SSH AGENT ROUTING / LINUX

LANYARD One socket. Every agent within reach.

Keep Git signing and SSH authentication working as you move between a local 1Password agent and forwarded laptop sessions—even inside the same long-running terminal-multiplexer session, whether you use Zellij, tmux, or another multiplexer.

Four braided cords connected to an industrial selector switch

OPERATING NOTE / 001

The stale socket problem.

01 / ARRIVE

SSH in with agent forwarding.

Your laptop’s agent appears at a temporary socket.

02 / ATTACH

Join an existing multiplexer session.

Zellij, tmux, or another multiplexer still remembers whichever socket started it.

03 / ROUTE

Point everything at Lanyard.

The socket stays put. The available agents can change underneath it.

How Lanyard routes SSH agent requestsThree agent sources converge at Lanyard, which exposes one stable socket to SSH, Git, and terminal multiplexers.FORWARDED AGENTREGISTERED AGENT1PASSWORDLANYARDTRY · PROMOTE · FAIL CLOSEDSSHGIT SIGNMUX SESSION
FIG. 01 Requests enter through one stable socket. Lanyard finds a key without making your shell remember where it lives.

DESIGN ORDERS

A switchboard, not a vault.

01
Lanyard never stores private keys. It speaks the standard SSH agent protocol to agents you already trust.
02
Identities are combined and deduplicated. Signing tries current agents in policy order without relying on stale identity-list results.
03
A successful signer moves to the front of the line for that key. Timeouts and failures fall through to the next candidate.
04
If no agent can sign, Lanyard fails closed. Mutation, key import, and agent locking are deliberately out of service.