at a glance.

agent reports status via heartbeat

Full audit trail. Who connected, when, from where.

Every authentication, certificate issuance, and connection is logged. Compliance reports generate automatically on paid plans.

audit log — live
14:23:01 CONNECT alice@acme.dev → web-prod-1 cert:8h from 185.23.x.x
14:21:45 CERT    issued to alice@acme.dev target:web-prod-1 ttl:8h
14:21:44 AUTH    alice@acme.dev authenticated method:totp ip:185.23.x.x
14:18:32 CONNECT bob@acme.dev → api-prod-1 cert:8h from 93.87.x.x
14:15:10 EXPIRE cert for carol@acme.dev expired target:db-prod-1 ttl:0

Start for free.

One user, three servers. Upgrade when your team grows.