How to set up and use SSH keys for SSH/SFTP access

SSH keys provide a highly secure and convenient way to log into your hosting server. Instead of relying on a password that can be guessed or intercepted, SSH keys use a cryptographic key pair—a public key (which lives on the server) and a private key (which stays safely on your computer).

Using SSH keys protects your account from brute-force attacks and allows for seamless, passwordless logins for your automated deployment scripts and FTP clients.


  • Step 1: Generate an SSH key pair

    If you do not already have an SSH key, you can generate a modern, highly secure ED25519 key pair directly from your computer’s terminal.

    For macOS and Linux:

    1. Open the Terminal application.
    2. Run the following command:

      ssh-keygen -t ed25519

    3. You will be prompted to choose a file location. Press Enter to accept the default location (~/.ssh/id_ed25519).
    4. You will be asked to enter a passphrase. While optional, entering a passphrase adds an extra layer of encryption to your private key on your local machine.

    For Windows (Windows 10/11):

    1. Open Command Prompt or PowerShell.
    2. Run the exact same command:

      ssh-keygen -t ed25519

    3. Press Enter to accept the default save location (usually C:\Users\YourName\.ssh\id_ed25519).





  • Step 2: Upload your public key to the server

    To authenticate successfully, your server needs a copy of your public key. (Important: Never share or upload your private key.)

    Option A: The Automated Way (Mac / Linux)

    If you are on macOS or Linux, you can automatically create the required directories, set the strict security permissions, and upload your key in a single command.

    Open your terminal and run the following (enter your FTP password when prompted):

    ssh-copy-id -s -p 2222 -i ~/.ssh/id_ed25519.pub [your-ftp-username]@[your-domain.com]

    (If this succeeds, you can skip directly to Step 3. If it fails due to server restrictions, use Option B).

    Option B: The Manual Command Line (Windows / Fallback)


    Windows users, or users whose accounts are restricted strictly to SFTP, will need to create the security folders manually using the interactive SFTP prompt.

    1. Open your terminal, navigate to your hidden ssh folder, and connect to your server (ebter your FTP password when prompted):

      cd ~/.sshsftp -P 2222 [your-ftp-username]@[your-domain.com]

    2. Once connected, your prompt will change to sftp>. Run the following commands one by one exactly as shown below:

      sftp> mkdir .sshsftp> chmod 700 .sshsftp> cd .sshsftp> put id_ed25519.pub authorized_keyssftp> chmod 600 authorized_keyssftp> exit

    Option C: Using FileZilla (Visual Interface)

    If you prefer a visual interface, you can create the directory and upload your key manually using FileZilla:

    1. Connect to your server via SFTP in FileZilla using your current username and password.
    2. In the Remote site window (the right side), right-click on an empty space and select Create directory. Name it exactly .ssh and click OK.
    3. Press Right-click the new .ssh folder and select File permissions…. Enter 700 in the numeric value box and click OK.
    4. Double-click the .ssh folder to enter it.
    5. On your local computer (the left side), locate your public key file (id_ed25519.pub). Right-click it and select Upload.
    6. Once uploaded to the .ssh folder on the server, right-click the file, select Rename, and change its name to exactlyauthorized_keys.
    7. Right-click the authorized_keys file, select File permissions…, enter 600 in the numeric value box, and click OK.





  • Step 3: Connect using your SSH key

    Now that the server knows your public key, you can configure your software to log in using the private key.

    Using a Modern FTP Client (e.g., FileZilla):

    1.  Open FileZilla and go to Edit > Settings (or FileZilla > Settings on macOS).
    2. Under Connection, click on SFTP.
    3. Click Add key file… and select your private key file from your computer (e.g., id_ed25519)
    4. Open the Site Manager and ensure your connection is set to Protocol: SFTP, Port: 2222, and Logon Type: Interactive (or Key file).
    5. Click Connect. The client will now use your key instead of asking for a password.

      Using the Command Line / Deployment Scripts: To connect via the terminal or update your automated scripts, use the -i flag to point to your private key:

      sftp -P 2222 -i ~/.ssh/id_ed25519 [your-ftp-username]@[your-domain.com]