Set Up a Persistent SSH Server on Android Using Termux

15 min read Learn how to install and configure OpenSSH in Termux to run a reliable, always‑on SSH server on your Android device without rooting. October 09, 2026 22:30 How to Set Up a Persistent SSH Server on Android Using Termux (No Root)

Why Run an SSH Server on Android?

Having an SSH server on your phone turns it into a lightweight remote‑access point. You can:

  • Transfer files securely from a laptop or another phone.
  • Execute shell commands, scripts, or automation tasks while you are away.
  • Access the Termux environment as if it were a tiny Linux box.
  • Debug Android apps or IoT devices that need a reachable endpoint.

All of this is possible without rooting, because Termux runs in its own user space and the OpenSSH package works entirely within that sandbox.

Before You Start

Prerequisites

  • Android 7.0 (Nougat) or newer – older versions may lack the required storage permissions.
  • At least 200 MB of free internal storage for Termux and OpenSSH binaries.
  • Wi‑Fi or cellular data connection for downloading packages.
  • A secondary device (laptop, tablet, or another phone) to test the SSH connection.
  • Battery level above 50 % or the device plugged in – the SSH daemon will stop if Android kills the Termux process to save power.

Permissions: Termux needs storage access to read/write keys and optional file shares. You will grant this in the first step.

Step 1: Install Termux and Grant Permissions

  1. Open the F‑Droid page for Termux (recommended for the latest stable build) and install the app. If you prefer the Play Store, search for “Termux” and install the official version.
  2. Launch Termux. The first launch will automatically download a minimal set of command‑line tools.
  3. Grant storage permission so Termux can read/write files on your shared storage:
    termux-setup-storage
    You will see a system dialog – tap Allow. This creates a ~/storage folder linked to your internal storage.

After this step, you should see a prompt like username@localhost:~$. If you get an error about missing termux-setup-storage, ensure you are using the latest Termux version and repeat the command.

Step 2: Update Packages and Install OpenSSH

  1. Refresh the package repository and upgrade existing packages:
    pkg update && pkg upgrade -y
    This may take a few minutes depending on your connection.
  2. Install the OpenSSH package:
    pkg install openssh -y
  3. Verify the installation:
    ssh -V
    You should see something like OpenSSH_8.9p1, OpenSSL 1.1.1k 25 Mar 2021.

OpenSSH provides both the client (ssh) and the server daemon (sshd) you need.

Step 3: Create a Dedicated SSH User (Optional but Recommended)

Termux runs as a single Linux user that matches your Android user. For better security you can create a separate UNIX user that the SSH daemon will accept. This avoids exposing your primary Termux environment.

  1. Install the proot-distro helper (optional) if you want a full chroot, but for a simple user you can use adduser from the busybox package:
    pkg install busybox -y
  2. Create a new user called sshuser:
    busybox adduser sshuser
    You will be prompted for a password – choose a strong one. Press Enter for optional fields.
  3. Give the new user a home directory inside Termux:
    mkdir -p /data/data/com.termux/files/home/sshuser
  4. Set the correct ownership:
    chown sshuser:sshuser /data/data/com.termux/files/home/sshuser

If you prefer to keep using the default Termux user, skip this step and use the existing account for SSH logins.

Step 4: Generate SSH Host Keys

The SSH daemon needs a set of host keys to identify itself to clients. OpenSSH can generate them automatically.

  1. Run the key generation command:
    ssh-keygen -A
    This creates ssh_host_rsa_key, ssh_host_ecdsa_key, and ssh_host_ed25519_key in /data/data/com.termux/files/usr/etc/ssh/.
  2. Verify the keys exist:
    ls -l /data/data/com.termux/files/usr/etc/ssh/ssh_host_*

Do not share these private keys. They are used only by your device to prove its identity.

Step 5: Configure sshd_config

The default configuration is functional but we will tweak a few options for security and convenience.

