Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Guides · Connecting

    SFTP and file transfer

    Move and edit files on the servers you manage without leaving MangoSSH. The SFTP browser rides on the SSH session you already have open. Quick SFTP, FTP and TFTP cover the servers and devices you have not saved as hosts, and Compare shows what differs between two files or folders.

    • SFTP · FTP · TFTP
    • Windows · macOS · Linux
    • Nothing extra to install

    Which tool to use

    ToolWhere it livesUse it when
    SSH Browse/SFTPThe folder icon on a connected SSH session's toolbarYou are already connected to a saved host. It reuses that session, so there is no second login.
    Quick SFTPSFTP on the main toolbar, or Tools → Quick SFTPYou need files from a server you have not saved. Host, user and password, then connect.
    FTPTools → FTPThe other end only speaks FTP: an old appliance, a camera, a legacy drop box.
    TFTPTools → TFTPYou are pushing firmware or configs to switches, routers or phones, or netbooting something.
    CompareTools → CompareYou want to know what differs between two files or folders, on this machine or across two SSH hosts.

    Browse files on a connected host

    1. Connect to the host as usual. See SSH hosts.

    2. On the session toolbar, click the folder icon (tooltip SSH Browse/SFTP). The page opens with two panes: LOCAL on the left and REMOTE on the right, the remote one starting in your home folder.

    3. Double-click a folder to open it. Each pane has Back, Up (parent folder) and Refresh, and a path bar you can type into: type a path and press Enter to jump there.

    Click a column heading (Name, Type, Size, Modified) to sort. Drag the divider between the panes to give one side more room. With the list focused, typing a few letters jumps to the first matching name, the arrow keys move the highlight, and Enter opens the highlighted item.

    If the page says Connect to a host to browse files, there is no live SSH session behind it. The browser needs one, because it opens its SFTP channel inside that session.

    Move files

    There are three ways to copy a file, and they all do the same thing:

    • Drag it from one pane and drop it on the other. Local to remote uploads; remote to local downloads.
    • Select it and use the toolbar at the top of the page: Upload sends the selected local file into the current remote folder, Download brings the selected remote file into the current local folder.
    • Right-click it and choose Copy to Local or Copy to Remote.

    A progress bar with a percentage shows under the panes while a transfer runs. Click its × to dismiss it when it is done. Files larger than 2 MB are moved over four parallel streams, which helps most on high-latency links. If the name already exists in the remote folder, MangoSSH asks before overwriting it.

    One file at a time, and no folders

    Transfers work on single files. Folders cannot be dragged or copied, and there is no multi-select. To move a whole tree, archive it on one side first (tar czf site.tgz site/), copy the archive, and unpack it on the other side.

    Rename, delete and create folders

    • Rename: Rename on the toolbar, Rename on the right-click menu, or click a selected row a second time (slowly, like Explorer or Finder) to edit its name in place. Enter saves, Esc cancels.
    • Delete: Delete on the toolbar or menu, after a confirmation. Deleting a remote folder only works once it is empty.
    • New folder: the New remote folder and New local folder buttons in each pane's header, or New Folder on the right-click menu.

    The full right-click menu is Open, Open With…, Copy to Local, Copy to Remote, Rename, Permissions…, New Folder, Refresh and Delete. Open With… downloads a remote file into the current local folder and then shows the operating system's own app chooser; it is available on Windows only.

    Change permissions

    1. Select a remote file or folder and click Permissions on the toolbar, or right-click it and choose Permissions….

    2. In Set permissions, type the Octal mode, for example 644 for a normal file, 755 for a folder or script, 600 for something private. The line below it previews the result as rwx letters.

    3. Click Apply.

    Ownership cannot be changed from here. Use chown in the terminal for that.

    Edit a remote file

    Double-click a remote text file (or select it and press Enter) to open it in the built-in editor, with syntax highlighting and line numbers. The title bar shows ● unsaved once you change something. Save with Save or Ctrl+S (Cmd+S on a Mac); closing with unsaved changes asks first.

    The editor opens UTF-8 text files up to 4 MB. For anything larger, or a file MangoSSH recognises as binary, download it and edit it locally instead. Double-clicking a local file opens it in its default app.

