You connect to a VPS over SSH: open a terminal, run ssh root@YOUR_SERVER_IP, confirm the server’s fingerprint the first time, and type the password your provider gave you. Windows 10 and 11, macOS and Linux ship the OpenSSH client that does this, and Android and iPhone have SSH apps for the same job.
Below is how to connect to a VPS from each device, switch to an Ed25519 key, save a one-word alias and fix the exact errors that block a login, plus the VNC console route for when SSH itself is broken. Server commands target Ubuntu 24.04 LTS, with Debian 12 and 13 differences noted.
Key takeaways
- Windows 10 and 11, macOS and Linux all connect with the same command, ssh root@IP; PuTTY and phone apps are optional extras.
- Switch to an Ed25519 key on day one: ssh-keygen -t ed25519, then ssh-copy-id on macOS or Linux, or a one-line PowerShell pipe on Windows, which has no ssh-copy-id.
- The last line of an error names the failed stage: timed out means network or firewall, refused means nothing listens on that port, REMOTE HOST IDENTIFICATION HAS CHANGED means a new host key, Permission denied means the login itself.
- After an OS reinstall or when a deleted server’s IP is reused, verify the new fingerprint on the console, then clear the old one with ssh-keygen -R.
- The VNC console is a local login that works without SSH or network access, so keep a strong password even after you switch SSH to keys.
How to connect to a VPS in five steps
- Copy the server’s IP address, username and password from its page in the portal after you deploy it.
- Open a terminal: PowerShell or Windows Terminal on Windows, Terminal on macOS or Linux, or an SSH app on a phone.
- Run
ssh [email protected]with your own IP. Add-pand the port number if SSH does not listen on port 22. - On the first connection, check the server’s fingerprint, then type
yes. - Type the password (nothing appears while you type), then change it with
passwd.
The sections below cover each device and the switch to keys you should make on day one. New to servers? Read what a VPS is and when you need one first. The four details you need:
| Detail | Typical value | Notes |
|---|---|---|
| IP address | 203. (IPv4) or an IPv6 address | Each HourlyVPS server includes one IPv4 and IPv6. IPv6 works only if your own network has IPv6 too. |
| Username | root on most VPS images | Some cloud images use a named user such as ubuntu or debian. |
| Password or key | A root password, or a key you added at deploy | Change a delivered password on first login. |
| Port | 22 | The OpenSSH default. Only different if you or the image changed it. |
Practice server: you can follow this whole guide on a throwaway Quartz Q1. At $0.01/hour, two hours cost $0.02. A stopped server is still billed, because its vCPU, memory, disk and IP addresses stay reserved for you; only deleting the server stops billing. The meter is explained in how hourly VPS billing works, and all plans are on the pricing page.
Which SSH client should you use on each device?
| Device | Built in? | Use this | Alternatives |
|---|---|---|---|
| Windows 10 (1809+) and 11 | Yes: OpenSSH Client, an optional feature | PowerShell or Windows Terminal with ssh | PuTTY 0.85 |
| macOS | Yes | Terminal with ssh | Termius, Prompt 3 |
| Linux desktop | Yes on most distributions | Any terminal with ssh | sudo apt install openssh-client if missing |
| Android | No | Termux with pkg install openssh | ConnectBot (open source), Termius |
| iPhone and iPad | No | Termius | Blink Shell, Prompt 3 |
The ssh command is the same on every platform with a terminal, so the rest of this guide uses it. GUI apps ask for the same four details in a form.
How to connect to a VPS from Windows 10 and 11
PowerShell or Windows Terminal (built-in OpenSSH)
Open PowerShell or Windows Terminal and check that the client is there:
ssh -V
A version line that starts with OpenSSH_for_Windows means you are ready. If PowerShell says the term ssh is not recognized, type Optional features in the Start menu, open it, and add OpenSSH Client. Or run this in PowerShell opened as administrator:
Add-WindowsCapability -Online -Name OpenSSH.Client~~~~0.0.1.0
Then connect, with your server’s IP in place of the example:
ssh [email protected]
Answer the fingerprint question (see first login) and type the password; nothing appears as you type, which is normal. For a non-standard port, add -p 2222. Once you set up an alias, ssh ist1 is enough.
