How to set up and use SSH keys for SSH/SFTP access
SSH keys provide a highly secure and convenient way to log into your hosting server. Instead of relying on a password that can be guessed or intercepted, SSH keys use a cryptographic key pair—a public key (which lives on the server) and a private key (which stays safely on your computer).
Using SSH keys protects your account from brute-force attacks and allows for seamless, passwordless logins for your automated deployment scripts and FTP clients.
-
Step 1: Generate an SSH key pair
If you do not already have an SSH key, you can generate a modern, highly secure ED25519 key pair directly from your computer’s terminal.
For macOS and Linux:
- Open the Terminal application.
- Run the following command:
ssh-keygen -t ed25519 - You will be prompted to choose a file location. Press Enter to accept the default location (
~/.ssh/id_ed25519). - You will be asked to enter a passphrase. While optional, entering a passphrase adds an extra layer of encryption to your private key on your local machine.
For Windows (Windows 10/11):
- Open Command Prompt or PowerShell.
- Run the exact same command:
ssh-keygen -t ed25519 - Press Enter to accept the default save location (usually
C:\Users\YourName\.ssh\id_ed25519).
-
Step 2: Upload your public key to the server
To authenticate successfully, your server needs a copy of your public key. (Important: Never share or upload your private key.)
Option A: The Automated Way (Mac / Linux)
If you are on macOS or Linux, you can automatically create the required directories, set the strict security permissions, and upload your key in a single command.
Open your terminal and run the following (enter your FTP password when prompted):
ssh-copy-id -s -p 2222 -i ~/.ssh/id_ed25519.pub [your-ftp-username]@[your-domain.com](If this succeeds, you can skip directly to Step 3. If it fails due to server restrictions, use Option B).
Option B: The Manual Command Line (Windows / Fallback)
Windows users, or users whose accounts are restricted strictly to SFTP, will need to create the security folders manually using the interactive SFTP prompt.- Open your terminal, navigate to your hidden ssh folder, and connect to your server (ebter your FTP password when prompted):
cd ~/.sshsftp -P 2222 [your-ftp-username]@[your-domain.com] - Once connected, your prompt will change to
sftp>. Run the following commands one by one exactly as shown below:sftp> mkdir .sshsftp> chmod 700 .sshsftp> cd .sshsftp> put id_ed25519.pub authorized_keyssftp> chmod 600 authorized_keyssftp> exit
Option C: Using FileZilla (Visual Interface)
If you prefer a visual interface, you can create the directory and upload your key manually using FileZilla:
- Connect to your server via SFTP in FileZilla using your current username and password.
- In the Remote site window (the right side), right-click on an empty space and select Create directory. Name it exactly
.sshand click OK. - Press Right-click the new .ssh folder and select File permissions…. Enter 700 in the numeric value box and click OK.
- Double-click the
.sshfolder to enter it. - On your local computer (the left side), locate your public key file (
id_ed25519.pub). Right-click it and select Upload. - Once uploaded to the
.sshfolder on the server, right-click the file, select Rename, and change its name to exactlyauthorized_keys. - Right-click the
authorized_keysfile, select File permissions…, enter 600 in the numeric value box, and click OK.
- Open your terminal, navigate to your hidden ssh folder, and connect to your server (ebter your FTP password when prompted):
-
Step 3: Connect using your SSH key
Now that the server knows your public key, you can configure your software to log in using the private key.
Using a Modern FTP Client (e.g., FileZilla):
- Open FileZilla and go to Edit > Settings (or FileZilla > Settings on macOS).
- Under Connection, click on SFTP.
- Click Add key file… and select your private key file from your computer (e.g.,
id_ed25519) - Open the Site Manager and ensure your connection is set to Protocol: SFTP, Port: 2222, and Logon Type: Interactive (or Key file).
- Click Connect. The client will now use your key instead of asking for a password.
Using the Command Line / Deployment Scripts: To connect via the terminal or update your automated scripts, use the -i flag to point to your private key:
sftp -P 2222 -i ~/.ssh/id_ed25519 [your-ftp-username]@[your-domain.com]





