Create a restricted FTP account
Give a file-transfer user access only to the directory they need.
Where Tools → Files → FTP Accounts
Before you start
- Choose the exact permitted directory and an authorised recipient.
- Use encrypted transfer supported by your server. FTP, FTPS and SFTP are different protocols; ask support for the correct service and port.
Steps
-
1
Open FTP Accounts. Enter Log In and a strong unique password twice.
-
2
Review any quota shown, then click Create FTP Account only after checking the access scope.
-
3
Find the account in the list and use Configure FTP Client to obtain the correct username and server details.
-
4
Configure the client with the host’s supported encrypted protocol and supplied port. Do not assume an FTP subaccount automatically has SSH/SFTP access.
-
5
Use the row’s management controls to change access or remove it when no longer needed. Read deletion options carefully so removing a login does not also delete website files.
-
6
Inspect Directory carefully. This is the account’s permitted filesystem area, not a website address. Do not grant the whole home directory unless required.
Check Directory before creating the FTP login.
Check it worked
- Log in as that FTP user and check that it cannot browse outside the intended directory.
- Upload and remove a harmless test file only in the authorised test location.