How to SSH Into a Server or VPS
A step-by-step guide to remote access using SSH from Windows, Mac or Linux. Connect for the first time, log in as the right user, switch to SSH keys, and lock down password logins, with copy-and-paste commands for every step.
Windows, Mac & LinuxPassword & SSH key loginSecurity basicsTroubleshooting
Before you start
What you need to connect
Your hosting provider shows these details in its dashboard or in the welcome email for your server:
IP address
The server’s public address, like 203.0.113.10, or a domain that points to it.
Username
Often root. Cloud images may use ubuntu, debian or ec2-user.
Password or key
A root password, or an SSH key you added when you created the server.
Port
Usually 22. Only needed if your provider or admin changed it.
Step by step
How to connect to a server with SSH
Open a terminal
Windows 10/11: open PowerShell or Windows Terminal. Mac: open Terminal. Linux: open your terminal app.
Run the ssh command
Type ssh, then the username, an @ and the server address, and press Enter.
Trust the server
The first time, SSH shows the server’s fingerprint and asks if you want to continue. Type yes.
Log in
Enter the password. Nothing appears while you type; that’s normal. You’ll then see the server’s prompt.
Connect as a user
ssh root@203.0.113.10
Use a different port
ssh -p 2222 root@203.0.113.10
Use a specific key
ssh -i ~/.ssh/id_ed25519 deploy@203.0.113.10
To SSH as a different user, change the part before the @, for example ssh deploy@203.0.113.10. When you’re done, type exit or press Ctrl+D to close the connection. Need to connect to a Windows PC instead? See how to SSH into a Windows machine.
SSH keys
Connect to your server using an SSH key
Keys are safer than passwords and you never have to type them. You keep the private key on your computer and put the public key on the server. Create a key pair with ssh-keygen -t ed25519, or in your browser with our SSH Key Generator. Then copy the public key to the server:
macOS and Linux
ssh-copy-id -i ~/.ssh/id_ed25519.pub root@203.0.113.10
Windows PowerShell
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh root@203.0.113.10 "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"
You’ll be asked for the password one last time. After that, ssh root@203.0.113.10 logs you in with the key. Creating a new VPS? Most providers, including DigitalOcean, Vultr, Hetzner and Linode, let you paste your public key when you create the server, so it’s ready to use from the first login.
Security
Secure SSH on a new server
Do these once, right after your first login. The commands are for Ubuntu and Debian.
- Create your own user with admin rights:
adduser deploy, thenusermod -aG sudo deploy. Copy your key to this user and log in as them from now on. - Turn off password logins. In
/etc/ssh/sshd_config, setPasswordAuthentication noandPermitRootLogin no. Also check files in/etc/ssh/sshd_config.d/, since cloud images often turn passwords back on there. - Test and restart. Run
sudo sshd -tto check for mistakes, thensudo systemctl restart ssh(the service is calledsshdon Red Hat-based systems). - Turn on the firewall without locking yourself out:
sudo ufw allow OpenSSH, thensudo ufw enable.
Don’t lock yourself out
Keep your current SSH session open while you change these settings. Open a second terminal and check that you can still log in with your key as your new user. Only close the first session once that works.
If you do get locked out, most providers offer a web-based console in their dashboard that works even when SSH doesn’t.
Save time
Make connecting faster
Tired of typing ssh -i ~/.ssh/id_ed25519 -p 2222 deploy@203.0.113.10? Save it once in your SSH config file and connect with just ssh myserver. Our SSH Config Generator builds the file for you.
Host myserver
HostName 203.0.113.10
User deploy
Port 2222
IdentityFile ~/.ssh/id_ed25519
Troubleshooting
SSH connection errors and how to fix them
| Error | What it usually means | Fix |
|---|---|---|
Connection refused | The server is reachable but nothing is listening on that port. | Check the port number and that the SSH service is running on the server. |
Connection timed out | Your connection never reaches the server. | Check the IP address, and that the server and its firewall allow port 22. |
Permission denied (publickey) | The server didn’t accept any key you offered. | Check the username, use -i with the right key, and make sure the public key is in that user’s ~/.ssh/authorized_keys. |
REMOTE HOST IDENTIFICATION HAS CHANGED | The server’s fingerprint changed, often after a reinstall. | If you rebuilt the server, run ssh-keygen -R 203.0.113.10 and connect again. If you didn’t, stop and investigate. |
Too many authentication failures | SSH tried too many keys before the right one. | Add -o IdentitiesOnly=yes -i ~/.ssh/your_key, or set it in your SSH config. |
For anything else, run ssh -v user@server. It shows each step of the connection and usually points straight at the problem.
Need a server?
Where to get a VPS to practice on
If you don’t have a server yet, a small Linux VPS is the easiest way to learn SSH. All of these let you add your SSH key when you create the server. For prices, pros and cons, see our comparison of the best VPS hosting.
DigitalOcean
Beginner-friendly cloud servers (Droplets) with a clean dashboard, one-click apps and a huge library of tutorials.
Best for: Beginners and developers
Vultr
Cloud servers in a long list of locations worldwide, with hourly billing and a wide choice of operating systems.
Best for: Picking a location close to your users
Hostinger VPS
KVM servers with plenty of RAM for the price, NVMe storage and a beginner-friendly control panel. The lowest prices need a longer prepaid term.
Best for: More RAM for less money
RackNerd
Budget VPS plans, often with deep discounts on yearly deals. Great for side projects, VPNs and learning.
Best for: The lowest cost per year
FAQ
SSH questions, answered
What is SSH used for?
SSH (Secure Shell) gives you encrypted remote access to another computer’s command line, usually a Linux server. You can run commands, edit files, install software and transfer files as if you were sitting in front of it.
Do I need to install anything to use SSH?
Usually not. Windows 10 and 11, macOS and Linux all include the ssh command. You only need extra software if you want a graphical app, such as PuTTY or Termius.
Why can’t I see my password when I type it?
SSH hides passwords completely, without dots or stars, so nobody can see how long it is. Type it and press Enter.
How do I SSH as a different user?
Put that username before the @ sign, as in ssh deploy@203.0.113.10, or use ssh -l deploy 203.0.113.10. You can also set the user for each server in your SSH config file.
Is it safe to log in as root?
It works, but it is safer to log in as a normal user and use sudo for admin tasks. Once your own user is set up, disable root login over SSH.
What is the default SSH port?
Port 22. Some providers or admins change it to reduce automated login attempts. If so, connect with ssh -p followed by the port number.
Want something nicer than the terminal?
Compare the best SSH apps for Windows, Mac, Linux, iPhone and Android, from free classics to modern clients that sync your servers.