> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# SSH and terminal

> The SSH tunnel every kiste ssh, scp and forward uses, the host key it pins, and the browser terminal.

The SSH tunnel every `kiste ssh`, `scp` and `forward` uses, the host key it pins, and the browser terminal.

## Get the SSH host key

`GET /v1/instances/{name}/ssh-host-key`

The Kiste's SSH host key with the alias `NAME.kiste` and a ready `known_hosts` line. The CLI pins this key, so a connection to anything else fails.

**Path parameters:**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `name` | string | yes | The Kiste's name. |

```bash
curl -sS "https://kiste.run/v1/instances/review-42/ssh-host-key" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `200` OK. Body: [SshHostKeyResponse](https://docs.kiste.run/api/schemas.md#sshhostkeyresponse)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Open the SSH tunnel

`GET /v1/instances/{name}/ssh-tunnel`

A WebSocket that carries the raw SSH connection to the Kiste's SSH server; `kiste proxy` is the OpenSSH ProxyCommand that uses it. Binary frames both ways. Before the upgrade it answers `409` when the Kiste is not running, its SSH server is not listening yet, or the account already has 32 tunnels open. An idle tunnel closes after one hour without traffic; stopping, restarting or deleting the Kiste and signing out everywhere close it too.

**Path parameters:**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `name` | string | yes | The Kiste's name. |

**Responses:**

- `101` WebSocket upgrade.

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Open a browser terminal

`POST /v1/instances/{name}/terminal`

Issues a short-lived capability for a terminal in the browser, as the console's Terminal page uses it. `cols` and `rows` set the initial size.

**Path parameters:**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `name` | string | yes | The Kiste's name. |

```bash
curl -sS -X POST "https://kiste.run/v1/instances/review-42/terminal" \
  -H "Authorization: Bearer $KISTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"cols":120,"rows":40}'
```

**Request body:** [CreateTerminalSessionRequest](https://docs.kiste.run/api/schemas.md#createterminalsessionrequest)

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `cols` | integer (int32) | no |  |
| `rows` | integer (int32) | no |  |

**Responses:**

- `200` OK. Body: [TerminalSessionEnvelope](https://docs.kiste.run/api/schemas.md#terminalsessionenvelope)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Connect a browser terminal

`GET /v1/terminal/connect`

The WebSocket of a browser terminal, opened with the capability from the call above.

**Responses:**

- `101` WebSocket upgrade.

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Related topics

- [Overview](https://docs.kiste.run/api.md)
- [Conventions](https://docs.kiste.run/api/conventions.md)
- [Kisten](https://docs.kiste.run/api/instances.md)
- [Commands](https://docs.kiste.run/api/commands.md)
- [Snapshots](https://docs.kiste.run/api/snapshots.md)
- [Desktop](https://docs.kiste.run/api/desktop.md)
- [Kiste Stream](https://docs.kiste.run/api/stream.md)
- [Images and environments](https://docs.kiste.run/api/images.md)
- [Events, webhooks and alerts](https://docs.kiste.run/api/events.md)
- [Account and access](https://docs.kiste.run/api/account.md)
- [Sign-in and platform](https://docs.kiste.run/api/platform.md)
- [Schemas](https://docs.kiste.run/api/schemas.md)
- Previous: [Snapshots](https://docs.kiste.run/api/snapshots.md)
- Next: [Desktop](https://docs.kiste.run/api/desktop.md)
