Engity's Bifröst
SSH access with identity and session control
Bifröst lets platform teams combine SSH authorization with the environment in which a session runs. Users connect with a standard SSH client; OIDC Device Authorization also requires a browser and a supported identity provider. Sessions can run on a local account, in a Docker container or Kubernetes Pod, or through a separately authenticated SSH target. Bifröst is not a universal drop-in replacement for OpenSSH's sshd.
Bifröst was created for teams with time-bound off-boarding requirements, whether the target is 15 minutes, 60 minutes or another defined limit. Meeting it depends on the IdP, bounded access and checks of existing connections.
Install it as a host service: the host guide starts Bifröst on port 22 with the privileges required to open a real shell as an existing local account. Linux uses systemd, Windows uses a Windows service, and macOS uses a LaunchDaemon.
Choose your task
- Connect to a private OpenSSH server through an SSH gateway.
- Log in with OIDC using an SSH client and a browser verification step.
- Verify a session recording and export the recorded output.
Features
SSH access with your identity
Connect using OpenSSH, PuTTY or another standard SSH client. Authorize with local accounts, SSH keys or OIDC Device Authorization; OIDC adds a browser verification step, not a separate SSH client.
Choose where sessions run
Open a shell on the host, in a Docker container or in a Kubernetes Pod. Flows combine the authorization method and session environment; container isolation depends on the permissions you grant.
SSH gateway to private servers
Connect through Bifröst to an existing SSH server. The gateway verifies the target host key and authenticates to it separately; it does not transparently proxy every SSH request.
Verifiable audit and recording
Optionally sign audit events and terminal recordings for later verification. Recording captures terminal output, not raw keyboard input or SFTP and forwarding payloads.
Bound access over time
Set maximum connection and session lifetimes, and optionally provision or clean up local accounts. OIDC's default policy checks refresh grants even for sessions reused with a remembered public key and closes Bifröst connections after a grant is rejected. Time-bound off-boarding still needs an end-to-end check.