PuTTY (alternative)
PuTTY is a free SSH client with saved sessions in a window; version 0.85 was released on August 16, 2026. Download it only from the official PuTTY site.
- In Session, enter the IP in Host Name (or IP address), keep port 22 and connection type SSH.
- Type a name under Saved Sessions and click Save, so the next login is one double-click.
- Click Open, accept the host key alert after checking it, log in as
rootand enter the password.
For key logins, PuTTY uses its own .ppk format: in PuTTYgen pick EdDSA (Ed25519), generate, save the private key, and copy the line under Public key for pasting into OpenSSH authorized_keys file. Load the .ppk under Connection › SSH › Auth › Credentials. PuTTYgen’s Conversions menu converts keys to and from OpenSSH format.
How to connect to a VPS from macOS or Linux
Both include OpenSSH. On a Mac, open Terminal (Applications › Utilities); on Linux, open any terminal. Then:
ssh [email protected]
If a minimal Linux install lacks the client, install it on Debian or Ubuntu:
sudo apt install openssh-client
macOS also includes ssh-copy-id, which the key step uses.
Every keystroke in an SSH session travels to the server and back before it appears, so a server far away feels sluggish to type on. For interactive work, deploy close to where you sit (HourlyVPS deploys in Istanbul today, with New York coming soon); how to choose a VPS location shows how to measure it.
How to connect to a VPS from Android or iPhone
Phones need an app. These were listed in their official stores on October 3, 2026:
- Android: Termux (a Linux-style terminal from F-Droid or Google Play), ConnectBot (open source) and Termius.
- iPhone and iPad: Termius, Blink Shell and Prompt 3 by Panic.
GUI apps ask for host, port, username and a password or key. In Termux you install OpenSSH once and then use the same commands as on a laptop:
pkg install openssh
Two habits keep phone access safe:
- Generate a separate key on each phone and copy only its public key to the server. If the phone is lost, delete that one line from
~/.ssh/authorized_keysand every other device keeps working. - Protect the key with a passphrase or the app’s lock. A phone is easier to lose than a laptop.
First login: check the fingerprint and change the password
On the first connection OpenSSH cannot know whether it reached your server or an impostor, so it shows the server’s key fingerprint and asks:
The authenticity of host '203.0.113.10 (203.0.113.10)' can't be established.
ED25519 key fingerprint is SHA256:…
Are you sure you want to continue connecting (yes/no/[fingerprint])?
Typing yes trusts whatever answered. To be sure, open the VNC console from your server’s page in the HourlyVPS portal, log in there, and print the server’s real fingerprints:
for f in /etc/ssh/ssh_host_*_key.pub; do ssh-keygen -lf "$f"; done
Each line ends with the key type in brackets. If the SHA256: value on the line whose type matches the prompt (usually ED25519) is the same, type yes. You can also paste the fingerprint at the prompt instead of yes, and OpenSSH compares it for you. The key is then saved in ~/.ssh/known_hosts and checked on every later login.
Once you are in, change the delivered password, especially if it arrived by email:
passwd
Use a long, unique password from a password manager. The VNC console is a password login, so at least one account must keep a strong password even after SSH moves to keys.
Then, still as root, create an everyday user with sudo rights so you do not work as root. These commands come from the Ubuntu Server documentation; set a strong password when adduser asks, because you need it for sudo and for the console. On AlmaLinux and Rocky Linux the admin group is wheel instead of sudo.
adduser alex
adduser alex sudo
Tip: take a snapshot in the portal before you change SSH settings. If a change locks you out, restoring it is faster than debugging.
