Repository navigation
How It Works
Lanyard owns one marked block at the top of ~/.ssh/config, and never changes anything outside it:
# >>> lanyard managed section >>>
# Generated by Lanyard. Change these entries from the app or the
# `lanyard` CLI - manual edits inside this section are overwritten.
# GitHub - active account: work
Host github.com
User git
IdentityFile ~/.ssh/id_ed25519_github_work
IdentitiesOnly yes
# GitHub - account: work
Host github.com-work
HostName github.com
User git
IdentityFile ~/.ssh/id_ed25519_github_work
IdentitiesOnly yes
# GitHub - account: personal
Host github.com-personal
HostName github.com
User git
IdentityFile ~/.ssh/id_ed25519_github_personal
IdentitiesOnly yes
Host *
# <<< lanyard managed section <<<
# ...your own config, byte for byte as you wrote it...-
The active block (
Host github.com) is what plaingit@github.com:…URLs use. Switching accounts rewrites it. -
Alias blocks (
Host github.com-personal) always use one account's key, so URLs with the alias are unaffected by switching. -
IdentitiesOnly yesmakes SSH offer only that key. Without it, SSH also tries every key in the agent, which is how pushes end up on the wrong account. - Why at the top: SSH uses the first value it finds for each option, so these blocks must come before anything else that could match.
-
The trailing
Host *ends the managed blocks' scope, so the global options at the top of your own section still apply to every host.
The section is rebuilt from your saved accounts on every change. Edit accounts in the app or with the CLI rather than by hand; lanyard config sync regenerates it.
| File or folder | What Lanyard does with it |
|---|---|
~/.ssh/config |
Reads all of it; writes the managed section and the host blocks you edit. Backed up first. |
~/.ssh/<key> and <key>.pub
|
Creates keys you generate; moves keys you delete to the trash. |
~/.ssh/known_hosts |
Adds keys you trust, removes entries you forget. Backed up first. |
~/.gitconfig |
Sets user.name / user.email on switch, only for accounts with Set the global git identity on. |
<repo>/.git/config |
Only when you point a repository at an account: the remote URL and the repo's identity. |
~/.lanyard/state.json |
Your accounts, custom providers and settings. No keys or passphrases. |
~/.lanyard/backups/ |
Snapshots of config and known_hosts. |
~/.lanyard/trash/ |
Keys you deleted. |
Lanyard writes your existing files in place, so their permissions (and Windows ACLs, which OpenSSH checks) stay as they were. New files are created readable only by you.
The desktop app, the tray and the lanyard command run the same code against the same files. Lanyard watches ~/.ssh and ~/.lanyard, so a change made in one place, or by hand in an editor, shows up in the others within a moment.
The desktop app uses Tauri 2. Its Rust backend owns the window and system tray, handles native operations, and routes domain requests to a Node.js sidecar. The React renderer uses the typed app API and has no direct filesystem access. Passphrases are passed to the relevant OpenSSH tool and never stored. See SECURITY.md for the project's security notes.
This wiki is generated from docs/wiki in the repository. To suggest a change, edit the file there and open a pull request.
Start
Using the app
- Git accounts
- Hosts (remote servers)
- Keys
- ssh-agent
- Known hosts
- Backups
- Settings
- Tray, palette and shortcuts
Reference