# FTP and SFTP

> Transfer files securely with SFTP using the account login or SSH keys, or create extra FTP accounts over TLS, each limited to one folder and an optional quota.

Source: https://zopanel.net/docs/ftp-sftp  
Updated: 2026-10-07

Every hosting account can transfer files with SFTP, using the same username and password as the panel. For developers or designers who should only see one folder, you can add separate FTP accounts on the **FTP / SFTP** page.

## SFTP with the account login

SFTP is always available when the account's package allows it (the package's SFTP option, "Allow chrooted SFTP access").

| Setting | Value |
| --- | --- |
| Protocol | SFTP |
| Host | the server's host name or IP |
| Port | 22 |
| Username | the hosting account name |
| Password | the account's password |

The session is chrooted to the account's home directory: you see your own `domains/`, `backups/` and other folders, and nothing of other accounts. Websites live in `domains/<domain>/public_html` (or the website's document root).

Files uploaded over SFTP belong to the hosting account, so PHP can read them with the right permissions. If an application reports "permission denied" after an upload with another tool, re-upload over SFTP or fix permissions in the File Manager (files 640, folders 750).

Note that **My account → Change password** changes the panel password; ask your provider to change the SFTP password.

### Sign in with an SSH key

Keys are safer than passwords and work with FileZilla, WinSCP, rsync over SFTP and similar tools.

1. Open **My account** and find **SFTP & SSH keys**.
2. Paste your public key, one per line, for example:

   ```text
   ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA… you@laptop
   ```

3. Click **Add key**.
4. Once the key works, turn on **Keys only** to disable password login for this account.

Accepted key types are Ed25519, ECDSA (P-256, P-384, P-521), RSA of at least 2048 bits, and security-key types (`sk-ssh-ed25519@openssh.com`, `sk-ecdsa-sha2-nistp256@openssh.com`).

The card also shows the **Server fingerprints (check on first connection)**. Compare them with what your client displays the first time you connect, to make sure you are talking to your server.

To create a key on your computer:

```bash
ssh-keygen -t ed25519 -C "you@laptop"
cat ~/.ssh/id_ed25519.pub   # paste this line into the panel
sftp alice@server.example.com
```

## FTP accounts

FTP is optional. The administrator installs the FTP server (Pure-FTPd with TLS) with **Install FTP server** on the **FTP / SFTP** page, or from **Components**. The installer opens port 21 and the passive port range 30000-30100 in the firewall.

### Create an FTP account

1. On **FTP / SFTP**, click **New FTP account**.
2. Enter the **Username**. It is always prefixed with the account name, for example `alice_designer`.
3. Enter or generate a **Password** (8 to 128 characters).
4. Choose the **Directory** the account is limited to:
   - `domains/` (all websites);
   - `domains/<domain>` or `domains/<domain>/public_html` for a single website;
   - for Git or app websites, `domains/<domain>/shared` or `domains/<domain>/source`.
5. Set a **Quota (MB)** if you want to limit how much it can store (`0` = unlimited).
6. Click **Create** and copy the login details.

The FTP account cannot leave its directory, and files it uploads belong to the hosting account. The number of FTP accounts is limited by the package (10 by default in new packages). Edit an account to change its password, directory or quota; leave the password empty to keep it.

### Client settings

FTP requires TLS (explicit FTPS); plain-text logins are refused.

| Setting | Value |
| --- | --- |
| Protocol | FTP with explicit TLS (FTPES) |
| Host | the server's host name or IP |
| Port | 21 |
| Transfer mode | Passive (ports 30000-30100) |
| Username | the full FTP login, for example `alice_designer` |

In FileZilla, choose **Require explicit FTP over TLS** as the encryption. FTPS uses the panel's certificate: set **Settings → Panel domain & SSL** so clients see a trusted certificate instead of a warning.

Each client IP may open up to 10 connections, and the server accepts up to 100 FTP connections in total.

## Which one should I use?

| Need | Use |
| --- | --- |
| You manage your own websites | SFTP with your account login, ideally with an SSH key and **Keys only** on. |
| A freelancer needs one website's files | An FTP account limited to `domains/<domain>/public_html`, or add them as a **Member** of the website. |
| An old tool that only speaks FTP | An FTP account, with TLS. |
| Large or many files | SFTP or rsync over SFTP; or upload an archive in the **File Manager** and **Extract** it on the server. |

## Troubleshooting

| Symptom | What to check |
| --- | --- |
| SFTP: "Permission denied" at login | Wrong password, **Keys only** is on, or the package does not include SFTP. |
| FTP: login works but listing hangs | Passive ports 30000-30100 must be open on any firewall between you and the server; use passive mode. |
| FTP: login refused before the password is checked | The client is using plain FTP: switch it to explicit FTP over TLS. |
| Certificate warning in the client | Set a panel domain and issue its certificate in **Settings**. |
