SFTP
SSH File Transfer Protocol
- Pronunciation
- es-ef-tee-PEE
In short
SFTP (SSH File Transfer Protocol) is a protocol for securely uploading, downloading and managing files on a remote server over an encrypted SSH connection.
What is SFTP?
SFTP, the SSH File Transfer Protocol, moves files between computers inside an SSH connection, so logins, commands and file contents are all encrypted. It is often expanded as Secure File Transfer Protocol, but the official name refers to SSH. It runs as a subsystem of SSH on the same TCP port, 22, and uses the same logins: a password or, preferably, an SSH key.
Besides uploads and downloads, SFTP can list directories, rename, move and delete files, change permissions and resume interrupted transfers, so it works like a remote file system. The protocol was designed by an IETF working group but never finished as an RFC; nearly every implementation, including OpenSSH, uses version 3, described in a draft from 2001. Common clients include the sftp command, FileZilla and WinSCP, and libraries exist for every major language.
SFTP is a standard way for companies to exchange files in bulk: banks, payroll providers and retailers drop CSV and XML files on each other's SFTP servers every night. It's like a secure mailroom where every visitor shows ID at the door and every package travels in a locked case. Administrators often restrict SFTP-only users to a single folder with no shell access, and cloud providers offer managed SFTP servers that store the files in object storage.
SFTP is often confused with FTPS and with FTP itself. FTP, the original File Transfer Protocol, sends passwords and data in plain text over separate control and data connections, and FTPS is that same FTP encrypted with TLS and certificates. SFTP is not FTP at all, but a different protocol built on SSH that uses a single connection. It also differs from scp, which only copies files, although since OpenSSH 9.0 in 2022, the scp command uses the SFTP protocol under the hood.
Key takeaways
- SFTP transfers and manages files over an encrypted SSH connection.
- It uses SSH's port
22and SSH logins, including key-based authentication. - It can list, rename, delete and resume, not only upload and download.
- FTPS is FTP over TLS; SFTP is a separate protocol built on SSH.
- It is widely used for automated file exchange between companies.
Example
# Open a session with the same login and keys as SSH (port 22)
sftp deploy@files.example.com
sftp> ls /incoming # list a remote folder
sftp> put report.csv /incoming/ # upload
sftp> get /outgoing/invoice.pdf # download
sftp> rename /incoming/report.csv /incoming/report-2026-10.csv
sftp> bye
# Automated: run commands from a file, e.g. in a nightly cron job
sftp -b upload-batch.txt deploy@files.example.comReaders ask
What is the difference between SFTP and FTPS?
FTPS is the old FTP protocol wrapped in TLS encryption, with certificates and separate connections for commands and data. SFTP is a different protocol that runs inside SSH over a single connection and uses SSH keys or passwords.
What port does SFTP use?
SFTP uses the SSH port, TCP 22, by default, because it runs inside an SSH connection. Plain FTP uses port 21, and FTPS uses 21 or 990.
Is SFTP the same as SCP?
Both copy files over SSH, but scp only copies, while SFTP can also list, rename, delete and resume. Since OpenSSH 9.0, the scp command itself uses the SFTP protocol by default.
See also
- SSHNetworking, p. 30SSH is a cryptographic network protocol for securely logging in to and running commands on remote computers, encrypting all traffic between the two machines.
- TLSSecurity, p. 52TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- Public-Key CryptographySecurity, p. 36Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
- PortNetworking, p. 23A port is a number from 0 to 65535 that identifies a specific program or service on a device, so traffic reaching an IP address gets to the right application.
- File PermissionsOperating Systems, p. 11File permissions are rules stored with each file that decide which users may read it, change it, or run it, enforced by the operating system on every access.
- EncryptionSecurity, p. 15Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
Sources
Spotted a mistake or something missing on this page?Suggest an edit