ssh Log in to or run commands on a remote machine
Opens an encrypted connection to another computer and gives you a shell there, or runs a single command and returns. It is the standard way to administer servers. It can also forward network ports through the connection.
Synopsis
ssh [OPTION]... [user@]host [command]
Common options
| Option or form | What it does |
|---|---|
-i FILE | Use FILE as the private key (identity file) to log in |
-p PORT | Connect to PORT instead of the default 22. Lowercase p for ssh, capital P for scp |
-L [bind:]port:host:hostport | Local port forwarding: connections to port on your machine are sent through the tunnel to host:hostport |
-N | Do not run a remote command. Useful with -L when you only want the tunnel |
-v | Verbose mode. Prints debugging messages. Add more v's for more detail |
-J HOST | Jump through HOST (a bastion or jump server) to reach the destination |
-o OPTION | Set a config option on the command line, for example -o ServerAliveInterval=30 |
-f | Go to the background just before running the command. Often combined with -N and -L |
Examples
ssh user@host
ssh -i ~/.ssh/id_ed25519 -p 2222 user@host
ssh user@host 'df -h'
ssh -L 5433:localhost:5432 user@host
ssh -N -f -L 8080:localhost:80 user@host
ssh -J [email protected] [email protected]
Notes
- Without user@ the remote user name defaults to your local one. Write user@host to avoid logging in as the wrong account.
- In -L 5433:localhost:5432, the host part is resolved from the remote machine, so localhost means the server, not your computer. You then connect to localhost:5433 locally.
- The private key file must not be readable by others. If ssh says the permissions are too open, run chmod 600 on the key.
- ssh -p takes the port with lowercase p. scp uses capital -P for the same thing. Mixing them up is a common mistake.
- The first time you connect, ssh asks you to confirm the host key. If it later warns that the host identification has changed, stop and find out why before continuing.
- Put repeated settings (user, port, key) in ~/.ssh/config under a Host name so you can type ssh myserver.
See also
Last reviewed 2026-10-07.