CodeBrowser

SFTP vs SCP: Which Should You Use?

SFTP and SCP both copy files securely over SSH, but they work very differently. Here’s how they compare on features, speed and security, when to use each one, and where rsync fits in, with copy-and-paste commands.

Side-by-side comparisonscp & sftp commandsrsync explainedWindows, Mac & Linux

Short answer

Use SFTP, and keep using the scp command

SFTP is the modern, full-featured protocol. It can list, rename, delete and resume files, and every graphical file transfer app supports it.

The old SCP protocol is outdated, and the OpenSSH developers recommend against it. But the scp command is still fine: since OpenSSH 9.0 (2022), it uses the SFTP protocol behind the scenes. You get the simple scp syntax with SFTP underneath.

Pick the right tool

  • Copy one file quickly: scp
  • Browse, upload and manage files: sftp or an SFTP app
  • Sync folders or back up: rsync
  • Big transfer that might get interrupted: rsync --partial or SFTP’s reput

Compare

SFTP vs SCP at a glance

SFTPSCP (legacy protocol)
Runs overSSH, port 22SSH, port 22
Encryption and loginSame as SSH: passwords or keysSame as SSH: passwords or keys
List and browse remote foldersYesNo
Rename, delete, change permissionsYesNo
Resume interrupted transfersYes (reget, reput)No
Interactive sessionYesNo, one command per copy
Graphical appsWinSCP, FileZilla, Cyberduck, Transmit and moreFew, mostly WinSCP
SpeedFast with modern OpenSSHFast, but no longer faster in practice
StatusActively developed, the standardDeprecated by OpenSSH; scp now uses SFTP

The basics

What are SFTP and SCP?

SFTP (SSH File Transfer Protocol)

A complete file management protocol that runs inside an SSH connection. It works like a remote file system: you can browse folders, upload and download, rename, delete, change permissions and pick up where an interrupted transfer left off.

Despite the name, SFTP has nothing to do with FTP. It’s what apps like WinSCP and FileZilla use when you connect on port 22. See our comparison of the best SFTP clients.

SCP (Secure Copy)

A much older and simpler protocol based on the Unix rcp command. It does one thing: copy files from one place to another over SSH. There’s no browsing and no resume.

Its design made it hard to secure; several vulnerabilities let a malicious server write unexpected files. That’s why OpenSSH switched the scp command to SFTP in version 9.0. Add -O to force the old protocol for very old servers.

scp

scp command examples

The pattern is scp source destination. Remote paths are written as user@server:path.

Upload a file to your home folder

scp report.pdf user@server:~/

Download a file to the current folder

scp user@server:/var/log/app.log .

Copy a whole folder (-r)

scp -r website/ user@server:/var/www/

Use a different port (capital -P)

scp -P 2222 backup.tar.gz user@server:~/

Watch out: scp and sftp use a capital -P for the port, while ssh uses a lowercase -p.

sftp

sftp command examples

Run sftp user@server to open an interactive session, then use these commands at the sftp> prompt:

CommandWhat it does
ls / cdList and change remote folders
lls / lcdList and change local folders
put fileUpload a file (put -r for folders)
get fileDownload a file (get -r for folders)
reput / regetResume an interrupted upload or download
rename, rm, mkdirManage remote files and folders
exitClose the session

Open an SFTP session

sftp user@server

Connect on a custom port

sftp -P 2222 user@server

Run commands from a file (scripts)

sftp -b upload.txt user@server

What about rsync?

rsync: the best choice for syncing

rsync also runs over SSH, but it compares the source and destination and only sends what changed. That makes repeat transfers, backups and deployments dramatically faster than copying everything again with scp or sftp.

It’s built into macOS and Linux. On Windows, run it inside WSL. The server needs rsync installed too.

Sync a folder to a server

rsync -avz site/ user@server:/var/www/site/

Resume-friendly copy with progress

rsync -avz --partial --progress big.iso user@server:~/

FAQ

SFTP and SCP questions, answered

Is SCP deprecated?

The SCP protocol is considered outdated and the OpenSSH project recommends SFTP or rsync instead. The scp command itself is not going away: since OpenSSH 9.0 it transfers files using the SFTP protocol by default.

Is SFTP faster than SCP?

For most transfers they now perform about the same. The old SCP protocol could be slightly quicker for a single large file on high-latency links, but modern OpenSSH versions of sftp send multiple requests at once, which closes the gap.

Are SFTP and SCP equally secure?

Both encrypt everything using SSH. The difference is the protocol design: SCP had flaws that let a malicious server overwrite files on your computer, which is one reason OpenSSH moved scp to SFTP.

Do SFTP and SCP use the same port?

Yes. Both run over SSH, so they use port 22 by default, or whatever port your SSH server listens on.

Is SFTP the same as FTPS?

No. SFTP runs over SSH. FTPS is the older FTP protocol wrapped in TLS encryption, with its own ports and firewall rules. Most Linux servers support SFTP out of the box but need extra software for FTPS.

Can I use scp and sftp on Windows?

Yes. Windows 10 and 11 include both commands as part of the built-in OpenSSH client. Open PowerShell or Windows Terminal and use the same syntax as on Mac or Linux.

Skip the password prompts

scp, sftp and rsync all log in with your SSH key. Create one in seconds, right in your browser.

Open the SSH Key Generator