Guides

How to Connect to an SFTP Server on Windows (Password or Key File)

A vendor, bank or web host sent you a host, a username, and a password or a key file. What each detail means, how to connect from Windows - with an app or the built-in sftp command - and what the usual error messages are telling you.

· 7 min read · Vlad Fedoniuk

Someone has sent you SFTP access. A vendor wants your files on their server, a bank needs a daily upload, or a web host is giving you access to your site. The message has a host name, a username, and either a password or an attached key file - and nothing about what to do with them on Windows.

This guide covers what each detail means, two ways to connect - an app, or the sftp command Windows already has - and what the usual error messages are telling you.

What the details mean

You were givenWhat it is
Host, such as sftp.example.comThe server's address. Sometimes an IP address instead of a name.
Port22 unless they say otherwise. Some hosts use another, such as 2222 - use exactly what they sent.
UsernameYour account on that server. Not your email address, unless they say so.
PasswordFor password login. Some servers want a key instead, or a key and a password.
A key file: .ppk, .pem, id_rsa or id_ed25519Your private key, for key login. It may have a passphrase of its own.
A fingerprint such as SHA256:...The server's host key fingerprint, so you can check on the first connection that you reached the right server.
A folder such as /incomingWhere you may upload. On many vendor servers it is the only place you can write.
A link such as sftp://user@host:2222/incomingMost of the above in one line. Many apps take it as it is.

One thing the email often leaves out: many vendors accept connections only from addresses they know. If they asked for your IP address, send them your office's public IP before you try.

Connect with an app

A graphical client is the quickest way to see the server and drag files in and out. In FTPie:

  1. Choose Add storage and pick SFTP.
  2. Enter the Host, Port and Username. If you were sent an sftp:// link, paste the whole link into Host and FTPie fills in the port, username, password and folder from it. With Settings > Windows integration > Open ftp:// and sftp:// links in FTPie turned on, clicking the link opens this form already filled in, with the connection tested.
  3. Under Auth Method, choose Password Authentication, Key-Based Authentication, or Dual Authentication if the server wants a key and a password.
  4. For a key, click Select File next to Private Key and pick your key file. Enter its passphrase if it has one.
  5. Optionally set an Initial Directory such as /incoming, then click Test connection.
  6. On the first connection FTPie shows the server's Host Key Information. Compare the fingerprint with the one you were sent, then click Accept.
FTPie's SFTP connection details: host, port, username, and password or SSH key authentication
Host, port and username, then a password, a key file, or both.

SFTP is on FTPie's free plan for personal use, for up to three FTP, FTPS or SFTP servers. For work, FTPie Pro has a free trial.

Key files: .ppk, .pem or OpenSSH?

  • .ppk is PuTTY's format, made by PuTTYgen. There are two versions, 2 and 3.
  • .pem is a PEM key - what AWS gives you for an EC2 server, for example.
  • id_rsa or id_ed25519, with no extension, is an OpenSSH key made by ssh-keygen.
  • Anything ending in .pub is the public half. It belongs on the server; you never load it into a client.

Most tutorials begin by converting one format into another with PuTTYgen. FTPie reads all three as they are, with or without a passphrase, so you can skip that step. When it can't read a file it says why: the passphrase is missing or wrong, the file isn't a private key, or you picked the .pub file.

FTPie's SFTP form set to Key-Based Authentication: host sftp.example.com, user exports, private key id_ed25519 and an optional passphrase
Key-Based Authentication with an OpenSSH key, just as ssh-keygen made it. A .ppk or .pem file goes in the same field.

You still need to convert in one case: Windows' own sftp command can't read .ppk files. Open the key in PuTTYgen and use Conversions > Export OpenSSH key. Going the other way, PuTTYgen's Load followed by Save private key turns a .pem into a .ppk for tools that want one.

Connect with Windows' built-in sftp command

Windows 10 and 11 include the OpenSSH client. In PowerShell or Command Prompt:

sftp -P 22 exports@sftp.example.com

The port takes a capital -P; a lowercase -p means something else in sftp. The first time, sftp shows the server's fingerprint and asks Are you sure you want to continue connecting (yes/no/[fingerprint])? Compare it with the one you were sent, type yes, then enter your password. With a key file instead:

sftp -i C:\Users\you\.ssh\id_ed25519 exports@sftp.example.com

Once you're in, ls lists files, cd changes folder, put uploads, get downloads and bye quits. The SFTP command reference has the rest, and automating FTP and SFTP transfers shows how to turn a daily upload into a scheduled job.

When it won't connect

  • "Permission denied (publickey)" - the server accepts only keys, and the key you offered isn't on it. Check that you loaded the private key, not the .pub, and that whoever runs the server has added your public key.
  • "Permission denied (password)", or an authentication error in an app - the username or password is wrong. Usernames are case-sensitive on most servers.
  • "Connection timed out" - nothing answered. Usually a firewall, a wrong port, or a server that only lets in allow-listed IP addresses.
  • "Connection refused" - the machine answered, but nothing is listening on that port. Check the port number.
  • "Host key verification failed", or a warning that the host key has changed - the server's key no longer matches the one saved on your PC. That can be a rebuilt server or something worse, so check with the server's owner before you accept the new key. For Windows' sftp, ssh-keygen -R sftp.example.com removes the old entry.
  • "Permission denied" when uploading - you are connected but can't write there. Vendor servers often allow uploads into one folder only, such as /incoming.
  • FileZilla's "Could not connect to server" covers most of the above; its message log says which one it is.

Before you email the vendor, three free checks narrow it down: the SFTP connection tester (does the server answer from the internet at all?), the SFTP auth method checker (does it want a password, a key, or both?) and the host key fingerprint viewer (which keys does it present?). A server that only accepts allow-listed addresses will refuse these checks too.

Start Your 30-Day Free Trial

Download FTPie and start your free 30-day trial. Enjoy seamless FTP + cloud integration and keep using the free version afterward.

Download Free Trial
CASA Verified & VirusTotal Scanned
30-day trial · Free version included
Windows 10 & 11
Vlad Fedoniuk

Vlad Fedoniuk

I'm the founder and developer of FTPie, dedicated to creating innovative software solutions that simplify and enhance your digital life. Visit my personal website at fedoni.uk , or connect with me on X (formerly Twitter) , LinkedIn , or via email at vlad@ftpie.com