Set Up a Secure SFTP Server on Android Using Termux

17 min read Step‑by‑step guide to turn an Android phone into a secure SFTP server with Termux, key‑based authentication and auto‑start on boot. September 27, 2026 18:30 How to Set Up an SFTP Server on Android Using Termux for Secure File Transfers

Why Run an SFTP Server on Android?

Android devices are great for on‑the‑go storage, but the built‑in file sharing options (Bluetooth, Nearby Share, etc.) are either slow or lack encryption. An SFTP server gives you:

  • Encrypted transfer – SSH protects your data from eavesdropping.
  • Cross‑platform access – Any SFTP client on Windows, macOS, Linux, or another phone can connect.
  • Fine‑grained permissions – You can restrict which folders are visible and enforce key‑based login.

All of this can be achieved without rooting the device, using the free Termux environment.

Before You Start

Gather the following items before you begin:

  • A smartphone running Android 10 or newer (older versions work but may need extra steps).
  • At least 200 MB of free storage for Termux and the OpenSSH package.
  • Wi‑Fi or a reliable LAN connection – SFTP works best on the same subnet as the client.
  • A computer or another device with an SFTP client (e.g., FileZilla, WinSCP, or the sftp command).
  • Optional: a USB‑C OTG adapter if you want to keep the phone powered via a wall charger while the server runs.

Make sure the phone is charged above 50 % and, if possible, plugged in. Running a server can keep the CPU awake and drain the battery quickly.

Step 1 – Install Termux and Grant Storage Access

  1. Open the Google Play Store (or F‑Droid for the open‑source build) and install Termux.
  2. Launch Termux. The first launch will download a minimal Linux environment – wait until the prompt $ appears.
  3. Android 11+ restricts file access. Run the following command to request the READ/WRITE_EXTERNAL_STORAGE permission:
    termux-setup-storage
    Accept the system dialog. This creates a /storage/emulated/0 folder inside Termux, linked to your shared storage.
  4. If your device runs Android 13 or newer, you may also need to enable the "All files access" toggle for Termux in Settings → Apps → Termux → Permissions. This allows the SFTP server to read/write any folder you expose.

After these commands, you can navigate to your shared storage with cd /storage/emulated/0 and see your photos, downloads, etc.

Step 2 – Install OpenSSH (the SFTP Engine)

  1. Update the package index and upgrade existing packages:
    pkg update && pkg upgrade -y
  2. Install the OpenSSH package, which provides both ssh and sftp services:
    pkg install openssh -y
  3. Verify the installation by checking the version:
    ssh -V
    You should see something like OpenSSH_8.9p1, OpenSSL 1.1.1k 25 Mar 2021.

OpenSSH runs entirely in user space, so no root privileges are required.

Step 3 – Create a Dedicated SFTP User

Running the server as the default u0_aXXX user works, but separating the SFTP account makes permissions clearer and avoids accidental changes to your Termux environment.

  1. Create a new Linux user named sftpuser with its own home directory:
    adduser sftpuser
    You will be prompted for a password – choose a strong one (at least 12 characters) and remember it.
  2. Set the home directory to a location you want to share. For example, to expose the Download folder:
    usermod -d /storage/emulated/0/Download sftpuser
  3. Restrict the user’s shell to /usr/bin/nologin so they cannot obtain an interactive SSH shell (only SFTP):
    usermod -s /usr/bin/nologin sftpuser
  4. Adjust ownership so the user can read/write the shared folder:
    chown sftpuser:sftpuser /storage/emulated/0/Download

If you prefer to expose a different folder, replace the path in step 2 with the desired directory.

Step 4 – Enable Key‑Based Authentication (Recommended)

Password authentication works, but SSH keys are more secure and eliminate the need to type a password on every connection.

  1. On your computer, generate an SSH key pair if you don’t already have one:
    ssh-keygen -t ed25519 -C "android-sftp"
    Accept the default location (e.g., ~/.ssh/id_ed25519) and set a passphrase.
  2. Copy the public key to the Android device. The easiest way is to use scp (or simply paste the key via Termux):
    cat ~/.ssh/id_ed25519.pub | termux-clipboard-set
    Then, in Termux, run:
    mkdir -p /data/data/com.termux/files/home/.ssh
    chmod 700 /data/data/com.termux/files/home/.ssh
    termux-clipboard-get > /data/data/com.termux/files/home/.ssh/authorized_keys
    chmod 600 /data/data/com.termux/files/home/.ssh/authorized_keys
  3. Tell OpenSSH to trust this key for sftpuser:
    mkdir -p /home/sftpuser/.ssh
    chmod 700 /home/sftpuser/.ssh
    cat /data/data/com.termux/files/home/.ssh/authorized_keys > /home/sftpuser/.ssh/authorized_keys
    chmod 600 /home/sftpuser/.ssh/authorized_keys
  4. Edit the SSH daemon configuration to enable key authentication and disable password login (optional but recommended):
    nano $PREFIX/etc/ssh/sshd_config
    Ensure the following lines exist and are uncommented:
    PubkeyAuthentication yes
    PasswordAuthentication no
    Subsystem sftp internal-sftp
    Save and exit (Ctrl+X, Y, Enter).

After this, you can connect from your computer with:

sftp -i ~/.ssh/id_ed25519 sftpuser@ANDROID_IP

Replace ANDROID_IP with the phone’s local IP address (see Step 5).

Step 5 – Choose a Port and Start the SSH Daemon

Port 22 is the default, but many routers block it or it may conflict with other services. Port 2222 is a safe alternative.

