How to connect to a server with SSH

Open a secure command line on a remote server from Windows, macOS or Linux, and understand the host key prompt you see the first time.

1–2 minutes
Person working on a laptop at night in a dark room

SSH (Secure Shell) gives you an encrypted command line on another computer. It is how you manage almost every Linux server. You need three things from your host: the server’s IP address, a username (often root, ubuntu or your own), and either a password or an SSH key.

Connect

The ssh command is built into macOS, Linux and Windows 10 and 11. Open Terminal (or PowerShell on Windows) and run:

ssh root@203.0.113.10

Replace root with your username and the address with your server’s. If the server uses a port other than 22:

ssh -p 2222 root@203.0.113.10

The first-time prompt

The first time you connect, SSH shows the server’s fingerprint and asks if you trust it:

The authenticity of host '203.0.113.10' can't be established.
ED25519 key fingerprint is SHA256:Xb3...
Are you sure you want to continue connecting (yes/no/[fingerprint])?

Type yes. SSH saves the fingerprint in ~/.ssh/known_hosts and checks it every time after. If your host shows the fingerprint in its control panel, compare the two first.

Typing the password

When asked for a password, nothing appears as you type, not even dots. That is normal. Type it and press Enter.

When you are in

The prompt changes to something like root@server:~#. Useful first commands:

whoami
hostnamectl
df -h

Type exit or press Ctrl+D to disconnect.

Next steps

Passwords can be guessed. Switch to key-based login next: see how to set up SSH keys.

If it does not connect

MessageUsual cause
Connection timed outWrong IP, or a firewall is blocking port 22
Connection refusedThe server is up but SSH is not running on that port
Permission deniedWrong username, password or key
REMOTE HOST IDENTIFICATION HAS CHANGEDThe server was rebuilt, or something is intercepting the connection

For the last one, confirm with your host that the server was rebuilt, then remove the old entry with ssh-keygen -R 203.0.113.10 and connect again.

Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.