  1. Open the config file with nano (installed by default) or vim if you prefer:
    nano /data/data/com.termux/files/usr/etc/ssh/sshd_config
  2. Make the following changes (add or modify lines):
    # Disable password authentication if you plan to use keys only
    PasswordAuthentication no
    
    # Allow the dedicated user (or the default) to log in
    AllowUsers sshuser
    
    # Change the default port to something non‑standard (optional but reduces noise)
    Port 2222
    
    # Enable public‑key authentication
    PubkeyAuthentication yes
    
    # Restrict login to the home directory (chroot) – optional and requires extra setup
    #ChrootDirectory %h
    
  3. Save and exit (Ctrl+O, Enter, Ctrl+X in nano).

Changing the port to 2222 avoids conflicts with the Android system’s internal SSH daemon (if present) and reduces automated scans.

Step 6: Create an SSH Key Pair for Client Authentication

Using key‑based authentication is far more secure than passwords, especially when the device is reachable from the internet.

  1. On the client machine (e.g., your laptop), generate a key pair if you don’t already have one:
    ssh-keygen -t ed25519 -C "android-ssh"
    Accept the default location (~/.ssh/id_ed25519) and set a passphrase.
  2. Copy the public key to the Android device. The easiest way is to use ssh-copy-id over USB debugging or via Termux’s built‑in ssh client:
    ssh-copy-id -p 2222 -i ~/.ssh/id_ed25519.pub sshuser@DEVICE_IP
    If ssh-copy-id is not available, manually append the key:
    mkdir -p /data/data/com.termux/files/home/sshuser/.ssh
    cat ~/.ssh/id_ed25519.pub > /data/data/com.termux/files/home/sshuser/.ssh/authorized_keys
    chmod 600 /data/data/com.termux/files/home/sshuser/.ssh/authorized_keys
  3. Set proper ownership on the Android side:
    chown -R sshuser:sshuser /data/data/com.termux/files/home/sshuser/.ssh

After this, the client can log in without a password, provided the private key is present.

Step 7: Start the SSH Daemon Manually (First Test)

  1. Start the daemon with the custom config file:
    sshd -p 2222 -D -e
    The -D flag runs it in the foreground (useful for testing), and -e logs to stderr.
  2. From your client, attempt a connection:
    ssh -p 2222 sshuser@DEVICE_IP
    If you set up key authentication, you should be logged in without a password prompt.
  3. When you see the remote shell, type exit to close the session.
  4. Stop the foreground daemon by pressing Ctrl+C in Termux.

Successful connection confirms that the SSH server works and that the network path (Wi‑Fi, router, firewall) allows traffic on the chosen port.

Step 8: Make the SSH Server Start Automatically

Android may kill background processes to reclaim memory. Termux provides a helper called termux-services that registers a systemd-like service which survives across reboots and respects Android’s power‑saving policies.

  1. Install the service manager:
    pkg install termux-services -y
  2. Create a service definition file named sshd.service in the ~/.termux/boot directory (create the directories if they don’t exist):
    mkdir -p ~/.termux/boot
    cat > ~/.termux/boot/sshd.service <<'EOF'
    [Unit]
    Description=OpenSSH Daemon for Termux
    After=network.target
    
    [Service]
    ExecStart=/data/data/com.termux/files/usr/bin/sshd -p 2222 -D
    Restart=always
    
    [Install]
    WantedBy=default.target
    EOF
  3. Enable the service:
    termux-service enable sshd
  4. Start it immediately (or reboot to test persistence):
    termux-service start sshd

To verify that the service survived a reboot, simply restart the device and run:

termux-service status sshd

It should report active (running). If it shows inactive, check the log:

termux-service log sshd

Step 9: Adjust Android Battery Optimisation Settings

Even with termux-service, Android may stop the process if the app is placed in a battery‑optimisation whitelist.

  1. Open Settings → Battery → Battery optimisation (on some devices: Settings → Apps → Termux → Battery → Optimize battery usage).
  2. Switch the view to “All apps”. Find “Termux” and select “Don’t optimise”.
  3. Optionally, disable “Background restriction” for Termux if your device offers that toggle.

This tells Android that Termux is allowed to run in the background, which is essential for a persistent SSH server.

Step 10: Configure Router Port Forwarding (If You Need Remote Access)

For connections from outside your local Wi‑Fi (e.g., from home to office), you must forward the chosen port on your router to the Android device’s local IP.

