Agent forwarding
What agent forwarding does
Section titled “What agent forwarding does”With agent forwarding enabled, a remote host can ask your device to sign authentication requests with your local key — useful for hopping onward from a server, or pulling from a Git host, without copying your key to the server.
Every signature is approved locally
Section titled “Every signature is approved locally”Forwarded signing never happens silently in SigilTTY:
- Biometric-protected keys prompt for Touch ID / Face ID / passcode.
- Other keys show an explicit confirmation dialog.
You see each request as it happens and can deny it. A compromised server can’t quietly use your agent.
Security keys are deliberately left out of the forwarded identity list — a remote host cannot trigger a touch on your hardware key.
Enabling it
Section titled “Enabling it”Turn on agent forwarding per profile. Only enable it for servers you trust to make signing requests at all — the local approval step is the safety net, not a license to forward everywhere.