Credentials
Vault-backed credential management for SSH passwords, keys, certificates, API tokens, and SNMP communities.
8 articles
Credential Vault
How the NetStacks vault encrypts credentials: a free local vault unlocked by a master password (Argon2id + AES-256-GCM), Touch ID, and the enterprise Controller.
Touch ID Vault Unlock (macOS)
Enable Touch ID for the NetStacks local vault: how the master password is wrapped in the macOS Keychain via LAContext, the self-healing fallback, and the security model.
SSH Passwords & Keys
Store SSH password and public-key credentials in NetStacks: key file paths, encrypted passphrases, supported algorithms, and the legacy SSH toggle for older devices.
SSH Certificates
How the NetStacks Controller signs short-lived Ed25519 SSH user certificates at login, auto-renews them, and lets devices trust a single CA public key.
API Tokens
How NetStacks uses API tokens: the local agent's single Bearer auth token, and the 'API Token' vault credential type for third-party sources like NetBox.
SNMP Communities
Store SNMPv2c community strings on a credential profile and use them for network discovery and live interface polling in NetStacks.
Credential Folders
Organize saved SSH sessions and topologies into nested folders. Folders are an organizational tree, not an access-control or credential-storage feature.
Personal Vaults
Per-user private credentials in NetStacks: store, edit, and reveal your own SSH keys, passwords, and secrets with audited reveal and AES-256-GCM encryption.
Need Help?
Can't find what you're looking for? Browse all documentation or get in touch.