How to set up SSH key login with Ed25519
A key pair replaces the password: the private key stays on your device, the public key goes into ~/.ssh/authorized_keys on the server. Ed25519 has been the default key type in OpenSSH since version 9.5 (October 2023), and Microsoft documents it as the default in Windows’ OpenSSH too.
Step 1: Generate the key on your computer
The same command works in PowerShell, macOS Terminal and Linux. The -C comment labels the key so you can recognize its line in authorized_keys later:
ssh-keygen -t ed25519 -C "alex-laptop"
Accept the default file, ~/.ssh/id_ed25519 (on Windows C:\Users\you\.ssh\id_ed25519), and set a passphrase. id_ed25519 is the private key and never leaves the device; id_ed25519.pub is the public key you copy to servers.
Step 2 on macOS or Linux: copy the key with ssh-copy-id
ssh-copy-id -i ~/.ssh/id_ed25519.pub [email protected]
It logs in with the password once and appends your key to the user’s ~/.ssh/authorized_keys, creating the folder and file if needed.
Step 2 on Windows: the ssh-copy-id equivalent in PowerShell
Windows’ OpenSSH has no ssh-copy-id. This PowerShell line does the same job, with private permissions on anything it creates:
Get-Content ~\.ssh\id_ed25519.pub | ssh [email protected] "umask 077; mkdir -p ~/.ssh; cat >> ~/.ssh/authorized_keys"
Step 2 anywhere else: paste the key by hand
This works from a phone app or a PuTTY session, and from any session that already works when password logins are off. Log in as the target user, open the file and paste the public key as a single line:
mkdir -p ~/.ssh
nano ~/.ssh/authorized_keys
Save, then lock down the permissions. sshd refuses an authorized_keys file that other users can write to:
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
Step 3: Test the key, then load it into the agent
Open a new terminal and connect. You should be asked for the key’s passphrase, not the server password. Keep the old session open until this works.
ssh [email protected]
To type the passphrase once per session, hand the key to ssh-agent. On Windows the ssh-agent service is disabled by default; enable it from PowerShell opened as administrator:
Get-Service ssh-agent | Set-Service -StartupType Automatic
Start-Service ssh-agent
Then, in a normal window, run ssh-add with no arguments to load your default key. On macOS, store the passphrase in the Keychain instead:
ssh-add --apple-use-keychain ~/.ssh/id_ed25519
When key login works for your user, turn off password and root logins with our security checklist for a new Linux VPS; it covers the Ubuntu 24.04 drop-in file that silently overrides sshd_config. HourlyVPS servers are unmanaged, so this part is yours (see how we split security duties).
How to save servers as ~/.ssh/config aliases
Instead of remembering IPs, users and key files, describe each server once in ~/.ssh/config. On Windows that is C:\Users\you\.ssh\config, a file with no extension; in Notepad, choose All files as the type when saving, or it becomes config.txt. Example for two servers, the second with SSH on a custom port:
Host ist1
HostName 203.0.113.10
User alex
IdentityFile ~/.ssh/id_ed25519
IdentitiesOnly yes
Host lab1
HostName 198.51.100.20
User alex
Port 2222
IdentityFile ~/.ssh/id_ed25519
IdentitiesOnly yes
Host *
ServerAliveInterval 60
AddKeysToAgent yes
Now ssh ist1 is the whole command, and scp, sftp and rsync accept the same alias. It is also the starting point for a remote workstation such as Claude Code on a VPS, and for tunnels: SSH port forwarding uses the same alias to reach a database or dashboard that listens only on the server itself.
