SSH AGENT ROUTING / LINUX
LANYARD One socket. Every agent within reach.
Keep Git signing and SSH authentication working as you move between a local 1Password agent and forwarded laptop sessions—even inside the same long-running terminal-multiplexer session, whether you use Zellij, tmux, or another multiplexer.

DESIGN ORDERS
A switchboard, not a vault.
- 01
- Lanyard never stores private keys. It speaks the standard SSH agent protocol to agents you already trust.
- 02
- Identities are combined and deduplicated. Signing tries current agents in policy order without relying on stale identity-list results.
- 03
- A successful signer moves to the front of the line for that key. Timeouts and failures fall through to the next candidate.
- 04
- If no agent can sign, Lanyard fails closed. Mutation, key import, and agent locking are deliberately out of service.