Theme
Protocols and ports
What your users connect to
| Protocol | Port | Notes |
|---|---|---|
| SFTP | 22 | SSH File Transfer Protocol. The default choice |
| FTPES | 21 | FTP upgraded to TLS with AUTH TLS before credentials are sent. Explicit FTPS |
| FTPS | 990 | FTP inside TLS from the first byte. Implicit FTPS |
| HTTPS | 443 | The web client, and share links |
Plain, unencrypted FTP is never offered. A client that connects on port 21 and does not upgrade to TLS is refused.
Which credential opens which protocol:
| Credential | SFTP | FTPS and FTPES | Web client |
|---|---|---|---|
| Account password | Yes | Yes | Yes |
| SSH key | Yes | No | No |
| App password | Yes | Yes | Never |
| Organization sign in | No | No | Yes |
On a site that requires strong sign in, the two password rows are refused on every protocol and the other two remain.
Port 443 is always present and cannot be removed: it also answers the certificate renewal challenge.
Which of these your users may use is set per site on Site settings and per user on Users. A user may use a protocol only if both allow it.
Custom ports are available on dedicated plans, arranged with us, and are not a self service setting.
What your Connector connects to
| From | To | Port | When |
|---|---|---|---|
| Connector | portal.sftp.cloud | 443 | Enrollment, re-enrollment, and renewing the Connector's certificate every few weeks |
| Connector | Your site's server, head-<id>.on.sftp.cloud | 7600 | The permanent control and data link |
| Connector | sc-release.us-ord-10.linodeobjects.com | 443 | The daily update check, and downloading an update you approve |
| Connector | Your storage | whatever it uses | Every file operation |
All outbound. Nothing ever connects inbound to a Connector, and there is no firewall rule to write for it.
The head-<id> name is specific to your site and the Connector prints it: System > Network in the Connector's admin console lists every destination it dials, with a Copy as text button. Write your firewall rule against those names and not against your site address, which is a CNAME to the same server today but names only one server while a site is being moved. See Before you install.
The Connector's own admin console
| Port | Default bind |
|---|---|
| 8883 | 127.0.0.1, this machine only |
Never reachable from the internet by any SFTP.cloud mechanism. If you bind it wider, that is your network to secure. See Settings.
Which address to use
| You are connecting with | Use |
|---|---|
| A browser | Your platform address, or any live custom domain |
| SFTP, FTPS or FTPES | Your platform address only |
SFTP and FTPS work out which site you are on from your username, not from the hostname. A custom domain carries no site information at that layer, so it cannot be used for them.
Your platform address and every custom domain are listed on the site's Overview page, under How your people connect, with the live ports read from the server itself.
Encryption
| Layer | What is offered |
|---|---|
| Key agreement | ML-KEM-768 with X25519, on SFTP, FTPS and HTTPS, on every plan |
| TLS | 1.2 minimum by default; a dedicated plan can require 1.3 |
| SFTP algorithms | A safe baseline by default; a dedicated plan can require post quantum or Curve25519 key agreement and modern AEAD ciphers only |
See Site security.
SSH capabilities
The SSH service is SFTP only.
| SFTP | yes |
| Shell | no |
| Remote command execution | no |
| SCP | no |
| Port forwarding and tunnels | no |
A client that tries to open a shell reports that it could not. This is the design, not a misconfiguration.
Second factors by protocol
| Protocol | Password | SSH key | Authenticator or passkey |
|---|---|---|---|
| SFTP | yes | yes | no |
| FTPS | yes | no | |
| FTPES | yes | no | |
| Web client | yes | yes |
Only the web client can ask for a second factor. On the other three, a password is a single factor on its own.
The strong option on SFTP is an SSH key with the password removed. See Use an SSH key.
The SSH host key
Your site presents one host key, before any username is sent.
- On a shared plan it is the server's key, shared with the other sites on that server.
- On a dedicated plan it is yours alone.
The fingerprint is on Site settings, under Advanced. Publish it to your transfer partners; it is the only way for a client that has never connected before to tell your site from an impostor.
It changes when a site moves to a dedicated server. See Moving to a dedicated server.