Theme
Your first hour
This is the whole setup, once, in order. Follow it top to bottom. Every step links to the page that explains it in more depth, but you do not need those pages to finish this one.
You will finish with a working site, your own storage connected to it, one user account, and a successful file transfer.
What to have ready
- An email address you can receive mail at.
- A phone or computer with an authenticator app such as Google Authenticator, Microsoft Authenticator, 1Password or Bitwarden. Two step sign in is mandatory on SFTP.cloud.
- A credit card. Nothing is charged during the free trial; the card is saved to verify who you are.
- A Windows or Linux machine that can reach your storage and can make outbound connections to the internet. This is where the Storage Connector goes.
- The storage itself: a folder on that machine, a network share, or the credentials for an S3 bucket, an Azure container, a Google Cloud bucket or another SFTP server.
Part 1: your account
Step 1. Create the account
- Go to
https://portal.sftp.cloudand choose New to SFTP.cloud? Create an account. - Enter your organization name, your work email address and a password of at least 12 characters.
- Confirm that the account is for a business or organization and that you are authorized to create it.
- Choose Create account.
- Open the confirmation email and follow the link. Nothing exists until you do.
SFTP.cloud is a service for businesses, so use your organization's email address. Disposable addresses are refused.
Step 2. Set up two step sign in
Straight after the first sign in, the Portal takes you to the authenticator setup and will not let you go anywhere else until it is done.
- Scan the QR code with your authenticator app, or copy the secret and type it in by hand.
- Enter the six digit code the app shows.
- Save the recovery codes. They are shown once and never again. Each one works a single time and is the only way back into your account if you lose your authenticator.
More detail, including passkeys and trusted devices: Secure your sign in.
Part 2: your site
Step 3. Create your first site
The welcome wizard starts on its own after the authenticator step.
- Name. Pick a short name for your site. It becomes the first part of its address, so
acmegives youacme.on.sftp.cloud. Lowercase letters, digits and dashes, 3 to 30 characters, starting and ending with a letter or a digit. - Region. Pick the region closest to the people who will transfer files. This cannot be changed later.
- Domain. Pick which domain your address lives in, if more than one is offered. This cannot be changed later.
- Start. Choose the free trial or pick a plan straight away. The trial applies to your first site only.
- Card. Save a card with Stripe. Nothing is charged during the trial.
- Choose Create my site.
The site is created immediately. If its server still needs provisioning, the page says so; that usually takes a few minutes.
More detail: Create your first site.
Part 3: your storage
Step 4. Get an enrollment code
- Open your site and choose Storage.
- Choose Connect storage.
- The wizard mints a single use enrollment code and shows it once. Copy it now.
If you lose the code, cancel it in the wizard and mint a new one. A code cannot be shown twice.
Step 5. Install the Storage Connector
On the machine that sits next to your storage:
text
1. Download sc-setup-windows-amd64.zip from https://sftp.cloud/downloads
2. Extract it. You get sc-setup.exe and sc-setup.sig; keep both together.
3. Run sc-setup.exe. It installs the Connector, registers the service and
starts it.
4. Choose "Open setup in browser", which takes you to http://localhost:8883sh
# Download sc-setup-linux-amd64.tar.gz from https://sftp.cloud/downloads, then:
tar xzf sc-setup-linux-amd64.tar.gz
sudo ./sc-setup install
# The archive holds sc-setup and its signature sc-setup.sig; keep both in the
# same folder. The Connector is installed at /usr/local/bin/sc-conn, the service
# is registered and started, and the admin console listens on 127.0.0.1:8883.sh
docker run -d --name sc-conn -v sc-conn-data:/data \
--log-opt max-size=50m --log-opt max-file=5 \
docker.io/syncplify/sc-connFor a headless Linux server with no browser, install with sudo ./sc-setup install --access network. The admin console then listens on 0.0.0.0:8883 over HTTPS with a self signed certificate, so you can finish the setup from another machine. Your browser will warn about that certificate once.
Full instructions per platform: Install on Windows, Install on Linux, Install on macOS and FreeBSD, Run in Docker.
