SSH Command in Windows with examples
The ssh command explained (Windows)
Everything you need to use ssh on Windows, in plain English: log in, run commands, use keys, save shortcuts, go through jump hosts, forward ports, and fix the errors you will meet.
What the ssh command does
ssh (Secure Shell) opens an encrypted connection from your computer to another computer, usually a server, and gives you a command line on it. Everything you type, and everything the server answers, is scrambled on the way, so nobody on the network can read your password or your commands.
The same connection can also run a single command, carry file transfers (scp, sftp, rsync) and tunnel other network traffic. This page explains each use, one step at a time.
ssh. If Windows says it is not recognised, add OpenSSH Client in Settings, Apps, Optional features.The basic shape
ssh [options] [user@]host [command]- options change how it connects (port, key, tunnels…). The full list is further down.
- user is your login name on the server. If you leave it out, ssh uses your local user name.
- host is the server's name or IP address.
- command is optional. If you give one, ssh runs it and comes back; if not, you get a shell.
Your first login
ssh deploy@203.0.113.10Log in as the user deploy on that address
ssh deploy@web-01.example.comThe same with a name instead of numbers
ssh web-01.example.comUse your local user name as the login name
ssh -l deploy web-01.example.comAnother way to give the user name (-l, a lowercase L)
ssh -p 2222 deploy@web-01.example.comThe server listens on port 2222 instead of the normal 22
You are asked for a password (nothing appears while you type, which is normal) or, if you set up a key, you go straight in. To leave, type exit or press Ctrl+D.
The first-connection question (host keys)
The first time you connect to a server, ssh shows something like this:
The authenticity of host 'web-01.example.com (203.0.113.10)' can't be established. ED25519 key fingerprint is SHA256:Kx3m0yQ4mPq8wZ1nT7vB2cD9eF5gH6jL8aR0sUiYtXo. Are you sure you want to continue connecting (yes/no/[fingerprint])?
This is a safety check. The fingerprint is a short code that identifies that server. Think of it as checking a stranger's name before you hand over a package.
- If you can, compare the fingerprint with the real one. The server's administrator can show it with
ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub(run on the server). - Type
yesif it matches, or if you trust the network and the server is your own. ssh remembers it inC:\Users\you\.ssh\known_hostsand will not ask again. - Type
noif anything looks odd.
ssh-keygen -R web-01.example.comAfter you are sure the server was rebuilt: forget the old fingerprint
ssh-keygen -lf C:\Users\you\.ssh\known_hostsList the fingerprints you have already accepted
Run one command on a server
Put the command after the host. ssh runs it, prints the answer on your screen and returns to your own prompt.
ssh deploy@web-01 "uptime"Run uptime on the server
ssh deploy@web-01 "df -h /"Check free disk space
ssh deploy@web-01 "sudo systemctl status nginx"Check a service
ssh deploy@web-01 "ls /var/log | wc -l"Quotes make the whole command run on the server, pipe included
ssh deploy@web-01 "cat /etc/os-release" > %TEMP%\os.txtSave the server's answer into a file on your own computer
ssh -t deploy@web-01 "sudo nano /etc/hosts"-t gives the command a real terminal, needed for editors and sudo prompts
ssh host ls | wc -l counts on your computer; ssh host "ls | wc -l" counts on the server.Log in with a key instead of a password
A key pair is two files. The private key stays on your computer and must never be shared. The public key is copied to the server. When you connect, ssh proves you hold the private key without sending it. It is safer than a password and lets you skip typing one.
ssh-keygen -t ed25519 -C "me@example.com"Make a key pair. Press Enter to accept the default file name and choose a passphrase
type %USERPROFILE%\.ssh\id_ed25519.pubPrint your PUBLIC key (the one you share)
Windows has no ssh-copy-id. Use this PowerShell line instead; it adds your public key to the server:
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh deploy@web-01 "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"Append your public key on the server
ssh -i %USERPROFILE%\.ssh\id_ed25519 deploy@web-01Use one specific key file
ssh-add %USERPROFILE%\.ssh\id_ed25519Unlock the key once so you do not retype its passphrase
ssh-add -lList the keys your agent holds
If ssh-add says the agent is not running, open PowerShell as administrator and run Set-Service ssh-agent -StartupType Automatic; Start-Service ssh-agent.
