Skip to content

Engity's Bifröst

SSH access with identity and session control

Bifröst lets platform teams combine SSH authorization with the environment in which a session runs. Users connect with a standard SSH client; OIDC Device Authorization also requires a browser and a supported identity provider. Sessions can run on a local account, in a Docker container or Kubernetes Pod, or through a separately authenticated SSH target. Bifröst is not a universal drop-in replacement for OpenSSH's sshd.

Bifröst was created for teams with time-bound off-boarding requirements, whether the target is 15 minutes, 60 minutes or another defined limit. Meeting it depends on the IdP, bounded access and checks of existing connections.

Install it as a host service: the host guide starts Bifröst on port 22 with the privileges required to open a real shell as an existing local account. Linux uses systemd, Windows uses a Windows service, and macOS uses a LaunchDaemon.

Choose your task

Features

SSH access with your identity

Connect using OpenSSH, PuTTY or another standard SSH client. Authorize with local accounts, SSH keys or OIDC Device Authorization; OIDC adds a browser verification step, not a separate SSH client.

Choose where sessions run

Open a shell on the host, in a Docker container or in a Kubernetes Pod. Flows combine the authorization method and session environment; container isolation depends on the permissions you grant.

SSH gateway to private servers

Connect through Bifröst to an existing SSH server. The gateway verifies the target host key and authenticates to it separately; it does not transparently proxy every SSH request.

Verifiable audit and recording

Optionally sign audit events and terminal recordings for later verification. Recording captures terminal output, not raw keyboard input or SFTP and forwarding payloads.

Bound access over time

Set maximum connection and session lifetimes, and optionally provision or clean up local accounts. OIDC's default policy checks refresh grants even for sessions reused with a remembered public key and closes Bifröst connections after a grant is rejected. Time-bound off-boarding still needs an end-to-end check.

More topics