# Connecting via SFTP: FileZilla, Cyberduck, and Command Line

Source: https://support.kapsulehost.com/en-nz/sftp-access

SFTP (Secure File Transfer Protocol) gives you direct access to your site's files on the server. This guide covers everything you need to connect successfully, from finding your credentials to troubleshooting errors.

## What SFTP Is and When to Use It

The file manager built into KPanel is convenient for quick edits: renaming a file, viewing a config, or uploading a single asset. SFTP is the right tool when you need more:

- Uploading or downloading large numbers of files at once (migrating a site, bulk-uploading images).
- Transferring large files that would time out in a browser-based upload.
- Working as part of a development workflow where you edit files locally and push changes.
- Using a GUI client that lets you keep a local and remote folder in sync.
- Accessing logs or configuration files that are not exposed through KPanel's file manager.

SFTP encrypts all data in transit, which makes it more secure than plain FTP. KapsuleHost does not offer unencrypted FTP connections.

![The SSH and SFTP connection details for a site in KPanel](https://support.kapsulehost.com/help/screenshots/sftp-access.df4a2e3e.webp)

## Prerequisites

Before you can connect, you need two things in place.

**1. An SSH key added to your site in KPanel.**

SFTP on KapsuleHost uses SSH key authentication. Password authentication is disabled for security. If you have not yet added your SSH public key, follow the [Adding SSH Keys to Your Site](https://support.kapsulehost.com/en-nz/adding-ssh-keys) guide first, then return here.

**2. Your site username.**

Each site on KapsuleHost has a dedicated system user. This is not your KPanel email address. It is a short username tied specifically to that site.

To find it:
1. Log in to KPanel at [kpanel.kapsulehost.com](https://kpanel.kapsulehost.com).
2. Click **Websites** in the left sidebar.
3. Click the site you want to connect to.
4. Go to the **SSH / SFTP** page.
5. Your site username is shown at the top of this tab. It typically looks like `mysite_com` or `myexamplesite_net`.

**Connection details at a glance:**

| Field | Value |
|---|---|
| Host | `cp1-kapsule.kapsulehost.com` |
| Port | `22` |
| Protocol | SFTP (not FTP, not FTPS) |
| Authentication | SSH key only |
| Username | Your site username (from KPanel > Websites > [site] > Settings > SFTP) |

---

## Connecting with FileZilla

FileZilla is a free, cross-platform SFTP client available for Windows, macOS, and Linux. Download it from [filezilla-project.org](https://filezilla-project.org) if you do not already have it.

### Step-by-Step Setup

1. Open FileZilla.
2. Go to **File > Site Manager** (or press `Ctrl+S` on Windows / `Cmd+S` on Mac).
3. Click **Add Website** and give it a name (for example, "My KapsuleHost Site").
4. In the **General** tab, configure the following fields:

   | Field | Value |
   |---|---|
   | Protocol | **SFTP - SSH File Transfer Protocol** |
   | Host | `cp1-kapsule.kapsulehost.com` |
   | Port | `22` |
   | Logon Type | **Key file** |
   | User | Your site username (for example, `mysite_com`) |
   | Key file | Click **Browse** and navigate to your private key file |

5. For the key file, select the private key that corresponds to the public key you added in KPanel. On macOS and Linux, private keys are typically stored in `~/.ssh/` (for example, `~/.ssh/id_ed25519` or `~/.ssh/id_rsa`). On Windows, they are often in `C:\Users\YourName\.ssh\`.

> **Note:** If your private key has a passphrase, FileZilla will prompt you to enter it when you connect. This is normal. The passphrase protects your private key file and is separate from any KapsuleHost password.

6. Click **Connect** to test the connection, or click **OK** to save and connect later.

### Saving and Reconnecting

Once saved in Site Manager, you can reconnect at any time by going to **File > Site Manager** and clicking **Connect**. FileZilla also shows your saved sites in the dropdown on the toolbar for quick access.

> **Tip:** In FileZilla's Site Manager, check the **Always trust this host** checkbox the first time you connect to avoid the host key prompt on future connections.

---

## Connecting with Cyberduck

Cyberduck is a free SFTP client for macOS and Windows. Download it from [cyberduck.io](https://cyberduck.io).

### Step-by-Step Setup

1. Open Cyberduck.
2. Click **Open Connection** (the globe icon in the toolbar).
3. From the protocol dropdown at the top of the dialog, select **SFTP (SSH File Transfer Protocol)**.
4. Fill in the connection fields:

   | Field | Value |
   |---|---|
   | Server | `cp1-kapsule.kapsulehost.com` |
   | Port | `22` |
   | Username | Your site username (for example, `mysite_com`) |
   | Password | Leave blank |
   | SSH Private Key | Click **Choose** and select your private key file |

5. Click **Connect**.

On first connection, Cyberduck will ask you to verify the server's host key fingerprint. Click **Allow** to proceed. If you see this prompt on a subsequent connection with a different fingerprint, do not accept it and contact support, as it may indicate a configuration change.

### Saving as a Bookmark

To save the connection for future use:
1. After connecting successfully, go to **Bookmark > New Bookmark** (or press `Cmd+Shift+B` on Mac).
2. Give the bookmark a name and close the dialog. The bookmark appears in your Cyberduck bookmark list.

