SSH Client Configuration Audit

Review supported SSH client settings for a named target and explain selected first-obtained values offline.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Review SSH settings controls

Up to 200,000 characters and 5,000 lines. Host blocks and the options listed on this page are explained. Include and Match are refused instead of guessed at.

The name you would type on the command line, such as git.example.com. Host patterns are matched against this name.

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use SSH Client Configuration Audit

  1. Supply the ssh client configuration and target host you would connect to using the supported input described beside the controls.
  2. Review the selected options and the declared scope, then run the ssh client configuration audit.
  3. Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.

Example: SSH Client Configuration Audit

Explain a supplied supported SSH client configuration and flag declared risky options/conflicts. This example uses synthetic public data.

You add
SSH client configuration: # Work hosts Host *.example.com User deploy IdentityFile ~/.ssh/id_ed25519_work StrictHostKeyChecking yes Host jumpserver HostName jump.example.net ForwardAgent yes StrictHostKeyChecking no UserKnownHostsFile /dev/null Target host you would connect to: jumpserver
You get
4 options apply to jumpserver; 3 need a closer look. forwardagent | yes | line 9 | MEDIUM: The local SSH agent is offered to the remote host, so anything running there can use your keys while you are connected. hostname | jump.example.net | line 8 | No specific concern on this page. stricthostkeychecking | no | line 10 | HIGH: Host keys may be accepted without confirmation, including changed keys subject to client restrictions. Verify trusted pins separately.

Options

Target host
Enter the target name to compare with supported positive and negative Host patterns.
Supported options
Review the selected values and their reasons. Unsupported directives must be handled in the real client rather than assumed harmless.

Supported inputs and limits

Declared supported Host/configuration subset only. No Include/Match expansion, shell execution, host contact or complete OpenSSH environment audit.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Read the effective supported values in order

A setting obtained earlier can affect how later matching Host blocks are interpreted. The result models the supported supplied configuration, not other files, environment state or a particular installed SSH version. Include and Match need another workflow and are refused. Commands and hosts are never executed or contacted.

Questions about SSH Client Configuration Audit

Are Include files opened?

No. Include and Match are refused in this supported subset.

Will proxy commands run?

No. The review does not execute commands.

Is this my actual SSH configuration?

Only the supplied text and supported target semantics are modeled. Other files and runtime conditions are unverified.

Project manager: Tony Hines · Content updated 4 October 2026 · Report a problem