SSH Sessions

SSH session metadata is recorded for audit and troubleshooting. When ssh_recording is enabled in the server config, session stdout is also captured in chunks for playback.

List SSH Sessions

GET /api/v1/ssh/sessions
GET /api/v1/ssh/sessions?limit=50&offset=0

List SSH sessions. Admins see all sessions; operators see only their own sessions.

Query parameters:

Response: 200 OK

{
  "sessions": [
    {
      "id": "uuid",
      "user_id": "uuid",
      "username": "admin",
      "device_router_id": "10.0.0.1",
      "device_hostname": "router1",
      "protocol": "ssh",
      "client_ip": "198.51.100.20",
      "started_at": "2026-02-17T10:30:00Z",
      "ended_at": "2026-02-17T10:45:00Z",
      "bytes_sent": 4096,
      "bytes_received": 65536
    }
  ],
  "total": 150,
  "limit": 50,
  "offset": 0
}

Field notes:

Get SSH Session

GET /api/v1/ssh/sessions/{sessionID}

Get a single SSH session by ID. Admins can view any session; operators can only view their own.

Response: 200 OK (single session object)

Error responses:

Get SSH Session Log

GET /api/v1/ssh/sessions/{sessionID}/log

Get the session stdout log as an ordered array of recording chunks. Only available when session recording is enabled (ssh.session_recording) and the session has recorded data; otherwise the array is empty. Chunks are decrypted server-side when OSPREY_ENCRYPTION_KEY is configured.

Response: 200 OK — a flat array (not an envelope); concatenate data in chunk_index order.

[
  {
    "id": "uuid",
    "session_id": "uuid",
    "chunk_index": 0,
    "data": "base64-encoded-stdout-data",
    "recorded_at": "2026-02-17T10:30:01Z"
  }
]

Error responses: