OpenSSH 10.3, released April 2, 2026, adds standardized SSH agent-forwarding negotiation, agent capability queries, and new connection diagnostics. Existing forwarding setups can continue to work: OpenSSH retains its older @openssh.com extensions for interoperability while preferring the IANA-assigned codepoints when both peers advertise support. The main upgrade concern is a separate compatibility change: connections to peers that cannot rekey may fail once rekeying is needed.
What changed in OpenSSH 10.3 agent forwarding?
OpenSSH 10.3/10.3p1 adds support in ssh(1) and sshd(8) for the IANA-assigned SSH agent-forwarding codepoints associated with draft-ietf-sshm-ssh-agent. The peers advertise support through the SSH EXT_INFO message. If the other side offers the standardized names, OpenSSH prefers them; it still supports the older @openssh.com extensions so mixed-version connections can interoperate.
This is a wire-protocol negotiation change, not a new forwarding workflow or a new setting administrators must enable. Existing forwarding configurations can continue to work, while compatible peers have a standardized way to negotiate the feature. OpenSSH 10.3 was released by the OpenSSH Project on April 2, 2026; see the official release notes and release announcement.
How to query agent extensions and inspect connections
OpenSSH 10.3 adds tools for checking agent capabilities and understanding the connection carrying a session. These diagnostics can help distinguish a negotiation or connection issue from a key or policy problem.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
ssh-add -Qqueries the protocol extensions supported by the agent. OpenSSH 10.3’sssh-agent(1)implements the draft protocol’s query extension.- In an interactive SSH session, enter
~Iat the beginning of a line to display information about the current connection. - For a multiplexed connection, run
ssh -Oconninfo user@hostto request connection information. - For a multiplexed connection, run
ssh -O channels user@hostto list currently open channels.
Replace user@host with the destination matching the existing multiplexed connection. The control commands query that connection; they do not establish a separate diagnostic session.
What to check when upgrading
Forwarding across mixed OpenSSH versions
When agent forwarding fails across a bastion, CI runner, or other intermediary, check both the client and server versions at each hop. The standardized codepoints are used when offered, and the legacy extensions remain available, but failures may also involve the peer’s implementation or the route through which the forwarded connection is carried. Use ssh-add -Q to inspect agent extensions, and the connection and channel commands to establish which connection is active.
Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Peers that cannot rekey
OpenSSH 10.3 removes bug compatibility for implementations that do not support rekeying. If a connection uses such a peer, it may initially work and then fail when the transport needs to rekey. Test these connections during upgrade planning rather than treating a later disconnect as an agent-forwarding regression.
SSH configuration and accepted-key algorithms
The release validates shell metacharacters in command-line usernames earlier. This closes cases where values could be expanded from percent tokens in ssh_config, including %u in a Match exec block. OpenSSH 10.3 also fixes incomplete application of PubkeyAcceptedAlgorithms and HostbasedAcceptedAlgorithms to ECDSA keys, alongside other security and bug fixes documented in the release notes.
What forwarded agent access means for security
Agent forwarding exposes the ability to request signing operations; it does not copy private-key material to the remote host. The OpenSSH project describes forwarding as making the authentication agent available over connections without storing the user’s authentication keys on network machines other than the user’s own. That distinction reduces key exposure, but forwarding is still a trust decision: a compromised intermediate host may be able to ask the agent to authenticate.
Forward selectively, and use destination or confirmation constraints where supported by your wider SSH policy. The protocol negotiation improvements in 10.3 do not make an untrusted host safe to forward through.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

