Skip to content

Create a restricted FTP account

Give a file-transfer user access only to the directory they need.

Where Tools → Files → FTP Accounts

Before you start

  • Choose the exact permitted directory and an authorised recipient.
  • Use encrypted transfer supported by your server. FTP, FTPS and SFTP are different protocols; ask support for the correct service and port.

Steps

  1. 1

    Open FTP Accounts. Enter Log In and a strong unique password twice.

  2. 2

    Review any quota shown, then click Create FTP Account only after checking the access scope.

  3. 3

    Find the account in the list and use Configure FTP Client to obtain the correct username and server details.

  4. 4

    Configure the client with the host’s supported encrypted protocol and supplied port. Do not assume an FTP subaccount automatically has SSH/SFTP access.

  5. 5

    Use the row’s management controls to change access or remove it when no longer needed. Read deletion options carefully so removing a login does not also delete website files.

  6. 6

    Inspect Directory carefully. This is the account’s permitted filesystem area, not a website address. Do not grant the whole home directory unless required.

    Check Directory before creating the FTP login.

Check it worked

  • Log in as that FTP user and check that it cannot browse outside the intended directory.
  • Upload and remove a harmless test file only in the authorised test location.