Android devices are great for on‑the‑go storage, but the built‑in file sharing options (Bluetooth, Nearby Share, etc.) are either slow or lack encryption. An SFTP server gives you:
All of this can be achieved without rooting the device, using the free Termux environment.
Gather the following items before you begin:
sftp command).Make sure the phone is charged above 50 % and, if possible, plugged in. Running a server can keep the CPU awake and drain the battery quickly.
$ appears.READ/WRITE_EXTERNAL_STORAGE permission:
termux-setup-storage
Accept the system dialog. This creates a /storage/emulated/0 folder inside Termux, linked to your shared storage.After these commands, you can navigate to your shared storage with cd /storage/emulated/0 and see your photos, downloads, etc.
pkg update && pkg upgrade -y
ssh and sftp services:
pkg install openssh -y
ssh -V
You should see something like OpenSSH_8.9p1, OpenSSL 1.1.1k 25 Mar 2021.OpenSSH runs entirely in user space, so no root privileges are required.
Running the server as the default u0_aXXX user works, but separating the SFTP account makes permissions clearer and avoids accidental changes to your Termux environment.
sftpuser with its own home directory:
adduser sftpuser
You will be prompted for a password – choose a strong one (at least 12 characters) and remember it.
Download folder:
usermod -d /storage/emulated/0/Download sftpuser
/usr/bin/nologin so they cannot obtain an interactive SSH shell (only SFTP):
usermod -s /usr/bin/nologin sftpuser
chown sftpuser:sftpuser /storage/emulated/0/Download
If you prefer to expose a different folder, replace the path in step 2 with the desired directory.
Password authentication works, but SSH keys are more secure and eliminate the need to type a password on every connection.
ssh-keygen -t ed25519 -C "android-sftp"
Accept the default location (e.g., ~/.ssh/id_ed25519) and set a passphrase.
scp (or simply paste the key via Termux):
cat ~/.ssh/id_ed25519.pub | termux-clipboard-set
Then, in Termux, run:
mkdir -p /data/data/com.termux/files/home/.ssh
chmod 700 /data/data/com.termux/files/home/.ssh
termux-clipboard-get > /data/data/com.termux/files/home/.ssh/authorized_keys
chmod 600 /data/data/com.termux/files/home/.ssh/authorized_keys
sftpuser:
mkdir -p /home/sftpuser/.ssh
chmod 700 /home/sftpuser/.ssh
cat /data/data/com.termux/files/home/.ssh/authorized_keys > /home/sftpuser/.ssh/authorized_keys
chmod 600 /home/sftpuser/.ssh/authorized_keys
nano $PREFIX/etc/ssh/sshd_config
Ensure the following lines exist and are uncommented:
PubkeyAuthentication yes
PasswordAuthentication no
Subsystem sftp internal-sftp
Save and exit (Ctrl+X, Y, Enter).
After this, you can connect from your computer with:
sftp -i ~/.ssh/id_ed25519 sftpuser@ANDROID_IP
Replace ANDROID_IP with the phone’s local IP address (see Step 5).
Port 22 is the default, but many routers block it or it may conflict with other services. Port 2222 is a safe alternative.
nano $PREFIX/etc/ssh/sshd_config
Find the line starting with #Port 22 and change it to:
Port 2222
sshd -D -e
The -D flag runs it in the foreground, and -e logs to stderr. You should see a line like Server listening on 0.0.0.0 port 2222.
sftp -P 2222 sftpuser@ANDROID_IP
If you see a prompt for the key’s passphrase (or immediate login if you disabled passwords), the server works.
Ctrl+C. We will now set it up to run as a background service.Termux provides a small add‑on called Termux:Boot that launches scripts automatically after the device boots.
mkdir -p $HOME/.termux/boot
sshd_start.sh:
cat > $HOME/.termux/boot/sshd_start.sh <<'EOF'
#!/data/data/com.termux/files/usr/bin/sh
# Ensure the SSH daemon uses the proper config
sshd -f $PREFIX/etc/ssh/sshd_config
EOF
chmod +x $HOME/.termux/boot/sshd_start.sh
$HOME/.termux/boot/sshd_start.sh &
Verify that netstat -tlnp | grep 2222 (or ss -ltnp | grep 2222) shows the daemon listening.
If the daemon does not start, open Termux and run logcat | grep sshd to view any error messages.
Android may pause background processes when the device enters Doze mode. To prevent the SSH daemon from being killed:
termux-wake-lock. This acquires a partial wake lock, keeping the CPU on.cat >> $HOME/.termux/boot/sshd_start.sh <<'EOF'
termux-wake-lock
EOF
Remember to release the lock when you no longer need the server: termux-wake-unlock.
From your computer, run the following command (replace ANDROID_IP with the phone’s IP, which you can see with ifconfig or ip addr show wlan0 in Termux):
sftp -P 2222 sftpuser@ANDROID_IP
You should see an sftp> prompt. Try a few operations:
ls – lists the contents of the shared Download folder.put /path/to/local/file.jpg – uploads a file to the phone.get remote_video.mp4 – downloads a file to your computer.If all commands succeed, your SFTP server is ready for daily use.
Termux ships with iptables (via the iptables package). You can block connections from outside your LAN:
pkg install iptables -y
iptables -A INPUT -p tcp --dport 2222 -s 192.168.1.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 2222 -j DROP
Be careful: a mis‑typed rule can lock you out of the server. Always test connectivity after adding a rule.
ps | grep sshd. If not, start it manually or review the boot script./home/sftpuser/.ssh/authorized_keys and has 600 permissions.ssh -vvv -p 2222 sftpuser@ANDROID_IP from the client to see detailed debug output.ls -ld /storage/emulated/0/Download. It should show sftpuser sftpuser.chmod 755 on the folder.termux-wake-lock is active. You can also disable Doze for Termux by adding the app to the battery optimization whitelist (Settings → Battery → Battery optimization → All apps → Termux → Don’t optimize).pkg upgrade openssh.authorized_keys file and remove keys you no longer use.If you ever need to stop the server:
pkill sshd
To remove the setup completely, delete the user and the configuration files:
userdel -r sftpuser
rm -rf $HOME/.termux/boot/sshd_start.sh
pkg uninstall openssh -y
Remember to also revoke any firewall rules you added.
By following these steps you have turned an ordinary Android phone into a fully functional, encrypted SFTP server that can run in the background, start on boot, and be accessed from any computer on your LAN. The solution relies only on free, open‑source tools and does not require rooting, making it safe for most users. Use the server to back up photos, share large video files, or simply keep a portable repository that travels with you.









