‹ Guides

Agent forwarding v26.5.1+

Run git push or ssh on a server and sign in with the key on your phone — without copying the key onto the server.

Available in Term v26.5.1 and later.

Part of Term Pro.

Written

What it is for

You connect to a server with a key stored in Term. Then, on that server, you run something that needs a key of its own: git pull from GitHub, git push a branch, ssh to the next machine. The server has no private key, so it fails.

Agent forwarding lets the server borrow yours. When git or ssh on the server needs a signature, the request comes back over your connection and Term signs it on the phone. The server gets the signature, never the key.

It is what makes a remote dev box — or a coding agent running on one — able to push its own work.

Before and after

The same server, the same commands. First with forwarding off:

A terminal on a server named devbox. ssh-add -l answers that it could not open a connection to the authentication agent, and git clone git@git.internal:app.git fails with Permission denied (publickey).
Forwarding off. The server has no key: ssh-add -l finds no agent, and the clone is refused with Permission denied (publickey).

And with Forward agent turned on for the host:

The same terminal. ssh-add -l now lists one ED25519 key, git clone succeeds and receives the objects, and git log --oneline shows three commits.
Forwarding on. ssh-add -l lists the key from your phone — just that one — and the clone goes through. Nothing was copied onto the server.

Turn it on

Open the host: long-press it → Edit → Advanced options → Forward agent, then save.

The Forward agent switch in the host editor's advanced options, turned on, with its explanation underneath.
Host editor · Advanced options. One switch per host, off by default.

It needs three things:

To check it is working, run ssh-add -l on the server: it should list one key.

Before you turn it on

Only on servers you trust

While you are connected, anyone with root on that server can ask your phone to sign in as you. They cannot take the key, but they can use it for as long as the session is open. That is why it is off by default, per host, and why OpenSSH ships it off too.

Only this host’s key, only while connected

The server is offered the one key this host signs in with — none of your other keys — and nothing else: it cannot add, remove or list other keys. When you disconnect, it is gone.

Reaching another server? Use a jump host instead

If what you want is to get from a bastion to an internal machine, set up a jump host. Each hop signs in from your phone and your key is never usable on the bastion. Forwarding is for commands that run on the server, like git. With a jump chain, only the last host gets the agent.

If it doesn't work

“Could not open a connection to your authentication agent”

Forwarding is not reaching the server. Check that the switch is on for this host and saved, that the host signs in with a key and is an SSH host, and that you reconnected after turning it on. Some servers disable it: AllowAgentForwarding no in the server’s sshd config.

ssh-add -l lists the key, but git is still refused

Forwarding works; the destination does not know the key. Add the key’s public half there — for GitHub, under Settings → SSH keys.