scp and sftp on Linux: Copy Files Securely Over SSH (Upload, Download, Keys)

scp linux copy files - custom-scp-featured.png

scp and sftp ride on SSH: encrypted like your shell session, authenticated with keys or passwords, and available on virtually every Linux server.

Set up keys first with our SSH key guide. For repeated or large syncs, prefer
rsync over SSH after you are comfortable with one-off scp copies.

scp vs sftp vs rsync

scp is quick for single files or trees. sftp is interactive. rsync -e ssh resumes and sends only deltas.

architecturessh-copy.txt
  local files --SSH channel--> remote path (encrypted)
copy tools
scp, sftp, rsync

Upload (Push) to a Server

Syntax is scp local user@host:remote. Use -r for directories and quote paths with spaces.

bashupload
scp ./build/app.tar.gz [email protected]:/var/releases/
scp -r ./config [email protected]:/etc/myapp/
scp push
local to remote

Download (Pull) From a Server

Reverse the order: scp user@host:remote local. -p preserves modification times.

bashdownload
scp -p [email protected]:/var/log/nginx/error.log ./
scp pull
remote to local

SSH Keys and Non-Default Ports

Scripts should use keys, not embedded passwords. -P (capital P) sets the SSH port for scp.

bashcustom port
scp -P 2222 file.txt user@bastion:/tmp/
bashspecific key
scp -i ~/.ssh/deploy_ed25519 file.txt deploy@host:/tmp/
keys and -P
ssh-copy-id

Interactive sftp

Use when you browse remote paths, test uploads, or let non-shell users transfer files (with ForceCommand internal-sftp on the server).

bashsftp
sftp [email protected]
# sftp> put local.txt
# sftp> get remote.log
sftp session
put and get

Large Transfers: rsync Over SSH

For backups and directory sync, rsync compresses and can resume partial transfers.

bashsync
rsync -avz -e ssh /data/ [email protected]:/backups/data/
rsync -e ssh
backups

Verify After Copy

Compare checksums or at least file sizes before deleting the only copy.

bashchecksum both sides
sha256sum app.tar.gz
ssh [email protected] sha256sum /var/releases/app.tar.gz
verify
sha256sum

Quick Reference

  • Push: scp file user@host:/path; pull reverses order
  • -r directories; -P SSH port
  • Big jobs: rsync -avz -e ssh

Related tutorials

Diagrams are original illustrations by Gnome IT Solutions. Tutorial text © Gnome IT Solutions.