If you or your developer work from the command line, we can give your site SSH and SFTP access. You connect as your site’s own user, you land inside your own site, and you log in with a key only. This article covers what you get, how to ask for it, and why we handle keys the way we do.
What you get
-
SSH and SFTP as your site's own user.
Your files, with the same ownership and permissions your website uses, so nothing you upload ends up owned by the wrong account.
-
A walled-off space.
Each account runs inside its own isolated environment (CloudLinux CageFS). From your session you see your own site and nothing else on the server: no other customers' files, no other databases, no server configuration.
-
The tools developers expect.
WP-CLI for managing WordPress from the command line, git for pulling and pushing code, and PHP on the command line.
-
SFTP with the same key.
Any SFTP client (FileZilla, Transmit, Cyberduck, VS Code) works with the key you send us.
-
SSH tunnels.
SSH tunnels work, so a database client on your own machine can connect through the tunnel, and editors that work over SSH (for example VS Code Remote-SSH) connect the same way.
How to request it
-
Create a key
If you do not have a key yet, create one with the commands below. Press Enter to accept the default location, and set a passphrase when asked.
-
Send your public key
Open a support ticket and paste your public key. It is a single line that starts with ssh-ed25519. Never send the private key; it stays on your computer.
-
We switch access on
We install your key and reply with your server name, your username, and the server's fingerprint so you can confirm you are connecting to the right machine the first time.
-
Connect
Your website files are in the httpdocs folder.
macOS or Linux (Terminal)
ssh-keygen -t ed25519 -C "you@example.com"
cat ~/.ssh/id_ed25519.pub
Windows 10 or 11 (PowerShell)
ssh-keygen -t ed25519 -C "you@example.com"
Get-Content $env:USERPROFILE\.ssh\id_ed25519.pub
The second command prints the line to paste into your ticket.
To remove or replace a key, open a ticket. We remove the old key, confirm in the ticket, and install a replacement the same way as the first.
Why we store your keys
On our servers, a hosting account’s home folder is the same folder your website runs from, and your website’s code can write there. If login keys were stored in that folder, a compromised plugin could add a key of its own and turn a website problem into a permanent back door. So we keep SSH keys in a separate store your website cannot write to, and we add and remove them on request.
This is a stricter setup than many hosts use. It exists to protect your site: nothing running on your website can give itself a login.
Availability
SSH and SFTP access is available on servers that have moved to our CloudLinux platform, with the rest of the fleet rolling out this week. If your server is not ready yet when you ask, we will tell you in the ticket and switch you on as soon as it is.
Frequently asked questions
Can my developer have access?
Yes. Each person gets their own key, so each one can be removed on its own. When a contractor finishes, we take out their key and nobody else is affected. Ask each person to send their public key through a ticket on your account, or send them yourself.
Can I use it for deployments?
Yes. git and rsync over SSH both work, so you can deploy from your own machine or from a build service with its own key. If you prefer push-to-deploy from GitHub with no command line at all, see Automatic Git Deployments from GitHub.
Does SSH access change my site’s security?
No. Keys are added only by us, only on request, and your website has no way to grant itself a login. Your session is walled off from other accounts on the server, and password guessing does not work because there are no passwords to guess.
Do I need SSH to manage my site?
No. Most customers never use it. Your control panel, file manager, and WordPress dashboard cover day-to-day work, and our team handles updates, backups, and monitoring for you.
Questions? Contact us at support [at] webops [dot] host or submit a support ticket. Our team is available 9am-5pm, 7 days a week (24/7 for emergencies).