By NHI Mgmt Group Editorial TeamBased on JumpCloud: “Beyond SSH Keys: Securing Server Access for Engineers” (September 18, 2025)

TL;DR: Static SSH keys and hardcoded passwords create permanent, hard-to-audit server access paths that break modern privileged access governance, according to JumpCloud. The real issue is not just stronger authentication, but eliminating standing access and making every session attributable, time-bound, and centrally revocable.


At a glance

What this is: This is a JumpCloud analysis arguing that static SSH keys and hardcoded passwords no longer fit modern server access governance because they create permanent, untraceable access paths.

Why it matters: It matters because IAM, PAM, and NHI programmes need server access that is attributable, time-bound, and centrally revocable rather than permanently issued and manually cleaned up.


Context

Static SSH keys are long-lived credentials used to authenticate server access without interactive login. In this model, the credential itself becomes the control point, which means leakage, reuse, and forgotten revocation can leave persistent access behind long after the original need has passed.

The governance gap is not authentication alone but lifecycle control. For IAM and PAM teams, the article’s core argument is that server access should be issued through centralized identity, enforced with MFA where possible, and expired automatically so access is auditable and removable at scale.


Key questions

Q: What breaks when static SSH keys are used for server access governance?

A: Static SSH keys break governance because access can persist long after the business need has ended. They are hard to attribute, hard to revoke everywhere at once, and easy to forget during offboarding. That leaves permanent access paths that behave more like standing privilege than controlled access, which is why lifecycle management matters as much as authentication.

Q: Why do standing credentials increase risk in server environments?

A: Standing credentials increase risk because they outlive the session, the task, and sometimes the employee who received them. If a key is copied or leaked, it can be reused until every copy is found and removed. That creates both lateral movement opportunity and an audit gap, especially in fleets where manual cleanup does not scale.

Q: How can security teams tell whether server access is actually time-bound?

A: Server access is time-bound only when credentials expire automatically and can be traced back to a specific identity, target, and session. If teams must rely on periodic key sweeps or manual removal after offboarding, the access model is still standing privilege. The signal is whether revocation happens centrally, not host by host.

Q: Should organisations keep managing SSH keys directly or move to mediated access?

A: If teams spend more time distributing, revoking and auditing keys than using them for real operational access, mediated access usually wins. The decision is less about convenience than about whether the programme can reliably enforce lifecycle controls at scale. Direct key management works only when ownership, rotation and offboarding are tightly disciplined.


Technical breakdown

Why static SSH keys become standing privilege

Static SSH keys grant access until someone remembers to remove them. That makes them structurally different from time-bound credentials because the access decision is front-loaded at issuance and often detached from later context such as role changes, device posture, or session purpose. Once copied to multiple servers, keys become hard to inventory, hard to attribute, and easy to miss during offboarding. The governance problem is not just exposure. It is that the access path persists independently of the business need that created it.

Practical implication: treat static SSH keys as standing privilege and map every long-lived key to an owner, system, and revocation path.

How JIT access changes server authentication

Just-in-time access shifts server access from permanent entitlement to temporary issuance. Instead of relying on a reusable SSH key, the access broker issues time-limited credentials tied to a specific identity, target system, and session window. That reduces the blast radius of a stolen credential because the access token expires automatically and does not remain valid for future use. The central benefit is not convenience. It is that access becomes attributable, bounded, and easier to govern across a server fleet.

Practical implication: design server access so credentials expire by default and are issued only for the specific task and system in question.

Why centralised identity and audit trails matter

Centralized identity control makes server access visible across the full lifecycle. When access is brokered through a common control plane, security teams can correlate who requested access, which server was reached, what commands were run, and when the session ended. That auditability is what static keys usually lack. It also reduces the risk of orphaned access after offboarding, because revocation happens once at the identity layer rather than server by server. In governance terms, this is the difference between scattered enforcement and centrally managed accountability.

Practical implication: move server authentication into a central control plane so offboarding and forensics do not depend on manual host-by-host cleanup.


Threat narrative

Attacker objective: The attacker seeks durable server access that survives normal identity changes and can be reused without easy attribution or revocation.

  1. Entry occurs when a static SSH key or hardcoded password is copied, stolen, shared, or left behind in infrastructure and then reused for server access.
  2. Credential abuse follows because the key remains valid indefinitely unless someone manually removes it from every affected host.
  3. Impact comes from persistent, untraceable access into production systems, which creates a durable backdoor and complicates forensic reconstruction.
  • JumpCloud breach 2023: North Korean hackers breached JumpCloud and abused its device commands framework against a few customers; all admin API keys were reset.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Static SSH keys are a standing privilege problem, not an authentication nuance. Once a key is issued, the access path persists until humans find and remove it, which makes the control model dependent on perfect hygiene across every server. That is an offboarding and revocation failure mode, not a login problem. Practitioners should treat any long-lived SSH key as persistent authority that must be governed as a lifecycle object.