---

## Connecting from Terminal (Mac, Linux, or WSL)

If you prefer the command line, the `sftp` command is available on macOS, Linux, and Windows Subsystem for Linux (WSL).

### Basic Connection

```bash
sftp mysite_com@cp1-kapsule.kapsulehost.com
```

Replace `mysite_com` with your actual site username. If your private key is not in the default location (`~/.ssh/id_rsa` or `~/.ssh/id_ed25519`), specify it with the `-i` flag:

```bash
sftp -i ~/.ssh/your_private_key mysite_com@cp1-kapsule.kapsulehost.com
```

On first connection, you will be asked to confirm the server's host fingerprint. Type `yes` and press Enter. This only happens once per key per device.

### Useful SFTP Commands

Once connected, you will see an `sftp>` prompt. Use these commands to navigate and transfer files:

| Command | What It Does |
|---|---|
| `ls` | List files in the current remote directory |
| `lls` | List files in the current local directory |
| `cd [dir]` | Change directory on the remote server |
| `lcd [dir]` | Change directory on your local machine |
| `pwd` | Show current remote directory path |
| `lpwd` | Show current local directory path |
| `get [file]` | Download a file from remote to local |
| `get -r [dir]` | Download a directory recursively |
| `put [file]` | Upload a file from local to remote |
| `put -r [dir]` | Upload a directory recursively |
| `rm [file]` | Delete a file on the remote server |
| `mkdir [dir]` | Create a directory on the remote server |
| `quit` | Close the SFTP connection |

**Example: downloading a file**
```bash
sftp> cd htdocs/wp-content/themes
sftp> get my-theme.zip
```

**Example: uploading a file**
```bash
sftp> lcd ~/Desktop
sftp> cd htdocs/wp-content/uploads
sftp> put my-image.jpg
```

---

## Where Your Files Are

After connecting, you will land in your site user's home directory: `/home/[siteuser]/`.

The directory structure looks like this:

```
/home/mysite_com/
├── htdocs/              ← Your web root (main location for site files)
│   ├── index.php
│   ├── wp-config.php
│   ├── wp-content/
│   │   ├── themes/
│   │   ├── plugins/
│   │   └── uploads/
│   └── ...
├── logs/                ← PHP and access logs
└── tmp/                 ← Temporary files
```

The web root where your WordPress (or other application) lives is `htdocs/`. This is the directory you will spend most of your time in. On some site configurations it may be named `public_html/` instead. If you connect and see `public_html/` rather than `htdocs/`, use that.

> **Note:** You can only access files belonging to your site user. You cannot navigate above `/home/[siteuser]/` or access other customers' directories. This is by design.

---

## Troubleshooting Connection Issues

### "Connection refused"

The connection was actively rejected before it was established.

**Check:** Confirm you are using host `cp1-kapsule.kapsulehost.com` and port `22`. A common mistake is entering port `21` (which is FTP, not SFTP) or a typo in the hostname.

### "Permission denied (publickey)"

The server accepted the connection attempt but rejected your authentication.

**Check each of the following:**
- Your SSH public key is added in **KPanel > Websites > [site] > Settings > SSH Keys**. If it is not listed there, the server has no record of it.
- You have selected the correct private key in FileZilla/Cyberduck, specifically the private key that pairs with the public key you added to KPanel.
- If your key has a passphrase, make sure you are entering it correctly.
- If you have multiple keys, confirm you are not accidentally selecting the wrong one.

### "Host key verification failed"

Your SFTP client has seen a different host key for this hostname before and is warning you of a mismatch.

**On first connection:** You will be asked to accept the fingerprint. This is normal. Click Accept or type `yes`.

**On a subsequent connection with a new fingerprint:** This can indicate a configuration change on the server. Contact support at [support@kapsulehost.com](mailto:support@kapsulehost.com) before accepting, and mention what you saw.

To clear an old host key in the terminal, edit `~/.ssh/known_hosts` and remove the line for `cp1-kapsule.kapsulehost.com`.

### "Could not read from remote repository" or Wrong Directory

You may have used your KPanel email address as the username instead of your site username.

**Check:** The username must be your site username (for example, `mysite_com`), not your email address. Find the correct username in **KPanel > Websites > [site] > Settings > SFTP**.

### Connection Times Out

The connection attempt hangs and then times out without any error.

**Possible causes:**
- Your IP address may be temporarily blocked by KapsuleHost's firewall due to repeated failed login attempts. Contact support at [support@kapsulehost.com](mailto:support@kapsulehost.com) and ask them to check the firewall log.
- A local firewall or VPN on your network may be blocking outbound connections on port 22. Try from a different network (for example, mobile hotspot) to rule this out.

---

## Related Articles

- [Adding SSH Keys to Your Site](https://support.kapsulehost.com/en-nz/adding-ssh-keys)
- [Using the File Manager in KPanel](https://support.kapsulehost.com/en-nz/file-manager)
- [Connecting to Your Database via SSH Tunnel](https://support.kapsulehost.com/en-nz/database-ssh-tunnel)
