Sample code for 30+ languages & platforms
Dart

SSH Keyboard-Interactive Authentication

See more SSH Examples

Demonstrates keyboard-interactive authentication with an SSH server. StartKeyboardAuth returns XML describing the server's prompts, and ContinueKeyboardAuth submits each response. Authentication is complete when the returned XML contains either a success or an error node.

Background: Keyboard-interactive is SSH's flexible, prompt-driven method: rather than assuming a single password, the server asks one or more questions — a password, a one-time code, a security question — and the client answers each. This is how SSH supports two-factor and other challenge-response schemes. The prompt XML also indicates whether each response should be echoed, so a client knows when to mask input. A server may issue several rounds, so a robust implementation loops until it sees success or error rather than assuming one exchange is enough.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  // Demonstrates keyboard-interactive authentication with an SSH server.  The server sends one or
  // more prompts as XML, and the application answers each with ContinueKeyboardAuth.

  final ssh = CkSsh();

  ssh.connectTimeoutMs = 5000;
  ssh.readTimeoutMs = 15000;

  final hostname = 'ssh.example.com';
  final port = 22;
  try {
    ssh.connect(hostname, port);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Begin keyboard-interactive authentication.  The returned XML describes the server's prompts.
  String xmlResponse;
  try {
    xmlResponse = ssh.startKeyboardAuth('mySshLogin');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // If the server sent a user authentication banner, an application may display it before
  // prompting.
  print('UserAuthBanner: ${ssh.userAuthBanner}');

  final xml = CkXml();
  try {
    xml.loadXml(xmlResponse);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Authentication is complete when the XML contains either a "success" or an "error" node.
  if (xml.hasChildWithTag('success')) {
    print('No password required, already authenticated.');
    return;
  }

  if (xml.hasChildWithTag('error')) {
    print('Authentication failed.');
    return;
  }

  // Normally you would not hard-code the password in source.  You should instead obtain it
  // from an interactive prompt, environment variable, or a secrets vault.
  final password = 'mySshPassword';

  // Answer the prompt.  Typically one call is enough, but a server may issue several rounds of
  // prompts, so a robust client loops until it sees "success" or "error".
  try {
    xmlResponse = ssh.continueKeyboardAuth(password);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  try {
    xml.loadXml(xmlResponse);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  if (xml.hasChildWithTag('success')) {
    print('SSH keyboard-interactive authentication successful.');
    return;
  }

  if (xml.hasChildWithTag('error')) {
    print('Authentication failed.');
  }
}