Theme
Connect with an SFTP client
An SFTP client is a desktop program that shows your remote files beside your local ones. It is the right tool for regular use, large files and whole folders.
The settings, whichever client you use
| Field | Value |
|---|---|
| Protocol | SFTP, sometimes written SFTP over SSH. Not FTP, and not SCP |
| Host | The address you were given, for example company.on.sftp.cloud |
| Port | 22 |
| Username | Your full username, including everything after the @ |
| Password | Yours, an app password you created in the web client, or blank if you use a key |
Use the address you were given for SFTP
If your organization has a branded web address such as files.company.com, that address is for the browser only. SFTP connects to the address your administrator gave you for it, which usually ends in .on.sftp.cloud.
Ask if you are not sure which is which.
The host key prompt
The first time you connect, your client shows an unfamiliar key and asks whether to trust it. This is normal and it happens exactly once.
Before you accept it, compare the fingerprint with the one your administrator published. It is the only way to know you are talking to the right server rather than to somebody in the middle.
If your client shows this prompt again later, on a connection that used to work, stop and ask your administrator. There is a legitimate reason for it, for example a move to a new server, and there is an illegitimate one.
WinSCP, on Windows
- New Session.
- File protocol: SFTP.
- Host name: your address. Port number: 22.
- User name: your full username.
- Password: yours, or leave it blank and set your key under Advanced, then SSH, then Authentication, Private key file.
- Login.
- Compare the host key fingerprint, then accept it.
Save the session so you do not retype it.
Duplicate (right click a remote file) copies it on the server instead of through your machine; the same rules apply as for the command line cp below.
FileZilla
- File, then Site Manager, then New site.
- Protocol: SFTP - SSH File Transfer Protocol.
- Host: your address. Port: 22.
- Logon Type: Normal for a password, or Key file for a key.
- User: your full username.
- Connect, then compare the host key fingerprint and accept it.
Avoid the Quickconnect bar for anything you will do twice; a saved site keeps the settings.
Cyberduck, on macOS and Windows
- Open Connection.
- Choose SFTP (SSH File Transfer Protocol) at the top.
- Server: your address. Port: 22.
- Username: your full username.
- Password, or tick Use Public Key Authentication and pick your key.
- Connect, then compare the fingerprint and accept it.
The command line
With OpenSSH, which ships with macOS, Linux and modern Windows:
sh
sftp -o User=alice@company company.sftp.cloudPassing the username separately avoids the confusion of two @ signs. This also works:
sh
sftp alice@company@company.sftp.cloudThe client splits on the last @, so the username is alice@company and the host is company.on.sftp.cloud.
Inside the session:
ls list the current remote folder
cd reports change folder
put file.csv upload
get file.csv download
mkdir new create a folder
rm file.csv delete
bye disconnectCopying on the server
OpenSSH 9.0 and newer has a cp command that copies a file on the server, without downloading and uploading it:
cp reports/q1.csv archive/q1.csvThe copy runs where the file lives. Between two folders of one storage, or between two storages on the same Connector, the bytes never leave your network; between two Connectors they pass through the Head. There is a size ceiling for these synchronous copies; above it the command is refused, and you copy the file the usual way instead (the reason travels in the status message, which some clients show and the OpenSSH client reports as a plain Failure). The destination is created (and truncated) before the copy starts, so a refused copy leaves an empty file you can delete.
With a key:
sh
sftp -i /path/to/your/private_key -o User=alice@company company.sftp.cloudOr record it once in your OpenSSH client configuration file and forget about it:
Host transfers
HostName company.sftp.cloud
User alice@company
IdentityFile /path/to/your/private_keyThen simply:
sh
sftp transfersWhat you will and will not be able to do
Your administrator decides which folders you see and what you may do in each. Some folders allow uploads and not downloads, or the other way around.
An action you are not allowed simply fails. The client will not tell you why, and neither will the server; your administrator can see the exact reason.
SFTP only
The connection is SFTP and nothing else. There is no shell, no remote command execution, no SCP and no port forwarding, by design. A client that tries to open a shell will report that it could not.
For scripts and scheduled jobs
Use a key, not a password. See Use an SSH key and Automated and scheduled transfers.