How to Connect to Your VPS via SSH
The first thing you do on every new server — connect over SSH from your laptop. This guide walks through key generation, first login, password vs. key authentication, and the small habits that save you from hours of lockouts later.
SSH (Secure Shell) is how every Linux VPS is administered. It opens an encrypted tunnel between your local machine and the server, lets you run commands, copy files, and forward ports. This article gets you from a fresh welcome email to a working session in under ten minutes, the right way the first time.
What you'll need
- Your VPS's public IP address (in the welcome email or client area).
- A username and password (often
rooton a fresh VPS) or an SSH key pair on your laptop. - A terminal: macOS / Linux already has one; on Windows use
Windows Terminalor PuTTY.
1Open a terminal and log in with a password
This is the simplest first connection. Replace your.vps.ip with the IP from your welcome email.
ssh [email protected] # You'll be asked to confirm the host fingerprint (type yes) # Then enter the password from your welcome email
Host fingerprint prompt — this is normal
On every brand-new server, SSH asks you to verify the host key. Type yes and press Enter. Your laptop will remember this server from now on and warn you only if the key changes (which would indicate a man-in-the-middle attempt).
2Generate an SSH key pair on your laptop
Password logins work, but key-based auth is faster, safer, and the only method we recommend for production. A key pair is two files: a private key (id_ed25519) that never leaves your laptop, and a public key (id_ed25519.pub) you copy to the server.
# On your LOCAL machine ssh-keygen -t ed25519 -C "you@laptop" # Press Enter to accept the default path (~/.ssh/id_ed25519) # Set a passphrase if your laptop ever leaves your sight
RSA still exists, but use Ed25519 if you can
Ed25519 keys are shorter, faster, and at least as secure as 4096-bit RSA. If a legacy device demands RSA, generate one with ssh-keygen -t rsa -b 4096 — otherwise stick with Ed25519.
3Copy the public key to your VPS
One command does this end-to-end. It logs in once with the password, appends your public key to ~/.ssh/authorized_keys on the server, and sets the right file permissions so SSH will actually use it.
# Still on your LOCAL machine ssh-copy-id [email protected] # Now try to log in again — no password should be asked this time ssh [email protected]
If ssh-copy-id isn't installed (some minimal Windows setups), the manual equivalent works too:
# Print your public key locally cat ~/.ssh/id_ed25519.pub # Then on the SERVER, paste it into authorized_keys mkdir -p ~/.ssh && chmod 700 ~/.ssh echo "ssh-ed25519 AAAA... you@laptop" >> ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys
4Disable password login (once keys are working)
Now that key auth works, close the password door. A VPS exposed to the public internet receives hundreds of brute-force attempts per hour — turning off password auth makes all of them harmless.
# On the SERVER sudo nano /etc/ssh/sshd_config.d/10-hardening.conf
PasswordAuthentication no KbdInteractiveAuthentication no PubkeyAuthentication yes PermitRootLogin prohibit-password
sudo sshd -t # validate the config sudo systemctl reload ssh # apply (use sshd on RHEL family)
Keep your current session open while you test
Open a second terminal and confirm you can SSH in from there before closing the first session. If the new config has a typo, the first session is your only way back in.
5Use an SSH config file to stop typing the same thing every time
Editing ~/.ssh/config on your laptop lets you connect with ssh prod-web instead of ssh -i ~/.ssh/id_ed25519 [email protected] -p 2222.
Host prod-web
HostName 198.51.100.42
User deploy
Port 22
IdentityFile ~/.ssh/id_ed25519
ServerAliveInterval 60
Host *
AddKeysToAgent yes
UseKeychain yes # macOS only
Now ssh prod-web just works. Add one stanza per server and you have a tidy address book.
Common SSH commands you'll use every day
# Run a single remote command and exit ssh deploy@web01 "df -h /var" # Copy a local file to the server scp ./backup.tar.gz deploy@web01:/tmp/ # Copy a remote file down scp deploy@web01:/etc/nginx/nginx.conf . # Sync a directory (resumes interrupted transfers) rsync -avz --progress ./site/ deploy@web01:/var/www/site/ # Forward a remote port to your laptop (handy for databases) ssh -L 5432:127.0.0.1:5432 deploy@web01
Frequently asked questions
Why does SSH say "Permission denied (publickey)"?
-i to point at it explicitly), the permissions on ~/.ssh or authorized_keys are too open (run chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys on the server), or the line you pasted into authorized_keys got broken across multiple lines. Re-paste as one continuous line.How do I connect from Windows?
ssh user@ip exactly like on Linux. For older Windows, use PuTTY: it loads .ppk keys generated by PuTTYgen and connects through a graphical session manager.Can I keep an SSH session alive when my laptop sleeps?
tmux or screen on the server. Start a tmux session, do your work, detach with Ctrl+B then D, and re-attach later with tmux attach even after a fresh SSH login. Your shell history and running processes survive.What if I lose my SSH key?
~/.ssh/authorized_keys and add a new one. If you've locked yourself out completely, open a ticket from your client area — we can boot your VPS into rescue mode and install a new key for you within the SLA window of your plan.Should I change the SSH port from 22?
Need a VPS to practice on?
Spin up an NVMe VPS in under 60 seconds. Every plan includes rescue mode and snapshots, so you can experiment without fear of locking yourself out.
Deploy a VPS Open a Ticket