- In GitSync.md, tap Add Repository → Enter URL Manually.
- Paste your remote:
git@git.example.com:team/notes.git(or anhttps://URL). - Pick SSH Private Key auth, paste your OpenSSH private key and passphrase.
- On first connect, compare the SHA-256 host-key fingerprint and tap Trust Host.
- Clone — then pull, commit, and push like any other repo.
Self-hosted Git on iOS, without a Mac
iOS has no system git and no SSH agent your apps can borrow. GitSync.md ships the real thing embedded: libgit2 compiled with libssh2 and OpenSSL, so clone, fetch, pull, commit, and push all run on-device and speak native Git + SSH to your server. Keys and tokens live in the iOS Keychain, scoped per repository.
The result is the same as on your desktop: a real folder with a real .git directory that other tools — including the Obsidian Git plugin — can work with directly.
1. Add the repository by URL
Tap Add Repository on the home screen and choose Enter URL Manually. All of these forms work:
https://git.example.com/team/notes.git— HTTPSgit@git.example.com:team/notes.git— SSH (SCP style)ssh://git@git.example.com:2222/team/notes.git— SSH with a custom port
Works with Gitea, Forgejo, GitLab, Bitbucket, Gogs, plain git daemon remotes, or any host that speaks the Git wire protocol. Set the branch and your author name and email while you are here — they go on every commit.
2. Pick the authentication method
The Authentication section adapts to the URL you entered. For a self-hosted server you will use one of:
Paste an OpenSSH private key — Ed25519, ECDSA, or RSA — with its optional passphrase. The username defaults to git. The key is stored in the iOS Keychain and used from memory at connect time; it never leaves the device.
For HTTPS remotes: your server username plus an access token. On GitLab that is a personal access token with read_repository and write_repository; on Gitea/Forgejo, a generated token or your password.
Public repos can use No Authentication. Each repository stores its own credentials, so you can mix a GitHub account, a GitLab token, and an SSH key side by side.
3. Trust the host key — once
The first time GitSync.md connects to your server over SSH, it stops and shows the server's host-key fingerprint:
SHA256:tQd0O4OktZ/v8GOTYc4VnHCLr+dJd3jEJbKtzqE1dXk
Compare it against what your server actually presents — on a desktop you can run ssh-keyscan git.example.com and check the fingerprint yourself. If it matches, tap Trust Host; GitSync.md pins it per host and port, then automatically retries the clone that prompted it.
This is trust-on-first-use, the same model OpenSSH uses. If the key ever changes, GitSync.md blocks the connection with a loud warning instead of silently continuing — a changed key means either a server migration you should know about or a possible man-in-the-middle.
4. Daily workflow against your own server
- Pull — fetch and fast-forward. If your device and the server have diverged, GitSync.md refuses to guess: you choose merge or pull-with-rebase explicitly.
- Commit & Push — stage, commit, and push. Pushes are verified against the server afterward, so a silently rejected push (permissions, protected branches, hooks) surfaces as a real error instead of fake success.
- Branches, stash, tags, history — create, switch, merge, and delete branches; stash work in progress; create annotated or lightweight tags and push them; browse full commit history with per-commit file changes.
- Git LFS — self-hosted LFS works too, including
lfs.url/.lfsconfigendpoints and LFS-over-SSH viagit-lfs-authenticate.
Need to repoint a repo later? Repository Settings lets you edit the remote URL and swap credentials — the origin remote is updated in place, no re-clone needed.
Troubleshooting
"Trust SSH Host?" appears on every new server
Expected — each host (and port) is trusted independently, once. After you tap Trust Host, the fingerprint is remembered on this device.
"SSH Host Key Changed"
Your server's key no longer matches the pinned fingerprint. If you intentionally rotated the host key, verify the new fingerprint out-of-band before trusting it. If you did not, treat it as a security event.
"The remote rejected the saved SSH key"
The key is valid but lacks access: check that its public half is added to your account's SSH keys on the server, and that the passphrase (if any) is correct.
HTTPS authentication fails
Confirm the token has repository read/write scope for your server (GitLab: read_repository + write_repository) and the username is not empty.
Custom port not honored
SCP-style URLs cannot carry a port — use the full form: ssh://git@git.example.com:2222/team/notes.git.
Recap
Self-hosted Git on iOS is the same workflow as GitHub: add by URL, pick SSH key or HTTPS token auth, trust the host key once, then use real pull, commit, and push. Your server, your keys, your working copy — no middleman.
