Having an SSH server on your phone turns it into a lightweight remote‑access point. You can:
All of this is possible without rooting, because Termux runs in its own user space and the OpenSSH package works entirely within that sandbox.
Prerequisites
Permissions: Termux needs storage access to read/write keys and optional file shares. You will grant this in the first step.
termux-setup-storage
You will see a system dialog – tap Allow. This creates a ~/storage folder linked to your internal storage.After this step, you should see a prompt like username@localhost:~$. If you get an error about missing termux-setup-storage, ensure you are using the latest Termux version and repeat the command.
pkg update && pkg upgrade -y
This may take a few minutes depending on your connection.pkg install openssh -yssh -V
You should see something like OpenSSH_8.9p1, OpenSSL 1.1.1k 25 Mar 2021.OpenSSH provides both the client (ssh) and the server daemon (sshd) you need.
Termux runs as a single Linux user that matches your Android user. For better security you can create a separate UNIX user that the SSH daemon will accept. This avoids exposing your primary Termux environment.
proot-distro helper (optional) if you want a full chroot, but for a simple user you can use adduser from the busybox package:
pkg install busybox -ysshuser:
busybox adduser sshuser
You will be prompted for a password – choose a strong one. Press Enter for optional fields.mkdir -p /data/data/com.termux/files/home/sshuserchown sshuser:sshuser /data/data/com.termux/files/home/sshuserIf you prefer to keep using the default Termux user, skip this step and use the existing account for SSH logins.
The SSH daemon needs a set of host keys to identify itself to clients. OpenSSH can generate them automatically.
ssh-keygen -A
This creates ssh_host_rsa_key, ssh_host_ecdsa_key, and ssh_host_ed25519_key in /data/data/com.termux/files/usr/etc/ssh/.ls -l /data/data/com.termux/files/usr/etc/ssh/ssh_host_*Do not share these private keys. They are used only by your device to prove its identity.
sshd_configThe default configuration is functional but we will tweak a few options for security and convenience.
nano (installed by default) or vim if you prefer:
nano /data/data/com.termux/files/usr/etc/ssh/sshd_config# Disable password authentication if you plan to use keys only
PasswordAuthentication no
# Allow the dedicated user (or the default) to log in
AllowUsers sshuser
# Change the default port to something non‑standard (optional but reduces noise)
Port 2222
# Enable public‑key authentication
PubkeyAuthentication yes
# Restrict login to the home directory (chroot) – optional and requires extra setup
#ChrootDirectory %h
Changing the port to 2222 avoids conflicts with the Android system’s internal SSH daemon (if present) and reduces automated scans.
Using key‑based authentication is far more secure than passwords, especially when the device is reachable from the internet.
ssh-keygen -t ed25519 -C "android-ssh"
Accept the default location (~/.ssh/id_ed25519) and set a passphrase.ssh-copy-id over USB debugging or via Termux’s built‑in ssh client:
ssh-copy-id -p 2222 -i ~/.ssh/id_ed25519.pub sshuser@DEVICE_IP
If ssh-copy-id is not available, manually append the key:
mkdir -p /data/data/com.termux/files/home/sshuser/.ssh
cat ~/.ssh/id_ed25519.pub > /data/data/com.termux/files/home/sshuser/.ssh/authorized_keys
chmod 600 /data/data/com.termux/files/home/sshuser/.ssh/authorized_keyschown -R sshuser:sshuser /data/data/com.termux/files/home/sshuser/.sshAfter this, the client can log in without a password, provided the private key is present.
sshd -p 2222 -D -e
The -D flag runs it in the foreground (useful for testing), and -e logs to stderr.
ssh -p 2222 sshuser@DEVICE_IP
If you set up key authentication, you should be logged in without a password prompt.exit to close the session.Successful connection confirms that the SSH server works and that the network path (Wi‑Fi, router, firewall) allows traffic on the chosen port.
Android may kill background processes to reclaim memory. Termux provides a helper called termux-services that registers a systemd-like service which survives across reboots and respects Android’s power‑saving policies.
pkg install termux-services -ysshd.service in the ~/.termux/boot directory (create the directories if they don’t exist):
mkdir -p ~/.termux/boot
cat > ~/.termux/boot/sshd.service <<'EOF'
[Unit]
Description=OpenSSH Daemon for Termux
After=network.target
[Service]
ExecStart=/data/data/com.termux/files/usr/bin/sshd -p 2222 -D
Restart=always
[Install]
WantedBy=default.target
EOFtermux-service enable sshdtermux-service start sshdTo verify that the service survived a reboot, simply restart the device and run:
termux-service status sshd
It should report active (running). If it shows inactive, check the log:
termux-service log sshd
Even with termux-service, Android may stop the process if the app is placed in a battery‑optimisation whitelist.
This tells Android that Termux is allowed to run in the background, which is essential for a persistent SSH server.
For connections from outside your local Wi‑Fi (e.g., from home to office), you must forward the chosen port on your router to the Android device’s local IP.
ip addr show wlan0
Look for the line with inet, e.g., 192.168.1.42/24.192.168.1.1 or 192.168.0.1).To test from an external network, use your public IP (found at https://ifconfig.me from the Android device) and the forwarded port:
ssh -p 2222 sshuser@PUBLIC_IP
If the connection fails, double‑check that your ISP does not block inbound ports and that the Android device’s Wi‑Fi IP has not changed (consider setting a static DHCP lease).
Even though the server runs on a personal device, applying a few hardening steps reduces risk.
PermitRootLogin no is present in sshd_config.MaxAuthTries 3 to mitigate brute‑force attacks.iptables (requires root, so skip on non‑root devices).ssh-keygen -A after a clean reinstall or every few months.nc -zv DEVICE_IP 2222 from the client./data/data/com.termux/files/home/sshuser/.ssh/authorized_keys and has 600 permissions.sshd_config line PubkeyAuthentication yes is not commented out.sshuser).ss -tlnp | grep 2222 in Termux to see if another service occupies the port.sshd_config and any client commands.chown -R sshuser:sshuser /data/data/com.termux/files/home/sshuser/.ssh
chmod 700 /data/data/com.termux/files/home/sshuser/.ssh
chmod 600 /data/data/com.termux/files/home/sshuser/.ssh/authorized_keyssftp -P 2222 sshuser@DEVICE_IP to browse files.
ssh -p 2222 sshuser@DEVICE_IP 'ls -l ~/downloads'
Because Termux runs a regular Linux userland, any standard OpenSSH feature works as long as the underlying Android kernel supports it.
| Item | Check |
|---|---|
| Strong, unique password for the dedicated SSH user (if password auth is enabled) | |
| Public‑key authentication configured | |
| Battery optimisation disabled for Termux | |
| Port forwarding rule active (if remote access needed) | |
| Host keys generated and stored securely | |
| SSH daemon set to start on boot via termux‑service |
By following the steps above you have turned a standard Android phone into a reliable, always‑on SSH server without rooting. The setup uses only free, open‑source tools that run entirely in user space, respects Android’s power‑saving policies, and offers a solid security baseline through key‑based authentication.
Remember to keep your device’s software up to date, rotate keys periodically, and monitor the sshd logs (logcat | grep sshd) for any unexpected activity. With this foundation you can explore more advanced workflows—remote backups, automated scripts, or even a tiny Git server—directly from the palm of your hand.