Zero standing privilege is the correct governance lens for server access. The article’s core point is that permanent credentials do not age well in modern infrastructure because they are hard to attribute, easy to reuse, and fragile under scale. A server access programme built on JIT issuance and central identity control aligns governance with actual use rather than assumed trust. The implication is that access should exist only while the task exists.

Static credential sprawl creates hidden accountability debt. The more keys are distributed across servers, engineers, and automation paths, the harder it becomes to prove who had access at any moment. That weakens incident response, recertification, and offboarding alike because the authoritative state lives on hosts instead of in the identity layer. The practical conclusion is that governance must move from host-level cleanup to centrally managed entitlement state.

Ephemeral server access should be the default control objective for infrastructure identity. Static SSH keys and hardcoded passwords assume access is stable enough to manage manually, but modern server estates are too dynamic for that assumption. The right question is no longer how to secure a permanent credential, but how to make access disappear when the task ends. Teams should redesign server access around temporary issuance, visibility, and revocation at the identity plane.

From our research library:

What this signals

Static SSH keys create governance debt because the control lives in the credential, not in the session. That means revocation depends on finding every copy, while accountability depends on reconstructing usage after the fact. For infrastructure teams, the real shift is toward issuance-time control, not post-incident cleanup.

Ephemeral server access changes what identity teams need to measure. The important signal is no longer how many keys exist, but whether access can be issued, traced, and removed from a single control plane before a task completes. That is the operational boundary modern PAM and NHI programmes have to enforce.


For practitioners

  • Audit and inventory static SSH keys Find all SSH keys, hardcoded passwords, and shared credentials across production, staging, and automation paths. Map each one to an owner, a server set, and a revocation method so orphaned access is visible before it becomes a cleanup issue.
  • Replace standing access with JIT issuance Issue temporary credentials for a specific server and task window instead of allowing reusable keys to remain valid indefinitely. Tie the request to a central identity so access expires automatically when the session ends.
  • Centralize revocation at the identity layer Remove reliance on manual host-by-host key deletion by revoking access from a central control plane when roles change or people leave. This reduces the chance that forgotten keys remain active on unmanaged servers.
  • Require session-level auditability Log who accessed which server, when access started and expired, and what commands were run. Use those records for forensics, access reviews, and compliance evidence instead of assuming a static key is enough proof.

Key takeaways

  • Static SSH keys and hardcoded passwords leave permanent access paths that do not fit modern server governance.
  • The central risk is not just exposure of a credential but the loss of revocation, attribution, and lifecycle control.
  • Just-in-time access and centralized identity control reduce standing privilege by making server access temporary and auditable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingStatic keys persist after role changes and leavers, which is an offboarding failure mode.
NHI-05 — Overprivileged NHIStanding SSH keys often grant more persistent access than the task requires.
NHI-07 — Long-Lived SecretsStatic SSH keys are long-lived secrets with indefinite reuse potential.
Recommendation — Tie SSH key removal to offboarding and revoke any credential that outlives the user or workload need. Reduce standing SSH access by limiting every credential to the minimum server scope and shortest practical duration. Replace long-lived SSH keys with time-bound credentials and enforce automatic expiry.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementIA-5 covers issuance, rotation, and revocation of authenticators used for server access.
Recommendation — Use IA-5 to manage SSH authenticator lifecycle, including rotation and rapid revocation.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article focuses on centrally governing and revoking access permissions for server identities.
Recommendation — Apply PR.AA-05 to centralize entitlements and remove standing server access from the identity plane.
NIST Zero Trust (SP 800-207)3.4 — Access Control in Zero Trust ArchitectureJIT server access aligns with zero trust principles by removing persistent trust in static credentials.
Recommendation — Use zero trust access control to broker server sessions dynamically instead of trusting permanent keys.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementStatic key theft and reuse are common enablers of credential abuse and movement across servers.
Recommendation — Map exposed SSH keys to credential access and lateral movement detections in your monitoring pipeline.

Key terms

  • Static SSH Key: A static SSH key is a long-lived public and private key pair used for remote login and system access. Because it persists until someone manually removes it, it can outlive employment changes, become hard to inventory, and create standing access that is difficult to govern at scale.
  • Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
  • Zero Standing Privilege: A control model in which an identity does not keep persistent access unless it is actively needed. For NHIs, this means credentials and permissions are issued for a narrow task and then removed. It reduces the time window and reuse value of stolen access.
  • Authenticator Lifecycle Management: Authenticator lifecycle management is the governance of a credential from issuance to renewal, replacement, and retirement. For human identity programmes, it ensures that keys, smart cards, and certificates stay tied to the right user and are removed when the user, role, or device is no longer trusted.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org