Step 6. First run: create the Connector administrator
Open http://localhost:8883 on that machine. The first run wizard has three steps.
- Administrator. Create the first administrator account for this Connector: a username and a password of at least 8 characters. This account is local to this Connector and is separate from your Portal account.
- Secure sign in. Scan the QR code with an authenticator app and confirm with the six digit code. This is mandatory.
- Connect to your site. Leave the portal address as it is and paste the enrollment code from step 4. Choose Connect.
The wizard confirms Connected and shows the site it bound to.
More detail: First run and Enroll to your site.
Step 7. Define what storage the Connector serves
In the Connector's admin console:
- Choose Storage, then Virtual file systems, then create one.
- Give it a Name. This name is what you will see in the Portal later, so make it recognizable, for example
Company files. - Pick a Type and fill in its fields:
- Disk wants a filesystem path such as
/srv/data,C:\Dataor\\server\share. - S3 wants a bucket, a region, an access key ID and a secret.
- Azure wants an account name, a container and either an account key or a SAS token.
- Google Cloud Storage wants a bucket and the service account key JSON.
- SFTP wants a host, a username and a password or private key.
- Disk wants a filesystem path such as
- Leave Encrypt data at rest off for now unless you have read Encryption at rest. The choice is permanent for that virtual file system.
- Save.
More detail: Virtual file systems and Storage backends.
Part 4: your first user
Moving from another product with users already in place? Once your site and storage exist, import them in one pass instead of creating them one by one.
Step 8. Create the user in the Portal
Back in the Portal, on your site:
- Choose Users, then New user.
- Username. Lowercase letters, digits, dots, underscores and hyphens, starting with a letter or a digit. If your site is
acmeand you typealice, the full username isalice@acme, and that is what the user types when they connect. - How they sign in. Set a password, paste one or more SSH public keys, or both.
- Which protocols they may use. Leave everything unchecked to allow all of them.
- Home folders. Leave it on Automatic: the storage you grant in the next step becomes this user's home by itself.
- Choose Create user.
More detail: Create your first user.
Step 9. Grant the user access on the Connector
Creating the user made an account, nothing more. What they may reach, and what they may do there, is the Connector administrator's decision, made on the Connector; the storage granted here also becomes the user's home.
In the Connector's admin console:
- Choose Access, then Users. Your new user is listed there, synced from the Portal.
- Open the user and choose Give access.
- Which folders. Pick the virtual file system you created, using Or just one folder.
- What can they do. Pick a permission level. Full access is read, write, rename and delete.
- Review, then Give access.
Until this step is done, the user's sign in is refused, with a message that says a storage grant is what is missing. The grant reaches sign in within about half a minute.
More detail: Permissions.
Part 5: prove it works
Step 10. Connect
From any machine, with any SFTP client:
sh
sftp alice@acme@acme.sftp.cloudThe username is alice@acme and the host is acme.on.sftp.cloud, which is why the line has two @ signs. Most graphical clients have separate fields for the two, which is easier to read: host acme.on.sftp.cloud, username alice@acme, port 22.
Your client will ask you to accept the server's SSH host key the first time. The fingerprint to compare it against is on your site's Settings, under Advanced.
Then upload a file, list the directory, and download it again.
Clients with screen by screen instructions: Connect with an SFTP client.
Step 11. Try the web client
Open https://acme.on.sftp.cloud in a browser and sign in as alice@acme. You should see the same files.
You are done
What you have now:
- A site on the internet with a real address and a real certificate.
- Your own storage behind it, on hardware you control.
- One user who can transfer files, and permissions you decide.
What to do next
| If you want to | Go to |
|---|---|
| Add the rest of your users | Users |
Use your own domain such as files.yourcompany.com | Site settings |
| Turn off protocols you do not want | Site settings |
| Restrict which countries or networks may connect | Site security |
| Group folders so new users are set up in one click | Folder sets |
| Encrypt your storage at rest | Encryption at rest |
| Pick a plan before the trial ends | Plan and billing |
| Give your colleagues Portal access | Your team and their roles |