Skip to content

Agent forwarding

With agent forwarding enabled, a remote host can ask your device to sign authentication requests with your local key — useful for hopping onward from a server, or pulling from a Git host, without copying your key to the server.

Forwarded signing never happens silently in SigilTTY:

  • Biometric-protected keys prompt for Touch ID / Face ID / passcode.
  • Other keys show an explicit confirmation dialog.

You see each request as it happens and can deny it. A compromised server can’t quietly use your agent.

Turn on agent forwarding per profile. Only enable it for servers you trust to make signing requests at all — the local approval step is the safety net, not a license to forward everywhere.