What Bastyx works with today.
Device enrollment, workstation login, SSH and app access are listed separately, because they’re separate questions. Each entry is marked available, beta or planned.
Status labels
- Available
- In the product today, supported for production use.
- Beta
- Works today; details may change. Ask before relying on it.
- Planned
- On the roadmap. Not usable yet.
Not listed means not supported yet. Ask at hello@bastyx.com.
Laptops and workstations
macOS, Windows and Linux
People install the Bastyx app once. It enrolls the device, handles login and issues SSH credentials to the standard OpenSSH client.
| macOS | Windows | Linux | |
|---|---|---|---|
| Device enrollmentBastyx app: .pkg, .msi, .deb and .rpm. Deployable with your MDM. | Available | Available | Available |
| Workstation loginUnlock with a fingerprint or security key instead of a password. | Available | Available | Available |
| SSH clientThe standard OpenSSH client, 8.2 or later. Your ssh command doesn’t change. | Available | Available | Available |
| bastyx CLIbastyx login and bastyx status from the terminal. | Available | Available | Available |
Device enrollment
- macOS
- Available
- Windows
- Available
- Linux
- Available
Workstation login
- macOS
- Available
- Windows
- Available
- Linux
- Available
SSH client
- macOS
- Available
- Windows
- Available
- Linux
- Available
bastyx CLI
- macOS
- Available
- Windows
- Available
- Linux
- Available
Servers
The bastyx agent runs on each server, adds the Bastyx user CA to sshd and ends sessions on revocation.
- Available
Linux with systemd and OpenSSH 8.2+
For example Ubuntu 20.04+, Debian 11+, RHEL 8+ and Amazon Linux 2023.
Identity providers
People, teams and roles sync from your directory. Offboarding there offboards in Bastyx.
- Available
Okta
Directory sync
- Available
Microsoft Entra ID
Directory sync
- Available
Google Workspace
Directory sync
- Available
No identity provider
Manage people and teams in Bastyx
Application access
How people reach web apps, cloud consoles and legacy software without a password.
- Available
SAML 2.0 and OpenID Connect
SaaS, cloud consoles and internal apps with SSO
- Available
Access proxy
Internal web apps without SSO, via a trusted identity header
- Available
Vaulted credentials
Apps that only accept a username and password
- Available
Active Directory and Kerberos
Apps using Integrated Windows Authentication
Authenticators
Standard FIDO2 hardware. Nothing proprietary is required.
- Available
YubiKey
YubiKey 5, Security Key and YubiKey Bio Series (FIDO2)
- Available
Other FIDO2 security keys
USB-A, USB-C and NFC
- Available
Built-in fingerprint sensors and passkeys
On the laptops people already have
- Available
Bastyx USB-C fingerprint reader
Optional, for machines without a sensor
AI agents
Agents get their own identities instead of borrowing a person’s token.
- Available
Agent identities
Named owner, policy and short-lived credentials
Checking fit for your setup?
The quickstart lists installation requirements and the server-side change, and the pilot plan shows what four weeks look like.
Bring every login, key and server under one control layer.
Tell us what you’re securing and see Bastyx live in 20 minutes. We reply the same business day.