pkg.soopen package index

brew / rank 6437

Install monkeysphere with Homebrew, apk, Nix

Use the OpenPGP web of trust to verify ssh connections. Version 0.44 via Homebrew; verified 2026-05-25. Also installable with nix: nix profile install nixpkgs#monkeysphere.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install monkeysphere

local Homebrew formula metadata

Linux

Alpine Linux apkverified · 92%
sudo apk add monkeysphere

Alpine Linux edge package indexes · monkeysphere · source: dl-cdn.alpinelinux.org

Nixverified · 92%
nix profile install nixpkgs#monkeysphere

nixpkgs package indexes · pkgs/by-name/mo/monkeysphere/package.nix · source: api.github.com

overview

Package summary

Use the OpenPGP web of trust to verify ssh connections

Commands and aliases

  • agent-transfer
  • monkeysphere
  • monkeysphere-authentication
  • monkeysphere-host
  • openpgp2pem
  • openpgp2spki
  • openpgp2ssh
  • pem2openpgp

history

Project history and usage

Monkeysphere is a security tool from the OpenPGP and Debian-adjacent world that tries to bring the OpenPGP web of trust to SSH and TLS authentication. Its README frames the project as extending OpenPGP's trust model to more areas of the Internet, with an implementation that lets users keep using OpenSSH while identifying users and servers through OpenPGP keys managed by GnuPG.

Project history

The project was written by Jameson Rollins and Daniel Kahn Gillmor, according to the monkeysphere(7) manual page. Early changelog entries from 2008 show rapid work on server diagnostics, key expiration, certifier management, privilege separation, OpenSSH known_hosts and authorized_keys handling, and Debian packaging, which fits its role as a glue layer around GnuPG and OpenSSH rather than a replacement protocol.

How it is used

Administrators use Monkeysphere to bind human-readable OpenPGP user IDs to SSH keys and host identities. The tools update authorized_keys and known_hosts after checking key validity, expiration, revocation, authentication-capable subkeys, and signatures from trusted identity certifiers. That makes its package-manager niche a specialized PKI bridge for people who already trusted OpenPGP key signing and wanted that trust graph to govern SSH host verification or user login access.

security posture

Risk level: blue

broad file, network, media, or database tool signal.

Risk classifier

blue risk · medium confidence · tool

Why

  • broad file, network, media, or database tool signal

Signals

  • text:ssh

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
agent-transferexecutableindexed executableDiscovered from the local executable index.
monkeysphereexecutableindexed executableDiscovered from the local executable index.
monkeysphere-authenticationexecutableindexed executableDiscovered from the local executable index.
monkeysphere-hostexecutableindexed executableDiscovered from the local executable index.
openpgp2pemexecutableindexed executableDiscovered from the local executable index.
openpgp2spkiexecutableindexed executableDiscovered from the local executable index.
openpgp2sshexecutableindexed executableDiscovered from the local executable index.
pem2openpgpexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version0.44
manager updated2026-05-25
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:monkeysphere
Version0.44
Package managerHomebrew
Homepagehttps://tracker.debian.org/pkg/monkeysphere
Last updated2026-05-25T17:02:24-04:00
Pulseupdated
Bottlenot recorded
Servicenone declared

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

monkeysphere

nix profile install nixpkgs#monkeysphere
  • normalized package name match
  • Matched by: Monkeysphere
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/mo/monkeysphere/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

monkeysphere 0.44-r4

OpenPGP web of trust certification tools for SSH and TLS servers

https://github.com/dkg/monkeysphere

sudo apk add monkeysphere
  • License: GPL-3.0-or-later
  • Architecture: x86_64
  • Source Package: monkeysphere
  • 1 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Monkeysphere
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: monkeysphere from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
apk95%

monkeysphere-doc 0.44-r4

OpenPGP web of trust certification tools for SSH and TLS servers (documentation)

https://github.com/dkg/monkeysphere

sudo apk add monkeysphere-doc
  • License: GPL-3.0-or-later
  • Architecture: x86_64
  • Source Package: monkeysphere
  • normalized package name match
  • Matched by: Monkeysphere
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: monkeysphere-doc from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation