Custos documentation
Centralized SSH access and secrets for a fleet of machines. One control plane, with every access and secret read audited.
Start with one host
Run the control plane, enroll a host, and gate a real SSH login through Custos.
Grant SSH access
Register keys, grant access to hosts, and revoke it from a single place.
Deliver machine secrets
Seal secret sets to your hosts and serve them to local apps from memory.
Build with the API
Explore the same HTTP API used by the web app, with requests and responses.
Two binaries
custoscp— the control plane: an HTTP API backed by Postgres. Source of truth for users, hosts, keys, grants, and secrets.custosd— a per-host daemon. It hooks sshd’sAuthorizedKeysCommandso every SSH login is gated by Custos, and it holds a long-lived WebSocket to the control plane, dialing out, so hosts need no inbound ports. It receives authorized-key snapshots and sealed secret sets, and serves those secrets to local apps.