How to Configure SSH Access on AtomCam with authorized_keys File

AtomCam tools configure SSH access by checking for an authorized_keys file on the SD-Card at boot; if present, init scripts copy the keys to /root/.ssh and start the SSH daemon automatically.

The mnakada/atomcam_tools repository provides a firmware overlay that enables key-based SSH access on Wyze/AtomCam devices. Instead of hardcoding passwords, the system leverages a writable SD-Card partition to securely inject your public keys during the boot process. This guide explains the exact mechanism, from the initialization scripts that check for the file to the workflow for adding your keys before building the firmware.

How SSH Initialization Works on AtomCam

AtomCam boots using an initramfs that mounts the SD-Card’s second partition as /media/mmc. The firmware includes two specialized init scripts that run during startup to conditionally enable SSH based on the presence of an authorized_keys file in that mount point.

S55sshd: Conditional SSH Daemon Startup

Located at overlay_rootfs/etc/init.d/S55sshd, this script acts as a gatekeeper for the SSH service. It first verifies that the ssh-keygen binary exists, then immediately exits if /media/mmc/authorized_keys is not found. This design ensures the device can operate without SSH exposed if no keys are provided. When the file exists, the script generates host keys on first boot and launches the daemon:

[ -f /media/mmc/authorized_keys ] || exit 0    # Only continue if authorized_keys is present

/usr/bin/ssh-keygen -A                         # Generate host keys if missing

/usr/sbin/sshd                                 # Start the SSH daemon

According to the source code in S55sshd, this conditional check prevents the SSH service from starting unnecessarily, reducing the attack surface on devices where remote access is not required.

S21rootkeys: Installing User Public Keys

Running in the same initialization phase, overlay_rootfs/etc/init.d/S21rootkeys handles the secure placement of your public keys. The script creates the root user’s SSH directory with restrictive permissions, then copies the authorized_keys file from the SD-Card into the standard location that sshd expects:

mkdir -p /root/.ssh
chmod 700 /root/.ssh
[ -f /media/mmc/authorized_keys ] && cp /media/mmc/authorized_keys /root/.ssh

Once copied to /root/.ssh/authorized_keys, the OpenSSH daemon automatically uses this file to authenticate incoming connections. The sshd process, started subsequently by S55sshd, validates connecting clients against these pre-installed public keys without requiring password authentication.

Setting Up SSH Access Before Building

To enable SSH access, you must populate the target/authorized_keys file in the repository before running the build process. This file is packaged into the final atomcam_tools.zip and extracted to the SD-Card’s /media/mmc directory during installation.

Append your local public key to the repository’s placeholder file:

cat ~/.ssh/id_rsa.pub >> ./target/authorized_keys

After adding your key, run the build command (typically inside the provided Docker container) to generate the firmware zip:

make

The build system includes target/authorized_keys in the output archive. When you flash this firmware to your SD-Card and insert it into the AtomCam, the init scripts detect the file at /media/mmc/authorized_keys and automatically configure SSH access on the next boot.

Connecting to Your AtomCam

Once the device boots with the configured SD-Card, connect using the root account and your private key:

ssh root@<atomcam-ip>

No password prompt appears; authentication proceeds silently using the public key you placed in target/authorized_keys. You can verify that your key was properly packaged into the firmware by inspecting the zip archive before flashing:

unzip -p atomcam_tools.zip authorized_keys

This command should output the public key string you previously appended.

Manual Key Installation (Post-Boot Debugging)

If you need to enable SSH on a running device without rebuilding the firmware, you can manually configure the keys via serial console or UART access. Execute these commands directly on the AtomCam shell:

mkdir -p /root/.ssh && chmod 700 /root/.ssh
echo "ssh-rsa AAAAB3N..." > /root/.ssh/authorized_keys
chmod 600 /root/.ssh/authorized_keys
/usr/bin/ssh-keygen -A
/usr/sbin/sshd

This bypasses the init script logic but achieves the same result: sshd will accept connections authenticated against the manually installed key.

Summary

  • Conditional startup: The S55sshd script at overlay_rootfs/etc/init.d/S55sshd only starts the SSH daemon if /media/mmc/authorized_keys exists on the SD-Card.
  • Key deployment: The S21rootkeys script copies the SD-Card’s authorized_keys to /root/.ssh/authorized_keys with correct 700 permissions on the directory.
  • Pre-build configuration: Add your public key to target/authorized_keys before running make to include it in the firmware zip.
  • Host key generation: The system runs ssh-keygen -A automatically on first boot to generate necessary host keys.
  • Root access: SSH connects as the root user using key-based authentication, with no password required.

Frequently Asked Questions

What happens if authorized_keys is missing from the SD-Card?

If /media/mmc/authorized_keys is not found, the S55sshd script exits immediately without starting sshd. The device continues to boot normally, but SSH access remains disabled. This ensures that cameras without configured keys do not expose an open SSH port.

Where does AtomCam store the SSH host keys?

Host keys are generated dynamically on the device’s first boot using ssh-keygen -A and stored in the standard system locations (typically /etc/ssh/). They are not bundled in the firmware zip; instead, they are created by the S55sshd script when it detects that authorized_keys is present and host keys are missing.

Can I add multiple public keys to the authorized_keys file?

Yes. The authorized_keys file supports multiple public keys, one per line. You can append as many keys as needed to target/authorized_keys before building, or concatenate multiple id_rsa.pub files. The S21rootkeys script copies the entire file contents to /root/.ssh/authorized_keys, preserving all entries for sshd to validate.

How do I manually enable SSH if I didn't include the key in the build?

You can manually create the /root/.ssh directory, set permissions to 700, and write your public key to /root/.ssh/authorized_keys with permissions 600. Then run /usr/bin/ssh-keygen -A to generate host keys and /usr/sbin/sshd to start the daemon. This is useful for debugging or recovering a device where the SD-Card keys were not pre-configured.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →