SSH Command in Windows with examples

The ssh command explained (Windows)

Everything you need to use ssh on Windows, in plain English: log in, run commands, use keys, save shortcuts, go through jump hosts, forward ports, and fix the errors you will meet.

What the ssh command does

ssh (Secure Shell) opens an encrypted connection from your computer to another computer, usually a server, and gives you a command line on it. Everything you type, and everything the server answers, is scrambled on the way, so nobody on the network can read your password or your commands.

The same connection can also run a single command, carry file transfers (scp, sftp, rsync) and tunnel other network traffic. This page explains each use, one step at a time.

WindowsWindows 10 and 11 include the OpenSSH client. Open Command Prompt or PowerShell and type ssh. If Windows says it is not recognised, add OpenSSH Client in Settings, Apps, Optional features.

The basic shape

Syntaxssh [options] [user@]host [command]
  • options change how it connects (port, key, tunnels…). The full list is further down.
  • user is your login name on the server. If you leave it out, ssh uses your local user name.
  • host is the server's name or IP address.
  • command is optional. If you give one, ssh runs it and comes back; if not, you get a shell.

Your first login

  • ssh deploy@203.0.113.10

    Log in as the user deploy on that address

  • ssh deploy@web-01.example.com

    The same with a name instead of numbers

  • ssh web-01.example.com

    Use your local user name as the login name

  • ssh -l deploy web-01.example.com

    Another way to give the user name (-l, a lowercase L)

  • ssh -p 2222 deploy@web-01.example.com

    The server listens on port 2222 instead of the normal 22

You are asked for a password (nothing appears while you type, which is normal) or, if you set up a key, you go straight in. To leave, type exit or press Ctrl+D.

The first-connection question (host keys)

The first time you connect to a server, ssh shows something like this:

The authenticity of host 'web-01.example.com (203.0.113.10)' can't be established.
ED25519 key fingerprint is SHA256:Kx3m0yQ4mPq8wZ1nT7vB2cD9eF5gH6jL8aR0sUiYtXo.
Are you sure you want to continue connecting (yes/no/[fingerprint])?

This is a safety check. The fingerprint is a short code that identifies that server. Think of it as checking a stranger's name before you hand over a package.

  • If you can, compare the fingerprint with the real one. The server's administrator can show it with ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub (run on the server).
  • Type yes if it matches, or if you trust the network and the server is your own. ssh remembers it in C:\Users\you\.ssh\known_hosts and will not ask again.
  • Type no if anything looks odd.
CarefulIf the fingerprint changes later, ssh stops with WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED. That means the server was reinstalled, or someone is between you and the server. Do not ignore it: ask the administrator first.
  • ssh-keygen -R web-01.example.com

    After you are sure the server was rebuilt: forget the old fingerprint

  • ssh-keygen -lf C:\Users\you\.ssh\known_hosts

    List the fingerprints you have already accepted

Run one command on a server

Put the command after the host. ssh runs it, prints the answer on your screen and returns to your own prompt.

  • ssh deploy@web-01 "uptime"

    Run uptime on the server

  • ssh deploy@web-01 "df -h /"

    Check free disk space

  • ssh deploy@web-01 "sudo systemctl status nginx"

    Check a service

  • ssh deploy@web-01 "ls /var/log | wc -l"

    Quotes make the whole command run on the server, pipe included

  • ssh deploy@web-01 "cat /etc/os-release" > %TEMP%\os.txt

    Save the server's answer into a file on your own computer

  • ssh -t deploy@web-01 "sudo nano /etc/hosts"

    -t gives the command a real terminal, needed for editors and sudo prompts

QuotesWithout quotes, your own shell reads pipes and wildcards first. ssh host ls | wc -l counts on your computer; ssh host "ls | wc -l" counts on the server.

Log in with a key instead of a password

A key pair is two files. The private key stays on your computer and must never be shared. The public key is copied to the server. When you connect, ssh proves you hold the private key without sending it. It is safer than a password and lets you skip typing one.

  • ssh-keygen -t ed25519 -C "me@example.com"

    Make a key pair. Press Enter to accept the default file name and choose a passphrase

  • type %USERPROFILE%\.ssh\id_ed25519.pub

    Print your PUBLIC key (the one you share)

Windows has no ssh-copy-id. Use this PowerShell line instead; it adds your public key to the server:

  • type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh deploy@web-01 "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"

    Append your public key on the server

  • ssh -i %USERPROFILE%\.ssh\id_ed25519 deploy@web-01

    Use one specific key file

  • ssh-add %USERPROFILE%\.ssh\id_ed25519

    Unlock the key once so you do not retype its passphrase

  • ssh-add -l

    List the keys your agent holds

If ssh-add says the agent is not running, open PowerShell as administrator and run Set-Service ssh-agent -StartupType Automatic; Start-Service ssh-agent.

CarefulOn Windows, if ssh says UNPROTECTED PRIVATE KEY FILE, the key is readable by other accounts. Right-click the file, Properties, Security, and leave only your own user with access. Keep the private key out of backups you share and never paste it into chat.

Shortcuts: the config file

Typing long commands gets old. Put your servers in the config file, C:\Users\you\.ssh\config, and give each one a short name (an alias).

Host web
    HostName 203.0.113.10
    User deploy
    Port 2222
    IdentityFile C:/Users/you/.ssh/id_ed25519

Host *
    ServerAliveInterval 30
    ServerAliveCountMax 4

Now ssh web does everything the long command did. scp, sftp and rsync understand the same names. The Host * block applies to every server: here, it sends a small keep-alive message every 30 seconds so idle sessions are not dropped by routers.

LineMeaning
HostThe short name you type. Wildcards work: Host *.example.com.
HostNameThe real address or domain.
User / PortLogin name and port, so you can leave them out.
IdentityFileWhich private key to use.
IdentitiesOnly yesTry only that key (avoids “too many authentication failures”).
ProxyJumpGo through a jump host (next section).
LocalForwardA saved port forward (see below).
ServerAliveIntervalSeconds between keep-alive messages.
SSH CommandSSH Command reads this file too. Type a Host name in its Connect box and the address, user, port and jump host fill themselves in.

Go through a jump host

Some servers are not reachable from the internet. You first log in to a bastion (or jump host), and it forwards you to the hidden server. With -J you do both steps in one command.

  • ssh -J jump@bastion.example.com deploy@10.0.0.5

    Reach 10.0.0.5 through the bastion

  • ssh -J jump1@a.example.com,jump2@b.example.com deploy@10.0.0.5

    Two jump hosts in a row

  • scp -J jump@bastion.example.com file.zip deploy@10.0.0.5:~

    File copies can jump too

In the config file, the same thing is one line: ProxyJump jump@bastion.example.com under the hidden server's Host block.

Port forwarding (tunnels)

A tunnel carries other network traffic through your SSH connection. There are three kinds. The numbers below are the port that is opened on the side named first.

FlagIn plain EnglishExample
-L LocalOpen a port on your computer. Anything sent to it goes through the server to a target.Use a database that only the server can see.
-R RemoteOpen a port on the server that leads back to something on your computer.Show a site running on your laptop to a colleague.
-D DynamicMake a SOCKS proxy on your computer. Point a browser at it and its traffic leaves from the server.Browse as if you sat at the server.
  • ssh -L 5432:127.0.0.1:5432 deploy@web-01

    Now connect your database program to 127.0.0.1:5432 on your own computer

  • ssh -L 8080:intranet.local:80 deploy@web-01

    Open http://localhost:8080 to reach intranet.local as the server sees it

  • ssh -R 9000:localhost:3000 deploy@web-01

    The server's port 9000 now reaches your computer's port 3000

  • ssh -D 1080 deploy@web-01

    SOCKS proxy at localhost:1080

  • ssh -N -L 5432:127.0.0.1:5432 deploy@web-01

    -N means "no shell, only the tunnel"; leave the window open

  • ssh -f -N -L 5432:127.0.0.1:5432 deploy@web-01

    -f sends it to the background after login

CarefulA tunnel is only as private as the port you open. Keep the default (your computer only). Writing 0.0.0.0:8080:... would let every computer on your network use your tunnel.