Shortcuts: the config file
Typing long commands gets old. Put your servers in the config file, C:\Users\you\.ssh\config, and give each one a short name (an alias).
Host web
HostName 203.0.113.10
User deploy
Port 2222
IdentityFile C:/Users/you/.ssh/id_ed25519
Host *
ServerAliveInterval 30
ServerAliveCountMax 4
Now ssh web does everything the long command did. scp, sftp and rsync understand the same names. The Host * block applies to every server: here, it sends a small keep-alive message every 30 seconds so idle sessions are not dropped by routers.
| Line | Meaning |
|---|---|
Host | The short name you type. Wildcards work: Host *.example.com. |
HostName | The real address or domain. |
User / Port | Login name and port, so you can leave them out. |
IdentityFile | Which private key to use. |
IdentitiesOnly yes | Try only that key (avoids “too many authentication failures”). |
ProxyJump | Go through a jump host (next section). |
LocalForward | A saved port forward (see below). |
ServerAliveInterval | Seconds between keep-alive messages. |
Host name in its Connect box and the address, user, port and jump host fill themselves in.Go through a jump host
Some servers are not reachable from the internet. You first log in to a bastion (or jump host), and it forwards you to the hidden server. With -J you do both steps in one command.
ssh -J jump@bastion.example.com deploy@10.0.0.5Reach 10.0.0.5 through the bastion
ssh -J jump1@a.example.com,jump2@b.example.com deploy@10.0.0.5Two jump hosts in a row
scp -J jump@bastion.example.com file.zip deploy@10.0.0.5:~File copies can jump too
In the config file, the same thing is one line: ProxyJump jump@bastion.example.com under the hidden server's Host block.
Port forwarding (tunnels)
A tunnel carries other network traffic through your SSH connection. There are three kinds. The numbers below are the port that is opened on the side named first.
| Flag | In plain English | Example |
|---|---|---|
-L Local | Open a port on your computer. Anything sent to it goes through the server to a target. | Use a database that only the server can see. |
-R Remote | Open a port on the server that leads back to something on your computer. | Show a site running on your laptop to a colleague. |
-D Dynamic | Make a SOCKS proxy on your computer. Point a browser at it and its traffic leaves from the server. | Browse as if you sat at the server. |
ssh -L 5432:127.0.0.1:5432 deploy@web-01Now connect your database program to 127.0.0.1:5432 on your own computer
ssh -L 8080:intranet.local:80 deploy@web-01Open http://localhost:8080 to reach intranet.local as the server sees it
ssh -R 9000:localhost:3000 deploy@web-01The server's port 9000 now reaches your computer's port 3000
ssh -D 1080 deploy@web-01SOCKS proxy at localhost:1080
ssh -N -L 5432:127.0.0.1:5432 deploy@web-01-N means "no shell, only the tunnel"; leave the window open
ssh -f -N -L 5432:127.0.0.1:5432 deploy@web-01-f sends it to the background after login
0.0.0.0:8080:... would let every computer on your network use your tunnel.Options reference
| Option | What it does | Example |
|---|---|---|
-p port | Connect to a different port. | ssh -p 2222 host |
-l user | Login name (same as user@host). | ssh -l deploy host |
-i file | Use this private key. | ssh -i key.pem host |
-v, -vv, -vvv | Show what ssh is doing; more v means more detail. First thing to try when a login fails. | ssh -v host |
-q | Quiet: hide warnings. | ssh -q host uptime |
-o Name=value | Set any config-file option for this one connection. | ssh -o ServerAliveInterval=30 host |
-F file | Use a different config file. | ssh -F work.conf host |
-J hosts | Go through one or more jump hosts. | ssh -J bastion host |
-L / -R / -D | Local, remote and dynamic port forwarding. | ssh -L 8080:host:80 server |
-N | Do not run a command or open a shell (tunnels only). | ssh -N -L … host |
-f | Go to the background after logging in. | ssh -f -N -L … host |
-t / -T | Force a terminal (needed for editors, sudo prompts) / never use one (scripts). | ssh -t host "sudo nano /etc/hosts" |
-A | Pass your key agent to the server so you can hop on from there. Only use it on servers you trust. | ssh -A host |
-C | Compress the connection (helps on slow links). | ssh -C host |
-4 / -6 | Use only IPv4 / only IPv6. | ssh -4 host |
-X / -Y | Show the server's graphical windows on your screen (X11 forwarding). | ssh -X host xclock |
-g | Let other computers use your forwarded ports (use with care). | ssh -g -L … host |
-V | Print the ssh version. | ssh -V |
Useful -o settings
| Setting | Meaning |
|---|---|
ServerAliveInterval=30 | Send a keep-alive every 30 seconds so the session stays open. |
IdentitiesOnly=yes | Offer only the key you named, not every key in your agent. |
PreferredAuthentications=password | Force password login (to test it). |
ConnectTimeout=10 | Give up after 10 seconds when a server does not answer. |
StrictHostKeyChecking=ask | The safe default. Setting it to no turns off the fingerprint check and is unsafe. |
Escape codes: unstick a frozen session
If a session freezes (for example, the Wi-Fi dropped), typing does nothing. ssh has escape codes that work even then. Press Enter first, then type the keys one after another:
| Keys | What it does |
|---|---|
| ~ then . | Close the connection and return to your own prompt. |
| ~ then ? | List all escape codes. |
| ~ then C | Add a port forward without reconnecting. |
Common errors and fixes
| Message | Meaning | What to do |
|---|---|---|
Permission denied (publickey) | The server did not accept your key, or no key was offered. | Check the user name. Run ssh -v to see which keys were tried. Make sure the public key is in ~/.ssh/authorized_keys on the server and that the private key has strict permissions. |
Permission denied, please try again. | Wrong password or user name. | Retype carefully (Caps Lock?). Confirm that the server allows passwords. |
Connection refused | Nothing is listening on that address and port, or a firewall rejects it. | Check the host and -p port. Ask whether the SSH service is running. |
Connection timed out | The server cannot be reached. | Check your internet, the address and any firewall. You may need a jump host (-J). |
Could not resolve hostname | The name does not exist or is mistyped. | Check the spelling or use the IP address. |
REMOTE HOST IDENTIFICATION HAS CHANGED | The server's fingerprint is not the one you saved. | Ask the administrator. If the server was rebuilt: ssh-keygen -R host, then connect again. |
Too many authentication failures | Your agent offered many keys and the server gave up. | Use -i key -o IdentitiesOnly=yes. |
UNPROTECTED PRIVATE KEY FILE | Others can read your private key, so ssh refuses to use it. | Fix the permissions as described in the keys section. |
Broken pipe / session drops when idle | A router closed an idle connection. | Add ServerAliveInterval 30 to the config file. |
When in doubt, add -v: the last few lines before the failure usually name the cause.
Frequently asked questions
What does the ssh command do?
It opens an encrypted connection to another computer and gives you a command line on it, or runs one command there. It is the standard way to administer Linux servers remotely.
What is the difference between ssh, scp and sftp?
ssh gives you a remote command line. scp and sftp copy files over the same encrypted connection. rsync can also use ssh and copies only what changed.
How do I use ssh with a different port?
Use -p: ssh -p 2222 user@host. For scp, the flag is a capital -P.
Is it safe to type yes at the host-key question?
Only if the fingerprint matches the real one, or you trust the network and the server. The answer is saved, so the question appears only once per server.
Is ssh free?
Yes. OpenSSH is free and open source and is included with Linux, macOS and Windows 10 and 11.
Run these commands with SSH Command
SSH Command is a desktop app for Mac, Windows and Linux that puts a real terminal, SFTP file panes, a sudo switch and a searchable Linux command finder in one window. Type what you want to do, and send the command to your server with one click.
Download free Linux commands with examples SFTP & FTP client