  1. Open the SSH configuration file again and set the listening port:
    nano $PREFIX/etc/ssh/sshd_config
    Find the line starting with #Port 22 and change it to:
    Port 2222
  2. Start the daemon manually to test the configuration:
    sshd -D -e
    The -D flag runs it in the foreground, and -e logs to stderr. You should see a line like Server listening on 0.0.0.0 port 2222.
  3. Leave this terminal open for a moment, then open a new Termux session (swipe from the left edge) and run a quick connectivity test from your computer:
    sftp -P 2222 sftpuser@ANDROID_IP
    If you see a prompt for the key’s passphrase (or immediate login if you disabled passwords), the server works.
  4. Stop the foreground daemon with Ctrl+C. We will now set it up to run as a background service.

Step 6 – Run sshd as a Background Service with Termux:Boot

Termux provides a small add‑on called Termux:Boot that launches scripts automatically after the device boots.

  1. Install the add‑on from the Play Store or F‑Droid.
  2. Create a startup script directory if it does not exist:
    mkdir -p $HOME/.termux/boot
  3. Create a script named sshd_start.sh:
    cat > $HOME/.termux/boot/sshd_start.sh <<'EOF'
    #!/data/data/com.termux/files/usr/bin/sh
    # Ensure the SSH daemon uses the proper config
    sshd -f $PREFIX/etc/ssh/sshd_config
    EOF
    chmod +x $HOME/.termux/boot/sshd_start.sh
    
  4. Test the script manually:
    $HOME/.termux/boot/sshd_start.sh &
    Verify that netstat -tlnp | grep 2222 (or ss -ltnp | grep 2222) shows the daemon listening.
  5. Reboot the phone and confirm the service starts automatically by checking the port again or attempting an SFTP connection.

If the daemon does not start, open Termux and run logcat | grep sshd to view any error messages.

Step 7 – Keep the Server Alive When the Screen Sleeps

Android may pause background processes when the device enters Doze mode. To prevent the SSH daemon from being killed:

  • Open Termux and run termux-wake-lock. This acquires a partial wake lock, keeping the CPU on.
  • To make it persistent, add the command to the same boot script after starting sshd:
    cat >> $HOME/.termux/boot/sshd_start.sh <<'EOF'
    termux-wake-lock
    EOF

Remember to release the lock when you no longer need the server: termux-wake-unlock.

Step 8 – Verify the Setup from a Client Machine

From your computer, run the following command (replace ANDROID_IP with the phone’s IP, which you can see with ifconfig or ip addr show wlan0 in Termux):

sftp -P 2222 sftpuser@ANDROID_IP

You should see an sftp> prompt. Try a few operations:

  1. ls – lists the contents of the shared Download folder.
  2. put /path/to/local/file.jpg – uploads a file to the phone.
  3. get remote_video.mp4 – downloads a file to your computer.

If all commands succeed, your SFTP server is ready for daily use.

Step 9 – Optional: Restrict Access with a Firewall

Termux ships with iptables (via the iptables package). You can block connections from outside your LAN:

  1. Install the package:
    pkg install iptables -y
  2. Add a rule that only allows traffic from the local subnet (e.g., 192.168.1.0/24):
    iptables -A INPUT -p tcp --dport 2222 -s 192.168.1.0/24 -j ACCEPT
    iptables -A INPUT -p tcp --dport 2222 -j DROP
  3. Save the rules so they survive a reboot. Termux does not have a persistent firewall service, but you can append the commands to the boot script created in Step 6.

Be careful: a mis‑typed rule can lock you out of the server. Always test connectivity after adding a rule.

Troubleshooting Common Issues

1. "Connection refused" or "No route to host"

  • Confirm the phone’s IP address has not changed. Android may assign a new address after a Wi‑Fi reconnection.
  • Check that the daemon is running: ps | grep sshd. If not, start it manually or review the boot script.
  • Make sure the chosen port (2222) is not blocked by your router’s firewall.

2. Authentication fails

  • If you disabled password login, ensure the public key is correctly placed in /home/sftpuser/.ssh/authorized_keys and has 600 permissions.
  • Run ssh -vvv -p 2222 sftpuser@ANDROID_IP from the client to see detailed debug output.

3. "Permission denied" when accessing the shared folder

  • Verify ownership: ls -ld /storage/emulated/0/Download. It should show sftpuser sftpuser.
  • If you need read‑only access for the client, set chmod 755 on the folder.

4. Server stops when the screen turns off

  • Ensure termux-wake-lock is active. You can also disable Doze for Termux by adding the app to the battery optimization whitelist (Settings → Battery → Battery optimization → All apps → Termux → Don’t optimize).

Security Best Practices

  • Use key authentication and keep the private key protected with a passphrase.
  • Keep the SSH daemon up to date: periodically run pkg upgrade openssh.
  • Change the default port (2222) to something less obvious if you expose the server to a larger network.
  • Limit the shared directory to only the files you need to transfer. Avoid exposing your entire internal storage.
  • Regularly review the authorized_keys file and remove keys you no longer use.

Cleaning Up

If you ever need to stop the server:

pkill sshd

To remove the setup completely, delete the user and the configuration files:

userdel -r sftpuser
rm -rf $HOME/.termux/boot/sshd_start.sh
pkg uninstall openssh -y

Remember to also revoke any firewall rules you added.

Wrap‑Up

By following these steps you have turned an ordinary Android phone into a fully functional, encrypted SFTP server that can run in the background, start on boot, and be accessed from any computer on your LAN. The solution relies only on free, open‑source tools and does not require rooting, making it safe for most users. Use the server to back up photos, share large video files, or simply keep a portable repository that travels with you.

User Comments (0)

Add Comment
We'll never share your email with anyone else.