Options reference

OptionWhat it doesExample
-p portConnect to a different port.ssh -p 2222 host
-l userLogin name (same as user@host).ssh -l deploy host
-i fileUse this private key.ssh -i key.pem host
-v, -vv, -vvvShow what ssh is doing; more v means more detail. First thing to try when a login fails.ssh -v host
-qQuiet: hide warnings.ssh -q host uptime
-o Name=valueSet any config-file option for this one connection.ssh -o ServerAliveInterval=30 host
-F fileUse a different config file.ssh -F work.conf host
-J hostsGo through one or more jump hosts.ssh -J bastion host
-L / -R / -DLocal, remote and dynamic port forwarding.ssh -L 8080:host:80 server
-NDo not run a command or open a shell (tunnels only).ssh -N -L … host
-fGo to the background after logging in.ssh -f -N -L … host
-t / -TForce a terminal (needed for editors, sudo prompts) / never use one (scripts).ssh -t host "sudo nano /etc/hosts"
-APass your key agent to the server so you can hop on from there. Only use it on servers you trust.ssh -A host
-CCompress the connection (helps on slow links).ssh -C host
-4 / -6Use only IPv4 / only IPv6.ssh -4 host
-X / -YShow the server's graphical windows on your screen (X11 forwarding).ssh -X host xclock
-gLet other computers use your forwarded ports (use with care).ssh -g -L … host
-VPrint the ssh version.ssh -V

Useful -o settings

SettingMeaning
ServerAliveInterval=30Send a keep-alive every 30 seconds so the session stays open.
IdentitiesOnly=yesOffer only the key you named, not every key in your agent.
PreferredAuthentications=passwordForce password login (to test it).
ConnectTimeout=10Give up after 10 seconds when a server does not answer.
StrictHostKeyChecking=askThe safe default. Setting it to no turns off the fingerprint check and is unsafe.

Escape codes: unstick a frozen session

If a session freezes (for example, the Wi-Fi dropped), typing does nothing. ssh has escape codes that work even then. Press Enter first, then type the keys one after another:

KeysWhat it does
~ then .Close the connection and return to your own prompt.
~ then ?List all escape codes.
~ then CAdd a port forward without reconnecting.

Common errors and fixes

MessageMeaningWhat to do
Permission denied (publickey)The server did not accept your key, or no key was offered.Check the user name. Run ssh -v to see which keys were tried. Make sure the public key is in ~/.ssh/authorized_keys on the server and that the private key has strict permissions.
Permission denied, please try again.Wrong password or user name.Retype carefully (Caps Lock?). Confirm that the server allows passwords.
Connection refusedNothing is listening on that address and port, or a firewall rejects it.Check the host and -p port. Ask whether the SSH service is running.
Connection timed outThe server cannot be reached.Check your internet, the address and any firewall. You may need a jump host (-J).
Could not resolve hostnameThe name does not exist or is mistyped.Check the spelling or use the IP address.
REMOTE HOST IDENTIFICATION HAS CHANGEDThe server's fingerprint is not the one you saved.Ask the administrator. If the server was rebuilt: ssh-keygen -R host, then connect again.
Too many authentication failuresYour agent offered many keys and the server gave up.Use -i key -o IdentitiesOnly=yes.
UNPROTECTED PRIVATE KEY FILEOthers can read your private key, so ssh refuses to use it.Fix the permissions as described in the keys section.
Broken pipe / session drops when idleA router closed an idle connection.Add ServerAliveInterval 30 to the config file.

When in doubt, add -v: the last few lines before the failure usually name the cause.

Frequently asked questions

What does the ssh command do?

It opens an encrypted connection to another computer and gives you a command line on it, or runs one command there. It is the standard way to administer Linux servers remotely.

What is the difference between ssh, scp and sftp?

ssh gives you a remote command line. scp and sftp copy files over the same encrypted connection. rsync can also use ssh and copies only what changed.

How do I use ssh with a different port?

Use -p: ssh -p 2222 user@host. For scp, the flag is a capital -P.

Is it safe to type yes at the host-key question?

Only if the fingerprint matches the real one, or you trust the network and the server. The answer is saved, so the question appears only once per server.

Is ssh free?

Yes. OpenSSH is free and open source and is included with Linux, macOS and Windows 10 and 11.

Run these commands with SSH Command

SSH Command is a desktop app for Mac, Windows and Linux that puts a real terminal, SFTP file panes, a sudo switch and a searchable Linux command finder in one window. Type what you want to do, and send the command to your server with one click.

Download free Linux commands with examples SFTP & FTP client