Wingetlywingetly
← All apps
O

OpenPubkey SSH

by OpenPubkeyv0.16.0

Last updated

A tool which enables SSH to be used with OpenID Connect, allowing SSH access management via identities like alice@example.com instead of long-lived SSH keys.

Install with winget

$ winget install --id openpubkey.opkssh --exact --version 0.16.0

Run in Command Prompt, PowerShell, or Windows Terminal. Prompts for any agreements.

Built by Pckgr

For Intune admins

Stop chasing app updates. Pckgr patches them for you.

Automated application patching for Microsoft Intune. Pckgr keeps a curated library of 1,000+ apps continuously up-to-date in your tenant via Microsoft Graph - no manual repackaging, no chasing vendor sites.

Start free 30-day trial

No credit card required.

About

opkssh is a tool which enables ssh to be used with OpenID Connect allowing SSH access management via identities like alice@example.com instead of long-lived SSH keys. It does not replace ssh, but rather generates ssh public keys that contain PK Tokens and configures sshd to verify the PK Token in the ssh public key. These PK Tokens contain standard OpenID Connect ID Tokens. This protocol builds on the OpenPubkey which adds user public keys to OpenID Connect without breaking compatibility with existing OpenID Provider.

Installers · v0.16.0

ArchitectureTypeScopeInstallDownload
x64Portable-Direct

Copy a command tailored to that specific architecture, type, and scope - useful when winget would otherwise pick a different default.

Security

1 known CVE via NVD

  • critical9.8Patched in wingetCVE-2025-4658affects before 0.5.0May 13, 2025

    Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in OpenPubkey also applies to OPKSSH versions p...

Source: NVD, updated 5h ago. Patch status is best-effort: NVD's fix version is compared against the latest version in winget, but the two version formats don't always align. Confirm with the vendor advisory before treating any specific build as safe.

Frequently asked questions

How do I install OpenPubkey SSH on Windows?
Open Windows Terminal, PowerShell, or Command Prompt and run: winget install --id openpubkey.opkssh --exact --version 0.16.0. winget downloads the installer from OpenPubkey and runs it. Requires Windows 10 (1809+) or Windows 11.
How do I install OpenPubkey SSH silently for unattended deployment?
Add --silent and accept the agreements upfront: winget install --id openpubkey.opkssh --exact 0.16.0 --silent --accept-package-agreements --accept-source-agreements. This is the variant Intune, Configuration Manager, and other deployment tools should use.
How do I uninstall OpenPubkey SSH via winget?
Run: winget uninstall --id openpubkey.opkssh --exact. Add --silent for unattended uninstalls. winget will use the registered uninstaller from OpenPubkey SSH's Apps & Features entry.
Is OpenPubkey SSH free?
OpenPubkey SSH is distributed under Apache-2.0. Refer to the publisher (https://github.com/openpubkey/opkssh) for the full license terms - Wingetly itself does not charge for installation.
Does OpenPubkey SSH work on Windows 10?
Yes, as long as your Windows 10 build supports winget (1809 or newer). winget ships with App Installer on Windows 10/11 and pulls OpenPubkey SSH directly from the publisher.
How do I keep OpenPubkey SSH up to date?
Run winget upgrade --id openpubkey.opkssh --exact, or winget upgrade --all to update everything winget tracks. We index 10 versions of OpenPubkey SSH from microsoft/winget-pkgs.

Recent versions

  • 0.16.0latest
  • 0.15.0
  • 0.14.0
  • 0.13.0
  • 0.12.0
  • 0.11.0
  • 0.10.0
  • 0.9.0
  • 0.8.0
  • 0.7.0