SFTP (Secure File Transfer Protocol) uses SSH over TCP port 22 to encrypt both commands and file contents in a single channel, making it the standard for secure file transfers in production environments. Unlike FTP, SFTP protects authentication credentials and data in transit, and it works across Windows, Linux, and macOS. Setup involves two parts: configuring the server and connecting a client.
Key Takeaways:
- SFTP runs over SSH on TCP port 22 and encrypts all data in a single channel (FTP uses two separate, unencrypted channels)
- Full SFTP setup has two components: server-side configuration (OpenSSH, user permissions, sshd_config) and client-side connection
- SSH key authentication is the recommended method; password-only authentication is a security risk in production
- Chroot directory jailing restricts SFTP users to a specific directory, preventing unauthorized file system access
- For data pipeline use cases, platforms like Integrate.io handle SFTP connections, encryption, and compliance without manual server management
What is SFTP?
SFTP (Secure File Transfer Protocol) is a network protocol that provides encrypted file transfer over SSH (Secure Shell). It operates over TCP port 22, uses a single channel for both commands and data, and is the standard for secure file transfers in production environments. Unlike FTP (File Transfer Protocol), SFTP encrypts both authentication credentials and file contents, making it the default choice for transferring sensitive business data.
Developed in the late 1990s as a more secure alternative to FTP, SFTP is now the protocol of choice for organizations moving files between systems, feeding data pipelines, and meeting compliance requirements under HIPAA, GDPR, and SOC 2.
Related Reading: SFTP vs. FTP: Understanding the Difference
What Does SFTP Setup Actually Involve?
SFTP setup covers more than installing a client. A complete, production-ready configuration includes both server-side and client-side work.
-
Protocol: SFTP uses SSH, operating over TCP port 22 by default
-
Server-side: Install OpenSSH, create a dedicated SFTP user, configure /etc/ssh/sshd_config, and set directory permissions with chroot jailing
-
Client-side: Install an SFTP client (WinSCP, FileZilla, Cyberduck) or use the built-in sftp command
-
Authentication: SSH key pairs are the recommended method; password authentication alone is not sufficient for production use
-
Data pipeline context: For automated, recurring file transfers into a data warehouse, a data integration platform handles SFTP connections, scheduling, and compliance without manual server management
Key takeaway: Most guides cover only the client side. The server-side configuration, especially sshd_config and chroot setup, is where most security gaps occur.
This section covers server-side SFTP configuration on Ubuntu/Debian. These steps apply to any Linux distribution with minor package manager differences.
Step 1: Install OpenSSH Server
OpenSSH is the standard SSH implementation on Linux. Install it with:
sudo apt update && sudo apt install openssh-server
Verify the service is running:
sudo systemctl status ssh
Step 2: Create a Dedicated SFTP User and Set Directory Permissions
Never use a root or admin account for SFTP transfers. Create a restricted user and set up a controlled upload directory:
sudo adduser sftpuser
sudo mkdir -p /var/sftp/uploads
sudo chown root:root /var/sftp
sudo chmod 755 /var/sftp
sudo chown sftpuser:sftpuser /var/sftp/uploads
The root-owned /var/sftp directory is required for chroot jailing to work correctly. If the chroot directory is owned by the SFTP user, the SSH daemon will refuse the connection.
Step 3: Configure sshd_config for SFTP-Only Access
Open the SSH daemon configuration file:
sudo nano /etc/ssh/sshd_config
Add the following block at the end of the file:
Match User sftpuser
ChrootDirectory /var/sftp
ForceCommand internal-sftp
AllowTcpForwarding no
X11Forwarding no
This configuration does three things:
- Restricts sftpuser to the /var/sftp directory (chroot jail)
- Forces SFTP-only access; the user cannot open a shell session
- Disables TCP and X11 forwarding to reduce the attack surface
Also confirm this line exists in sshd_config (it is present by default on most systems):
Subsystem sftp internal-sftp
Step 4: Restart SSH and Test the Connection
Apply the configuration changes:
sudo systemctl restart ssh
Test the connection from a client machine:
sftp sftpuser@your-server-ip
A successful connection returns an sftp> prompt. Run ls to confirm the user sees only the chroot directory contents.
Key takeaway: The Match User block in sshd_config is the most critical security step. Without it, SFTP users can access the full file system and open shell sessions.
