CodeBrowser

How to SSH Into a Server or VPS

A step-by-step guide to remote access using SSH from Windows, Mac or Linux. Connect for the first time, log in as the right user, switch to SSH keys, and lock down password logins, with copy-and-paste commands for every step.

Windows, Mac & LinuxPassword & SSH key loginSecurity basicsTroubleshooting

Before you start

What you need to connect

Your hosting provider shows these details in its dashboard or in the welcome email for your server:

IP address

The server’s public address, like 203.0.113.10, or a domain that points to it.

Username

Often root. Cloud images may use ubuntu, debian or ec2-user.

Password or key

A root password, or an SSH key you added when you created the server.

Port

Usually 22. Only needed if your provider or admin changed it.

Step by step

How to connect to a server with SSH

Open a terminal

Windows 10/11: open PowerShell or Windows Terminal. Mac: open Terminal. Linux: open your terminal app.

Run the ssh command

Type ssh, then the username, an @ and the server address, and press Enter.

Trust the server

The first time, SSH shows the server’s fingerprint and asks if you want to continue. Type yes.

Log in

Enter the password. Nothing appears while you type; that’s normal. You’ll then see the server’s prompt.

Connect as a user

ssh root@203.0.113.10

Use a different port

ssh -p 2222 root@203.0.113.10

Use a specific key

ssh -i ~/.ssh/id_ed25519 deploy@203.0.113.10

To SSH as a different user, change the part before the @, for example ssh deploy@203.0.113.10. When you’re done, type exit or press Ctrl+D to close the connection. Need to connect to a Windows PC instead? See how to SSH into a Windows machine.

SSH keys

Connect to your server using an SSH key

Keys are safer than passwords and you never have to type them. You keep the private key on your computer and put the public key on the server. Create a key pair with ssh-keygen -t ed25519, or in your browser with our SSH Key Generator. Then copy the public key to the server:

macOS and Linux

ssh-copy-id -i ~/.ssh/id_ed25519.pub root@203.0.113.10

Windows PowerShell

type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh root@203.0.113.10 "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"

You’ll be asked for the password one last time. After that, ssh root@203.0.113.10 logs you in with the key. Creating a new VPS? Most providers, including DigitalOcean, Vultr, Hetzner and Linode, let you paste your public key when you create the server, so it’s ready to use from the first login.

Security

Secure SSH on a new server

Do these once, right after your first login. The commands are for Ubuntu and Debian.

  1. Create your own user with admin rights: adduser deploy, then usermod -aG sudo deploy. Copy your key to this user and log in as them from now on.
  2. Turn off password logins. In /etc/ssh/sshd_config, set PasswordAuthentication no and PermitRootLogin no. Also check files in /etc/ssh/sshd_config.d/, since cloud images often turn passwords back on there.
  3. Test and restart. Run sudo sshd -t to check for mistakes, then sudo systemctl restart ssh (the service is called sshd on Red Hat-based systems).
  4. Turn on the firewall without locking yourself out: sudo ufw allow OpenSSH, then sudo ufw enable.

Don’t lock yourself out

Keep your current SSH session open while you change these settings. Open a second terminal and check that you can still log in with your key as your new user. Only close the first session once that works.

If you do get locked out, most providers offer a web-based console in their dashboard that works even when SSH doesn’t.

Save time

Make connecting faster

Tired of typing ssh -i ~/.ssh/id_ed25519 -p 2222 deploy@203.0.113.10? Save it once in your SSH config file and connect with just ssh myserver. Our SSH Config Generator builds the file for you.

Host myserver
    HostName 203.0.113.10
    User deploy
    Port 2222
    IdentityFile ~/.ssh/id_ed25519

Troubleshooting

SSH connection errors and how to fix them

ErrorWhat it usually meansFix
Connection refusedThe server is reachable but nothing is listening on that port.Check the port number and that the SSH service is running on the server.
Connection timed outYour connection never reaches the server.Check the IP address, and that the server and its firewall allow port 22.
Permission denied (publickey)The server didn’t accept any key you offered.Check the username, use -i with the right key, and make sure the public key is in that user’s ~/.ssh/authorized_keys.
REMOTE HOST IDENTIFICATION HAS CHANGEDThe server’s fingerprint changed, often after a reinstall.If you rebuilt the server, run ssh-keygen -R 203.0.113.10 and connect again. If you didn’t, stop and investigate.
Too many authentication failuresSSH tried too many keys before the right one.Add -o IdentitiesOnly=yes -i ~/.ssh/your_key, or set it in your SSH config.

For anything else, run ssh -v user@server. It shows each step of the connection and usually points straight at the problem.

Need a server?

Where to get a VPS to practice on

If you don’t have a server yet, a small Linux VPS is the easiest way to learn SSH. All of these let you add your SSH key when you create the server. For prices, pros and cons, see our comparison of the best VPS hosting.

DigitalOcean

Beginner-friendly cloud servers (Droplets) with a clean dashboard, one-click apps and a huge library of tutorials.

Best for: Beginners and developers

Vultr

Cloud servers in a long list of locations worldwide, with hourly billing and a wide choice of operating systems.

Best for: Picking a location close to your users

Hostinger VPS

KVM servers with plenty of RAM for the price, NVMe storage and a beginner-friendly control panel. The lowest prices need a longer prepaid term.

Best for: More RAM for less money

RackNerd

Budget VPS plans, often with deep discounts on yearly deals. Great for side projects, VPNs and learning.

Best for: The lowest cost per year

FAQ

SSH questions, answered

What is SSH used for?

SSH (Secure Shell) gives you encrypted remote access to another computer’s command line, usually a Linux server. You can run commands, edit files, install software and transfer files as if you were sitting in front of it.

Do I need to install anything to use SSH?

Usually not. Windows 10 and 11, macOS and Linux all include the ssh command. You only need extra software if you want a graphical app, such as PuTTY or Termius.

Why can’t I see my password when I type it?

SSH hides passwords completely, without dots or stars, so nobody can see how long it is. Type it and press Enter.

How do I SSH as a different user?

Put that username before the @ sign, as in ssh deploy@203.0.113.10, or use ssh -l deploy 203.0.113.10. You can also set the user for each server in your SSH config file.

Is it safe to log in as root?

It works, but it is safer to log in as a normal user and use sudo for admin tasks. Once your own user is set up, disable root login over SSH.

What is the default SSH port?

Port 22. Some providers or admins change it to reduce automated login attempts. If so, connect with ssh -p followed by the port number.

Want something nicer than the terminal?

Compare the best SSH apps for Windows, Mac, Linux, iPhone and Android, from free classics to modern clients that sync your servers.

See the best SSH clients