sockeye

Get the CLI from sockeye.sh:

curl -fsSL https://sockeye.sh | sh

Then log in from any machine holding a registered key:

SOCKEYE_URL=https://sockeye.dancroak.com soc login

It signs a challenge with your ssh-agent, stores the week's token, and prints a five-minute link that signs this browser in. Inside a clone of this server, plain soc login does the same. A key registers under /settings#keys once you are in.

No key yet? Ask your operator for a login link. The link lives five minutes.