Configuring SFTP on Windows
Configuring SFTP is straightforward on Windows 10, Windows Server 2019, and Windows Server 2022. The steps below cover both server-side and client-side setup.
Step 1: Ensure SSH is Installed
Windows 10 and Windows Server 2019 or later include OpenSSH as an optional feature. If it is not installed, add it through Settings > Apps > Optional Features > Add a Feature > OpenSSH Server. Alternatively, install OpenSSH directly.
Step 2: Open SFTP Port on Windows Firewall
- Open the Control Panel and navigate to Windows Defender Firewall
- Click "Advanced settings" in the left panel
- Select "Inbound Rules," then "New Rule..."
- Create a new inbound rule for TCP port 22, scoped to private networks
Step 3: Choose an SFTP Client
Popular Windows SFTP clients include WinSCP, FileZilla, and Cyberduck. Install your preferred client and connect using the server IP, port 22, and your credentials or SSH key.
Configuring SFTP on macOS and Linux (Client Side)
Step 1: Ensure SSH is Installed
-
macOS: SSH comes preinstalled on all Mac computers
-
Linux (Ubuntu): Install SSH with sudo apt install ssh
Step 2: Open SFTP Port
-
macOS: Go to System Preferences > Security and Privacy > Firewall > Firewall Options and allow SSH connections
-
Linux: Run sudo ufw allow ssh to open port 22
Step 3: Choose an SFTP Client
-
macOS: Cyberduck is a popular choice; Transmit is an excellent Mac-exclusive option
-
macOS and Linux: FileZilla works on both platforms
-
Command line: Use the built-in sftp username@hostname command directly from the terminal
Related Reading: How to Use SFTP to Securely Transfer Files
SSH Key Authentication for SFTP (Recommended)
Password-only authentication is a security liability in production SFTP environments. SSH key pairs eliminate brute-force risk and are the standard for any environment handling sensitive or regulated data.
Step 1: Generate an SSH Key Pair
On the client machine, run:
ssh-keygen -t ed25519 -C "your_email@example.com"
This generates a private key (kept on the client) and a public key (copied to the server). The ed25519 algorithm is preferred over older RSA keys for its security and performance.
Step 2: Copy the Public Key to the Server
ssh-copy-id sftpuser@your-server-ip
This appends your public key to /home/sftpuser/.ssh/authorized_keys on the server. If ssh-copy-id is not available, copy the key manually:
cat ~/.ssh/id_ed25519.pub | ssh sftpuser@your-server-ip "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"
Step 3: Disable Password Authentication
In /etc/ssh/sshd_config, set:
PasswordAuthentication no
Restart SSH:
sudo systemctl restart ssh
Key takeaway: Disabling password authentication and enforcing key-based auth is a core requirement for data security management in any environment handling regulated data. This applies to HIPAA, GDPR, and SOC 2 contexts.
SFTP Setup for Data Pipelines: How Integrate.io Handles It
Manual SFTP server management works for one-off transfers. For recurring, automated data pipelines, it introduces operational overhead, security risk, and maintenance burden. This is where a managed data integration platform changes the equation.
Integrate.io includes a built-in SFTP connector that handles both source and destination connections. You can pull files from an SFTP server into your data warehouse, push processed data back to an SFTP endpoint, or automate SFTP-to-SFTP data integration between systems, all without managing server configuration manually.
What Integrate.io's SFTP connector supports:
- CSV, Excel, JSON, and XML file ingestion from SFTP sources
- Scheduled and event-triggered pipeline runs
-
Handling CSV files over SFTP with automated validation and transformation
- Bidirectional transfers: SFTP as both source and destination
- Full SFTP data integration process visibility through pipeline monitoring and alerting
Security and compliance posture:
- SOC 2 certified, HIPAA compliant, GDPR compliant, CCPA compliant
- All data encrypted in transit and at rest
- Integrate.io acts as a pass-through layer and does not store your data
- Approved by Fortune 100 security teams
For teams evaluating whether SFTP or an API-based approach better fits their pipeline architecture, see SFTP vs. API and the full list of SFTP connectors supported on the platform.
Ready to automate your SFTP workflows? Get in touch with our team of data experts today or start your free 14-day trial of the Integrate.io platform.