| Option | What it does |
|---|---|
Host | The alias you type; * matches every host. |
HostName | The real IP address or DNS name. |
User | The login name. |
Port | Only when SSH is not on 22. |
IdentityFile | The private key for this host. |
IdentitiesOnly yes | Offer only that key, even if the agent holds more. |
ServerAliveInterval 60 | After 60 seconds of silence, send a keepalive through the encrypted channel, so idle sessions survive and dead ones are noticed. |
AddKeysToAgent yes | Adds the key to the running agent after the first passphrase prompt. |
OpenSSH uses the first value it finds for each option, so keep specific Host blocks at the top and Host * last. On a Mac you can add UseKeychain yes under Host *; elsewhere that line fails with “Bad configuration option: usekeychain” unless an IgnoreUnknown UseKeychain line comes before it. To print the settings ssh will use for an alias:
ssh -G ist1
Why can’t I SSH into my VPS? Errors and fixes
Read the last line of the error: it tells you which stage failed. A login passes four stages in order, and each one fails with its own message.
Two quick tests narrow it down. Verbose mode prints every stage, including which keys your client offers:
ssh -v [email protected]
A port test shows whether anything answers on port 22. In PowerShell:
Test-NetConnection 203.0.113.10 -Port 22
On macOS or Linux:
nc -vz 203.0.113.10 22
| Error you see | What it means | Fix |
|---|---|---|
ssh: connect to host 203. (macOS says Operation timed out) | Nothing answered: wrong IP, server off or still booting, or a firewall silently dropping port 22, on the server or on your network. | Check the IP and power state in the portal. From the VNC console run sudo ufw status and, if needed, sudo ufw allow OpenSSH. Try a phone hotspot to rule out an office or hotel firewall. |
ssh: connect to host 203. | The server answered, but nothing listens on that port: SSH moved to another port, sshd is stopped, or a firewall rule rejects you, for example a fail2ban ban after failed logins. | Use the right port with -p. On the console: sudo systemctl status ssh.. After a Port change on Ubuntu 24.04, run sudo systemctl daemon-reload and sudo systemctl restart ssh.. Banned: sudo fail2ban-client set sshd unbanip YOUR_. |
alex@ | You reached sshd, but none of the keys you offered is in that user’s authorized_. The brackets list the methods the server accepts: publickey alone means password logins are off; publickey, means both failed. | Check the username. In ssh -v output, look for “Offering public key”. Point to the right key with -i or IdentityFile. Fix permissions on the server (chmod 700 ~/.ssh, chmod 600 ~/.ssh/) or re-add the key. |
Permission denied, please try again. | Wrong password, or root password logins are off (PermitRootLogin prohibit-password is the OpenSSH default). | Check keyboard layout and Caps Lock; nothing echoes while you type. Log in as your sudo user, or set a new password on the console with passwd. |
WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! followed by Host key verification failed. | The server’s host key differs from the one in known_. Expected after an OS reinstall, or when a deleted server’s IP now belongs to a new server. It can also mean interception. | Check the new fingerprint on the console (ssh-keygen -lf, as in first login). Then remove the old entry with ssh-keygen -R 203. (custom port: ssh-keygen -R "[203.) and reconnect. |
WARNING: UNPROTECTED PRIVATE KEY FILE! and Permissions 0644 for '/home/ | Your private key is readable by other users, so ssh ignores it. | chmod 600 ~/.ssh/. On Windows the message starts with “Bad permissions. Try removing permissions for user:” and names the account; remove it in the file’s Properties › Security tab. |
Received disconnect from 203. | Your agent offered more keys than the server allows (MaxAuthTries, default 6) before reaching the right one. | Add IdentitiesOnly yes and IdentityFile to that host’s config block. |
kex_, or Connection closed by 203. before any prompt (clients older than OpenSSH 9.5 add kex_) | The TCP connection opened, then the server dropped it before SSH started: too many unauthenticated connections at once (MaxStartups), or on an OpenSSH 9.8 or newer server a temporary penalty on your address after failed logins (PerSourcePenalties). | Wait a few minutes and retry. On the console, sudo journalctl -u ssh -n 50 shows the reason. |
client_ | An idle or interrupted session was cut, usually by a router or firewall in between, or by a server reboot. | Set ServerAliveInterval 60. Run long jobs inside tmux so they survive a disconnect. |
** WARNING: connection is not using a post-quantum key exchange algorithm. | Your client is OpenSSH 10.1 or newer and the server offers no post-quantum key exchange: OpenSSH 8.8 or older (Ubuntu 20.04 ships 8.2, Debian 11 ships 8.4), or a KexAlgorithms line that removed it. The session still works. | Move to a current image such as Ubuntu 24.04 LTS (OpenSSH 9.6). On a newer server, check KexAlgorithms. For a legacy host you cannot upgrade, WarnWeakCrypto no in its config block silences the warning, as the OpenSSH post-quantum page explains. |
ssh: Could not resolve hostname ist1 | ssh did not find the alias: a typo, or the config file is in the wrong place or named config.. | Run ssh -G ist1 and check the hostname line. Rename the file to config. |
Deploying and deleting servers often? Reused IP addresses make the host key warning common with temporary servers, so run ssh-keygen -R on your computer when you delete one; our checklist before you delete a VPS covers the rest of the cleanup. For brand-new hosts, StrictHostKeyChecking accept-new saves their keys without asking but still refuses changed ones. Never set it to no, which lets changed keys through.