  1. Find the device’s IP address in Termux:
    ip addr show wlan0
    Look for the line with inet, e.g., 192.168.1.42/24.
  2. Log into your router’s web interface (usually 192.168.1.1 or 192.168.0.1).
  3. Navigate to the “Port Forwarding” or “Virtual Server” section.
  4. Create a new rule:
    • External Port: 2222 (or any port you chose).
    • Internal IP: Device_IP (e.g., 192.168.1.42).
    • Internal Port: 2222.
    • Protocol: TCP.
  5. Save the rule and, if required, restart the router.

To test from an external network, use your public IP (found at https://ifconfig.me from the Android device) and the forwarded port:

ssh -p 2222 sshuser@PUBLIC_IP

If the connection fails, double‑check that your ISP does not block inbound ports and that the Android device’s Wi‑Fi IP has not changed (consider setting a static DHCP lease).

Step 11: Harden the Server (Optional but Recommended)

Even though the server runs on a personal device, applying a few hardening steps reduces risk.

  • Disable root login: Ensure PermitRootLogin no is present in sshd_config.
  • Limit login attempts: Add MaxAuthTries 3 to mitigate brute‑force attacks.
  • Use fail2ban‑like logic: Termux doesn’t ship fail2ban, but you can script a simple watchdog that bans IPs after repeated failures using iptables (requires root, so skip on non‑root devices).
  • Rotate host keys periodically: Run ssh-keygen -A after a clean reinstall or every few months.

Troubleshooting Common Issues

1. “Connection timed out”

  • Check that the Android device is on the same Wi‑Fi network as the client.
  • Confirm the port is open: nc -zv DEVICE_IP 2222 from the client.
  • Verify the firewall (if any) on the Android side – Termux does not install a firewall by default, but apps like NetGuard can block traffic. Add an exception for Termux or disable the firewall temporarily.

2. “Permission denied (publickey)”

  • Ensure the public key is correctly placed in /data/data/com.termux/files/home/sshuser/.ssh/authorized_keys and has 600 permissions.
  • Check the sshd_config line PubkeyAuthentication yes is not commented out.
  • Make sure you are connecting as the correct user (sshuser).

3. SSH daemon stops after screen lock

  • Android may suspend background processes when the screen is off. The battery‑optimisation whitelist (Step 9) usually solves this.
  • If the device still kills Termux, enable “Keep screen on” temporarily while testing: Settings → Display → Stay awake (while charging).

4. Port 2222 already in use

  • Run ss -tlnp | grep 2222 in Termux to see if another service occupies the port.
  • Pick an unused port (e.g., 2022) and update both sshd_config and any client commands.

5. “Bad owner or permissions on /data/.../.ssh/authorized_keys”

  • SSH is strict about ownership. Run:
    chown -R sshuser:sshuser /data/data/com.termux/files/home/sshuser/.ssh
    chmod 700 /data/data/com.termux/files/home/sshuser/.ssh
    chmod 600 /data/data/com.termux/files/home/sshuser/.ssh/authorized_keys

Advanced Use Cases

  • SFTP file transfer: The same daemon provides SFTP out of the box. Use sftp -P 2222 sshuser@DEVICE_IP to browse files.
  • Remote script execution: From your laptop you can run a one‑liner:
    ssh -p 2222 sshuser@DEVICE_IP 'ls -l ~/downloads'
  • Git over SSH: Initialize a bare repository on Android and push from another machine.

Because Termux runs a regular Linux userland, any standard OpenSSH feature works as long as the underlying Android kernel supports it.

Security Checklist Before Going Live

ItemCheck
Strong, unique password for the dedicated SSH user (if password auth is enabled)
Public‑key authentication configured
Battery optimisation disabled for Termux
Port forwarding rule active (if remote access needed)
Host keys generated and stored securely
SSH daemon set to start on boot via termux‑service

Wrap‑Up

By following the steps above you have turned a standard Android phone into a reliable, always‑on SSH server without rooting. The setup uses only free, open‑source tools that run entirely in user space, respects Android’s power‑saving policies, and offers a solid security baseline through key‑based authentication.

Remember to keep your device’s software up to date, rotate keys periodically, and monitor the sshd logs (logcat | grep sshd) for any unexpected activity. With this foundation you can explore more advanced workflows—remote backups, automated scripts, or even a tiny Git server—directly from the palm of your hand.

User Comments (0)

Add Comment
We'll never share your email with anyone else.