Related reading: Allowing Integrate.io access to my data on Secure File Transfer Protocol (SFTP)
Common SFTP Setup Errors and How to Fix Them
Most SFTP connection failures fall into four categories. The table below covers the most common errors and their fixes.
| Error |
Likely Cause |
Fix |
| Connection refused |
Port 22 blocked or SSH not running |
Check firewall rules; run sudo systemctl status ssh to verify the service is active |
| Permission denied (publickey) |
Public key not in authorized_keys |
Run ssh-copy-id or manually append the key; check file permissions on ~/.ssh/authorized_keys (should be 600) |
| Broken pipe or timeout |
Idle timeout in sshd_config |
Add ClientAliveInterval 60 and ClientAliveCountMax 3 to sshd_config |
| Chroot failed |
Wrong directory ownership |
The chroot directory must be owned by root, not the SFTP user; run sudo chown root:root /var/sftp |
| Subsystem request failed |
internal-sftp not configured |
Confirm Subsystem sftp internal-sftp is present in sshd_config |
For teams deciding between SFTP and managed file transfer for higher-volume or more complex workflows, see MFT vs. SFTP.
Next Steps
SFTP is a secure, proven protocol for file transfers. Configured correctly with key-based authentication, chroot jailing, and proper permissions, it handles sensitive data reliably across Windows, Linux, and macOS.
For teams that need SFTP as part of a broader data pipeline, Integrate.io's data pipeline platform connects SFTP sources and destinations to your warehouse without manual server management, with SOC 2, HIPAA, and GDPR compliance built in.
For organizations that prefer a fully managed SFTP server with instant provisioning and compliance certifications, SFTP To Go is worth evaluating.
Frequently Asked Questions
What is SFTP and why is it important for secure file transfers?
SFTP (Secure File Transfer Protocol) is a network protocol that encrypts file transfers using SSH (Secure Shell). It operates over TCP port 22, uses a single channel for both commands and data, and protects both authentication credentials and file contents in transit. SFTP is the standard for transferring sensitive business data and is required for compliance with HIPAA, GDPR, and SOC 2.
What port does SFTP use?
SFTP uses TCP port 22 by default. This is the same port used by SSH. You can change the default port in the sshd_config file on the server by setting Port [number], though changing the port does not replace proper authentication and firewall controls.
What is the difference between SFTP and FTPS?
SFTP uses SSH as its underlying protocol. FTPS uses SSL/TLS layered over the traditional FTP protocol. They are architecturally different: SFTP uses a single connection on port 22, while FTPS uses separate command and data channels and requires additional firewall rules. SFTP is generally simpler to configure and more widely supported in modern data tools.
How do I set up SFTP on a Windows system?
Ensure OpenSSH is installed (it is included with Windows 10 and Windows Server 2019 or later). Open TCP port 22 in Windows Defender Firewall by creating a new inbound rule. Then install an SFTP client such as WinSCP, FileZilla, or Cyberduck and connect using your server credentials or SSH key.
Can I configure SFTP on macOS and Linux?
Yes. On macOS, SSH is preinstalled; allow port 22 through System Preferences > Security and Privacy > Firewall. On Linux (Ubuntu), install SSH with sudo apt install ssh and open the port with sudo ufw allow ssh. After SSH is running, use the built-in sftp command or a client like FileZilla to connect.
How do I test if my SFTP server is working?
Run sftp username@hostname from a terminal. A successful connection returns an sftp> prompt. You can also connect via FileZilla using the server IP, port 22, and your credentials. If the connection fails, run sudo systemctl status ssh on the server to confirm the SSH service is active and check that port 22 is open in your firewall.
Is SFTP secure enough for HIPAA-regulated data?
Yes, when configured correctly. SFTP with SSH key authentication, encrypted transport, chroot directory jailing, and access controls meets the technical safeguard requirements under HIPAA. Integrate.io's SFTP connector is HIPAA-compliant file transfers built in, with SOC 2 certification and encryption in transit and at rest.
What are common SFTP setup problems and how do I fix them?
The most frequent issues are: port 22 blocked by a firewall (check firewall rules and run systemctl status ssh), SSH keys not correctly added to authorized_keys (use ssh-copy-id or check file permissions), and chroot failures caused by incorrect directory ownership (the chroot directory must be owned by root). See the troubleshooting table above for a full breakdown.
The Unified Stack for Modern Data Teams
Get a personalized platform demo & 30-minute Q&A session with a Solution Engineer