Still can’t connect? Use the VNC console
The VNC console is the server’s own screen and keyboard, delivered through the control panel. It does not depend on SSH, the firewall or your keys, so it works when all three are broken. If a hardening change locked you out, the lockout recovery matrix in the security checklist matches each symptom to its fix.
- Open the VNC console from your server’s page in the HourlyVPS portal.
- Log in as root or your sudo user with the password. It is a local login, so SSH keys do not apply.
- Run the checks below, fix what they show, and test SSH from your computer before closing the console.
sudo systemctl status ssh.socket ssh
sudo sshd -t
sudo ufw status
sudo journalctl -u ssh -n 50 --no-pager
- Firewall blocks SSH:
sudo ufw allow OpenSSH, orsudo ufw allow 2222/tcpfor a custom port. sshd -tprints an error: fix the named line in/etc/ssh/sshd_configor/etc/ssh/sshd_config.d/(read first, so it wins), thensudo systemctl restart ssh.sshd -tsaysMissing privilege separation directory: /run/sshd: not a config error. On Ubuntu 24.04 that directory appears whenssh.servicefirst starts, so runsudo mkdir -p /run/sshdand test again.- Key rejected: fix ownership and permissions with
sudo chown -R alex:alex /home/alex/.ssh,sudo chmod 700 /home/alex/.sshandsudo chmod 600 /home/alex/.ssh/authorized_keys.
On Ubuntu 24.04, ssh.service can show inactive until a connection arrives, because ssh.socket holds port 22 and starts sshd on demand. Check that the socket is active before assuming SSH is down. Debian 12 and 13 run ssh.service directly, and sudo systemctl restart ssh applies changes there, port changes included. On Debian, drop sudo when you are logged in as root, and skip the UFW lines unless you installed UFW.
Warning: browser consoles often cannot paste from your clipboard, so keep console fixes short. Repair the cause there, then copy keys over SSH again. Lockouts caused by hardening steps (password logins off, UFW, a new port) have their own table in the VPS security checklist.
If no account can log in on the console either, restore a snapshot or reinstall the OS from the portal; a reinstall erases the disk. On a practice server, a fresh deploy is often quicker. New to all of this? Learning Linux on a VPS covers the next steps, and a one-day lab is simply 24 hours of hourly billing, as renting a VPS by the day shows.
Deploy this setup
Practice SSH on a throwaway server
Quartz Q1 · 1 shared vCPU · 1 GB RAM · 25 GB NVMe · Istanbul
- Per hour$0.01/hourFor this job
- Per day (24 h)$0.24/day
- Monthly cap$5.00/month
Starts with a $5 initial credit, which goes into the server’s balance and pays for its hours.
Billed by the hour, never more than $5.00 per billing period. Delete the server and billing stops.



