Need to move files to a server without exposing a separate file-transfer service? If the server offers OpenSSH, you may already have what you need: SFTP, a file-transfer protocol that runs over SSH.
The name is easy to misread. SFTP is not FTP with encryption added. It uses SSH’s secure connection for file operations such as listing directories, uploading, downloading, and renaming files.
The useful distinction: SSH carries, SFTP transfers
Think of SSH as the secure connection between your client and a remote machine. That connection can provide an interactive shell, or carry services such as SFTP.
When an SFTP client connects, the SSH server starts an SFTP subsystem to handle file requests. With OpenSSH, that subsystem is commonly available by default, though server configuration can vary. There usually isn’t a separate SFTP daemon or dedicated SFTP port to set up.
That distinction helps when troubleshooting: SSH access and SFTP access are related, but they are not the same operation. A server can allow shell access while its SFTP subsystem is unavailable or configured differently.
Connect and transfer a file
On a system with the OpenSSH client, start a session with:
sftp username@server
Once connected, SFTP gives you a prompt for remote file operations. For example, ls lists remote files, put uploads a local file, and get downloads a remote file. You can use a graphical SFTP client instead; it communicates with the same server-side subsystem.
A typical session might look like this:
sftp> ls
sftp> put report.csv
sftp> get results.csv
These are commands entered at the SFTP prompt, not separate shell commands. For more operations and navigation examples, see the OpenSSH SFTP command reference.
SFTP transfers the file contents without changing their format. A CSV stays a CSV; an archive stays an archive. SFTP is a protocol for transferring and managing files, not a file format or conversion tool.
Which port does SFTP use?
SFTP normally connects through TCP port 22 because it runs over SSH. It does not have a separate port of its own. If the SSH server listens on a custom port, your SFTP client must connect to that port as well.
This matters when a connection fails: checking only whether “SFTP port” is open can send you looking for a nonexistent separate service. Check the SSH server’s listening port and the network path to that port. The details of SFTP’s default port and custom-port connections are useful when a client and server disagree about where to connect.
SFTP, SCP, FTP, and FTPS are not interchangeable names
| Protocol | What it is | Typical use |
|---|---|---|
| SSH | A secure connection protocol that can provide remote shell access and carry services | Logging in to a remote machine |
| SFTP | A file-transfer and management protocol that runs as an SSH subsystem | Browsing, uploading, downloading, and managing remote files |
| SCP | A file-copy command; in modern OpenSSH, scp uses SFTP by default |
Copying files with a command-line workflow |
| FTP | A separate file-transfer protocol, typically unencrypted | Legacy systems |
| FTPS | FTP protected using TLS, rather than SFTP’s SSH connection | Systems built around FTP with TLS |
The shared letters in SFTP and FTP can make them sound like variations of one protocol. They are not: SFTP does not use FTP’s commands or connection model. FTPS is also distinct from SFTP; it adds TLS to FTP rather than running file operations through SSH.
One small source of confusion: references to port 115 may describe an older, unrelated protocol called Simple File Transfer Protocol. That is not the SSH-based SFTP used for secure transfers today.
What security does SFTP provide?
SFTP traffic is protected by SSH’s encrypted transport and uses SSH authentication, such as a password or public key. The client can also verify the server using its SSH host key. You don’t configure a separate SFTP encryption or authentication system.
Encryption protects traffic in transit, but it doesn’t grant permission to access every remote file. The account still needs appropriate access on the server. If a login works but an upload or directory operation fails, check the account’s permissions and the server’s SFTP configuration rather than assuming the transfer protocol is unencrypted.
For a new setup, SFTP is often available through an existing OpenSSH server. If you need to restrict an account to file transfers or configure the server-side subsystem, those are SSH server configuration choices—not a reason to install a standalone SFTP service by default.
The practical summary: connect with an SFTP client to the server’s SSH port, authenticate as you would with SSH, and use SFTP commands or a file browser to manage remote files. SSH provides the secure connection; SFTP provides the file operations.
I originally published a more detailed version of this guide on the SSHFlow blog.
I'm also building SSHFlow — an SSH client where every server gets its own workspace for terminals, SFTP, code, and databases.
Top comments (0)