BLAZINGFAST — SSH KEYS AND FIREWALL POLICIES Reviewed: 5 October 2026. Setup: 00-index.txt. Production release: SDK/CLI 0.1.17; contract 2026-10-07.1. Check GET /v1/version and GET /v1/capabilities before using optional workflow features. Strict response validation is enforced. PURPOSE Manage saved public SSH keys and reusable VPS firewall policies. These are account resources, not a replacement for portal authentication or OS passwords. PUBLIC API /v1/ssh/keys: list/import; name/public-key updates, default-key selection, public export and deletion. Key generation/private export are sensitive workflows. /v1/firewall/policies: list/create; policy update/delete and primary selection. /v1/vps/{serviceId}/sshkey and /firewall/policy/apply: apply supported settings. Permissions: ssh.read / ssh.write, firewall.read / firewall.write; VPS applications require vps.write; private export requires ssh.write and the correct passphrase. It is a sensitive operation, not part of normal key listing. CLI bf ssh list bf ssh public SSH_KEY_UUID bf firewall list bf vps firewall-policy SERVICE_UUID Use bf ssh --help and bf firewall --help before changes. Prefer keys generated locally and import only the public part. Never supply an SSH private key where a public key is expected. Avoid secret command-line arguments and shared transcripts for private export/generation workflows. MCP Hosted: list_ssh_keys, request_ssh_key_import/rename/primary/delete, list_firewall_policies, request_firewall_policy_create/replace/delete/primary, get_vps_firewall_policy, request_vps_firewall_policy. Hosted MCP returns public information only, never private keys. Local: bf_ssh_key_list and bf_firewall_policy_list only; no key/firewall mutations. LIMITS AND SAFETY Read the full policy/rules before replacing them. Retain SSH, monitoring and other required management access. Applying a policy can lock you out of your server. Changing a default key affects future access configuration; it is not a universal live SSH-key rotation across all deployed operating systems. Applying cloud-init settings does not prove a running guest immediately changed its authorized_keys.