Thanks! Perhaps we have different trust levels, but I prefer to have an ssh key per service/identity/device so that I can revoke specific items as needed. Plus, getting the key onto the host device is automated once you have the sibling daemon (brew install lukeed/tap/pocketty) running. It just takes a device-pairing code, much like adding a new Apple device to your iCloud acct