> For the complete documentation index, see [llms.txt](https://docs.gotempest.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.gotempest.app/authentication.md).

# Authentication

- [YubiKey & FIDO2 SSH Authentication](https://docs.gotempest.app/authentication/yubikey-fido2-ssh-authentication.md): Use a YubiKey or any FIDO2 security key to authenticate SSH in Tempest on Mac, Windows, Linux — no agent or PAM module, works with ed25519-sk keys.
- [Post-Quantum SSH Algorithms (PQC)](https://docs.gotempest.app/authentication/post-quantum-ssh-algorithms.md): Post-quantum SSH explained — the ML-KEM (FIPS 203) and SNTRUP761 hybrid key exchanges OpenSSH 9+ ships, how to check your connection is quantum-safe, and why Tempest enables PQC by default.
- [HashiCorp Vault — Fetch SSH Credentials at Connect Time](https://docs.gotempest.app/authentication/hashicorp-vault-ssh-credentials.md): Fetch SSH credentials from HashiCorp Vault at connect time — Vault-signed SSH certificates or KV v2 secrets — instead of storing keys and passwords locally in Tempest.
