SSH and FTP: Who Are You Handing Your Server Keys To?

“Send me SSH access” or “give me FTP,” the developer asks, and the business owner forwards some logins from an old email thread, not really understanding what they’re handing over. Meanwhile, this is access to your most valuable asset—the server where your website and customer data live.
In this article from our “IT Made Simple” series, we explain what SSH and FTP are, why they’re needed, and—most importantly—how to grant this access safely without losing control of your own server.
Why You Even Need to “Access” the Server
Your website is a collection of files and programs on a server in a data center (as we covered in previous articles in this series). The server is hundreds of miles away, so you can’t just walk up to it with a flash drive. To update the site, fix a bug, or set up backups, the developer connects to the server remotely—from their own computer, over the internet.
SSH and FTP are two different “entry points” for this kind of connection. Simply put: FTP is the door to the file warehouse, while SSH is the full control panel for the entire server.

FTP: File Transfer
FTP (File Transfer Protocol) is an old and simple way to exchange files with a server. The developer sees the server’s folders just like regular folders on their computer: they can upload new website files, download, or replace old ones. And that’s it—FTP can’t do anything else.
An important detail: classic FTP was created in an era when security wasn’t much of a priority—it even transmits passwords in plain text, making them easy to intercept. That’s why secure versions are used today: SFTP or FTPS (the “S” stands for secure). If your contractor is still using plain FTP in 2026, it’s worth asking why.

SSH: Full Server Control
SSH (Secure Shell) is an encrypted channel for managing a server. By connecting via SSH, a specialist can do more than just copy files—they can execute commands: install and update software, restart the website, check error logs, and set up automated backups.
It looks like a black window with text commands—the classic “hacker console” from the movies. There’s no need to be intimidated: it’s simply a way to talk to the server directly, without buttons or menus. For serious tasks—deploying a website, running diagnostics, configuring security—SSH is indispensable.
Another major plus for SSH is key-based login instead of passwords. A key is a pair of files: the “lock” is placed on the server, and the “key” is kept by the specialist. It’s virtually impossible to guess this key, and revoking a specific person’s access takes just a minute, without having to change a shared password for everyone.

Owner’s Checklist: How to Grant Access Safely
Server access means access to your website, customer database, and often your payment settings. Here are a few rules that will save you a lot of stress:
And the main rule from our previous articles applies here too: “root” access—the hosting panel, domain, and main SSH access—belongs to you. Contractors are given separate accounts that can be revoked without changing anything else.
- Share credentials via a password manager or at least use “disappearing” messages—not in plain text in emails that get stored for years.
- Give each specialist their own account or SSH key. If they leave or finish the project, you can revoke their access in a minute.
- Ask them to use SFTP/SSH instead of plain FTP—it’s just as convenient, but encrypted.
- Keep a simple list of who got access to what and when. A spreadsheet is enough.
- After the collaboration ends, change any passwords the contractor had access to.


Frequently asked questions
The developer is asking for SSH access. Is this normal?
Yes, for serious work (deployment, diagnostics, configuration), this is standard. The right way to do it: you create a separate user for them or add their SSH key—and you can revoke access at any time without affecting anything else.
How is SFTP different from FTP?
SFTP is file transfer over a secure SSH channel: everything is encrypted, and passwords aren’t sent in plain text. From the specialist’s perspective, the workflow looks exactly the same, so there’s practically no reason to choose the old FTP today.
What is a hosting “control panel”—is that SSH too?
No, that’s a third, more “human-friendly” entry point: a web interface with buttons (cPanel, ISPmanager, and others) where you can manage files, email, and databases without using the console. For simple operations, the panel is enough; SSH is needed for more advanced tasks.
Can a website be “hijacked” through stolen credentials?
Yes, this is the most common hacking scenario — not “genius hackers,” but a leaked password from an old email thread. That’s why you need: unique passwords, separate accounts, keys instead of passwords, and access revoked as soon as the work is done.