SSH and SFTP
Reveal and rotate your SFTP and SSH credentials, add SSH keys, restrict access by IP, and add extra SFTP accounts with their own folders.
Every environment has one primary SFTP and SSH user. Open your site, then Files, then SFTP/SSH, to see the host, port, and username, reveal the password, add keys, and restrict who can connect. The same details are on the Info tab. Each environment has its own credentials, and the page names the environment they belong to.
Reveal the credentials
- Open your site, then Info.
- Under Primary SFTP and SSH user, choose to show the password.
- Enter your account password again.
Avaloi asks for your account password before it shows a secret, and it hides the secret after a minute. The reveal is session only: it is never stored in your browser. Every reveal is audited and shows on the User activity tab with your name. Copy the password from here, or rotate it.
Rotate the credentials
Choose to rotate the password when you think it leaked or when someone who had it leaves. Avaloi sets a new password through a job. Anything that used the old password stops working until you update it.
Connect
The connection commands for SSH and SFTP are ready to copy. You can also download the FTP client config file and import it into your client.
Add an SSH key
Add your public key to sign in without a password. Remove a key when you no longer use that computer. Each change applies through a job.
SSH settings
Edit the authentication methods and the password expiration. Allow keys only to stop password sign-in, or keep both. Set an expiration so passwords must be rotated.
Restrict by IP
Edit the IP allowlist to limit SSH and SFTP to the addresses you choose, such as your office. When the list is empty, every address can try to connect. The list applies through a job.
Extra SFTP accounts
Additional SFTP users each get one folder. Use them to give a contractor access to one theme folder without the rest of the site.
- Under the SFTP accounts list, add an account.
- Pick the folder it can see.
- Save.
The password shows once in the response when the job ends within a few seconds. After that, reveal it the same way as the primary credentials, with your account password. You can switch SFTP on or off for the accounts, and remove an account you no longer need.
Limits
- A revealed secret hides after a minute.
- Each extra SFTP account sees one folder.
Quick answers
Why does Avaloi ask for my password to show a secret? Every reveal is audited and needs a recent sign-in, so a left-open browser cannot leak credentials.
I rotated the password and my deploy script broke. Update the script with the new password, or switch it to an SSH key.
Can a Site Developer reveal credentials? No. Only a Site Admin can reveal credentials or manage SSH on the site. See Give someone access to one site.
Can an extra SFTP account see the whole site? No. Each account gets one folder.
API
GET /v1/environments/{id}/credentials/sftpPOST /v1/environments/{id}/credentials/rotateGET /v1/environments/{id}/sshPATCH /v1/environments/{id}/sshGET /v1/environments/{id}/ssh/allowed-ipsPUT /v1/environments/{id}/ssh/allowed-ipsGET /v1/environments/{id}/ssh/configPOST /v1/environments/{id}/ssh-keysDELETE /v1/environments/{id}/ssh-keys/{key_id}GET /v1/environments/{id}/sftp-accountsPOST /v1/environments/{id}/sftp-accountsPUT /v1/environments/{id}/sftp-accounts/statusDELETE /v1/sftp-accounts/{id}
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.