If you want to connect to a Mac from another computer, you need to enable its SSH server. On macOS, that service is controlled by Remote Login. You don’t need to install a separate SSH server.
One distinction helps avoid a common mix-up: the ssh command is a client for connecting out to another machine. Remote Login lets other machines connect in to your Mac.
Turn on Remote Login
On the Mac you want to reach:
- Open Apple menu → System Settings.
- Go to General → Sharing.
- Turn on Remote Login.
- Choose All users or Only these users.
For a personal or team Mac, allowing only the accounts that need access is a sensible starting point. Select Only these users and add the appropriate accounts.
Remote Login also supports SFTP. You don’t need to enable Screen Sharing, Remote Management, or File Sharing just to use SSH. The optional full-disk-access setting is not required for ordinary shell access; leave it off unless you specifically need that access and understand the implications.
Enable it from Terminal
You can also manage Remote Login with systemsetup. Enabling or disabling it requires administrator privileges:
sudo systemsetup -setremotelogin on
Check its current state with:
sudo systemsetup -getremotelogin
To turn off incoming SSH access later:
sudo systemsetup -setremotelogin off
After enabling it from Terminal, use System Settings to review which users are permitted to connect.
Find the Mac’s username and address
On the Mac, open Terminal and run:
whoami
Use the result as the SSH username. It’s the account’s short name, which may differ from the display name on the login screen.
To get the Mac’s local host name, run:
scutil --get LocalHostName
If the result is build-mac, you can usually try build-mac.local from another device on the same network. If that name doesn’t resolve, use the Mac’s current local IP address instead.
From a second device, connect with:
ssh your-username@build-mac.local
Replace both example values with the Mac’s account name and address. The first time you connect, SSH may ask you to confirm the host key. Accept only if you trust that you’ve reached the correct Mac. Then authenticate with the credentials or method configured for the account.
You can test the service locally with ssh your-username@localhost, but that only checks the Mac itself. To confirm another device can reach it, test from that device.
Diagnose common connection errors
Connection refused
The request reached a device, but the SSH connection wasn’t accepted. Check that Remote Login is on and that you’re using the Mac’s current hostname or IP address.
Connection timed out
The Mac may be asleep, unreachable at that address, or blocked by network rules. Try from the same local network, wake the Mac, and verify its current address.
Permission denied
The network connection reached SSH, but authentication failed. Check the short username, confirm the account is allowed under Remote Login, and verify its credentials or authentication setup. Turning Remote Login off and on again usually won’t fix an account or authentication problem.
The .local name doesn’t resolve
Name resolution for local hostnames depends on the network. Try the Mac’s current local IP address and make sure both devices are on the same network.
Local access isn’t public internet access
Turning on Remote Login makes SSH available to permitted users, but it does not automatically make your Mac reachable from the public internet. Network routes, firewall rules, router configuration, and whether the Mac is awake all affect connectivity.
Start by testing on a trusted local network. Making SSH reachable from outside that network requires additional networking configuration and increases the number of systems that can attempt to connect. Limit access to the accounts that need it, use strong credentials or an appropriate key-based setup, and turn Remote Login off when you no longer need incoming access.
I originally published a more detailed version of this guide on the SSHFlow blog.
I'm also building SSHFlow — an SSH client where every server gets its own workspace for terminals, SFTP, code, and databases.
Top comments (0)