Cheatsheets / SSH Cheatsheet

SSH Cheatsheet

Connecting, key management, config files, port forwarding, and file transfer with OpenSSH - the commands behind every remote server workflow.

Last verified

OpenSSH ships by default on Linux and macOS, and as an optional Windows feature (Settings > Optional Features > OpenSSH Client) usable from PowerShell with identical syntax.

Connecting

ssh user@host

Opens an interactive shell on a remote host.

ssh -p 2222 user@host

Connects to a non-default SSH port.

ssh user@host "uptime"

Runs a single command on the remote host and returns its output, without an interactive session.

ssh -v user@host

Connects with verbose logging - the first thing to add when a connection is failing.

ssh -o StrictHostKeyChecking=no user@host

Skips the host-key confirmation prompt (use only for throwaway/CI hosts, never for anything you’d notice being MITM’d on).

Key management

ssh-keygen -t ed25519 -C "you@example.com"

Generates a new Ed25519 key pair (the current recommended default over RSA).

ssh-keygen -t rsa -b 4096 -C "you@example.com"

Generates a 4096-bit RSA key pair, for servers that don’t yet support Ed25519.

ssh-copy-id user@host

Copies your public key to a remote host’s ~/.ssh/authorized_keys, enabling passwordless login.

cat ~/.ssh/id_ed25519.pub | ssh user@host "cat >> ~/.ssh/authorized_keys"

Does the same thing manually, for systems without ssh-copy-id (e.g. some minimal Windows setups).

ssh-add ~/.ssh/id_ed25519

Adds a private key to the running SSH agent, so you’re not prompted for its passphrase every connection.

ssh-add -l

Lists keys currently loaded in the SSH agent.

chmod 600 ~/.ssh/id_ed25519

Sets the private key file’s permissions so SSH doesn’t refuse to use it (“permissions are too open”).

Config file (~/.ssh/config)

Host myserver
    HostName 203.0.113.10
    User deploy
    Port 2222
    IdentityFile ~/.ssh/id_ed25519

A config block that lets you run ssh myserver instead of typing the full connection string every time.

Host *
    ServerAliveInterval 60

Applies a setting to every host entry - here, sending a keepalive every 60 seconds to prevent idle disconnects.

ssh -F ~/.ssh/config myserver

Explicitly points SSH at a config file (rarely needed - ~/.ssh/config is read by default).

Port forwarding and tunnels

ssh -L 8080:localhost:80 user@host

Local forward: makes localhost:8080 on your machine reach port 80 on the remote host.

ssh -L 5432:db.internal:5432 user@bastion

Local forward through a bastion/jump host, reaching an internal database that isn’t directly exposed.

ssh -R 9000:localhost:3000 user@host

Remote forward: makes port 9000 on the remote host reach port 3000 on your local machine.

ssh -D 1080 user@host

Opens a local SOCKS proxy on port 1080, tunneling all traffic sent through it via the remote host.

ssh -N -L 8080:localhost:80 user@host

Sets up a forward without opening a shell (-N) - useful when you only want the tunnel, run in the background.

ssh -J bastion user@internal-host

Connects to internal-host by jumping through bastion in a single command (ProxyJump).

File transfer

scp file.txt user@host:/remote/path/

Copies a local file to a remote host.

scp user@host:/remote/file.txt ./

Copies a remote file to the local machine.

scp -r dir/ user@host:/remote/path/

Copies a directory recursively.

rsync -avz src/ user@host:/remote/path/

Syncs a directory to a remote host over SSH, transferring only changed files (-a archive mode, -v verbose, -z compress).

rsync -avz --delete src/ user@host:/remote/path/

Same sync, but also deletes files on the remote that no longer exist locally - use carefully.

sftp user@host

Opens an interactive file-transfer session (put/get/ls/cd commands).

Agent and multiplexing

eval "$(ssh-agent -s)"

Starts an SSH agent for the current shell session, so ssh-add has somewhere to load keys into.

Host *
    ControlMaster auto
    ControlPath ~/.ssh/sockets/%r@%h-%p
    ControlPersist 600

A config block enabling connection multiplexing - reuses one TCP connection for repeated SSH commands to the same host, making subsequent connections near-instant.

ssh -O check user@host

Checks whether a multiplexed master connection to a host is active.