    Saving never leaves a half-written file

    MangoSSH writes the new content to a temporary file next to the original, copies the original's permission bits onto it, then swaps it into place. If the connection drops while you save sshd_config over the very link it controls, the file holds either the old content or the new, never a truncated mix. Because of that temporary file, saving needs write permission on the folder, not just the file.

    Quick SFTP: files without a saved host

    1. Click SFTP on the main toolbar (tooltip Quick SFTP client).

    2. Enter Host, Port (22 by default), User and Password, then Connect.

    3. Work in the same two-pane layout as above: drag between panes, the upload and download buttons, rename, permissions, delete, the right-click menu and the editor all behave the same way.

    Each Connect opens a new tab above the panes, so you can keep several servers open and switch between them. Disconnect closes the current one.

    Quick SFTP is deliberately light. It signs in with a password only, so use a saved host (and the browser above) for key, certificate or MFA logins. It trusts a server's host key the first time without asking. If the key later changes, it refuses to connect. When you know why the key changed, right-click a saved host with that address, choose Properties…, and click Forget Host Key.

    FTP

    1. Open Tools → FTP.

    2. Enter Host, Port (21), User and Password. Leave Passive (PASV) on unless the server needs active mode.

    3. Click Connect. Transfer with Upload and Download or by dragging between the panes. The remote pane also has New folder and Delete selected.

    Transfers run in binary mode, so files arrive byte for byte. There is no rename, permissions or right-click menu on FTP.

    FTP is not encrypted

    This is plain FTP. Your password and every file cross the network in clear text. Use it only on a network you trust, or for a device that offers nothing else. If the server also runs SSH, use Quick SFTP instead.

    TFTP server and client

    Open Tools → TFTP. The page has three cards: a server, a client and an activity log.

    To serve files (a switch pulling firmware, a phone fetching its config):

    1. Set Root directory (files served from here) with Browse…, and the Port (69 is the standard).

    2. Tick Allow incoming writes (PUT) only if devices need to send files to you, such as a config backup.

    3. Tick Run TFTP server. The status changes from Stopped, and Reachable at lists this machine's addresses to give the device.

    Clients can only reach files inside the root folder. Paths that try to climb out of it, and Windows device names such as CON or NUL, are refused.

    To fetch or push a file yourself, use the TFTP Client card: enter the Server (IP or hostname) and Port, choose GET (Download) or PUT (Upload), fill in Remote file (on server) and Local file, then click Start Transfer.

    Every transfer in either direction lands in the Activity log with time, peer, direction, file, bytes and status. Clear empties it.

    TFTP has no login and no encryption: anyone who can reach the port can read the root folder, and write to it if writes are allowed. Run the server only while you need it, and point it at a folder that holds nothing else.

    Compare files and folders

    Open Tools → Compare. Two modes sit at the top of the page.

    Local ⇄ Local compares two paths on this machine.

    1. Fill LEFT and RIGHT with two files or two folders, typed or picked with File… and Folder…. Swap exchanges them.

    2. Click Compare. Files show side by side with the differences highlighted. Prev and Next (or the ↑ and ↓ keys) jump between differences, and the two arrow buttons copy the current difference from one side to the other.

    3. To fix a file by hand, use Edit Inline to type over lines in the diff, or Pop Edit for the full editor, then Save that side.

    A folder compare lists every file with its status: changed, only on the left, or only on the right. Double-click a changed file to open its diff, and Back to folder results to return. Text files up to 4 MB get a line-by-line diff; larger or binary files are compared byte for byte and reported as same or different. The + tab opens another compare alongside the first.

    Across Hosts (SSH) compares a path on one machine with a path on another, for example a config on staging against production.

    1. For each side, choose Local or Remote host. A remote side picks one of your saved SSH hosts.

    2. Enter the path, set Mode to Folder (recursive) or Single file, and click Compare.

    3. Open any changed file for a read-only, side-by-side diff.

    Remote sides are hashed on the server over SSH, so a folder with thousands of files is not downloaded to compare it. Only the file you open a diff on is fetched. Linux and macOS targets use sha256sum or shasum; Windows targets use PowerShell, and MangoSSH detects which. This mode signs in with the host's saved password, or asks for one, so it does not work for hosts that only accept keys. Cross-host diffs cannot be edited in place.

    When SFTP is blocked

    File transfer can be switched off for a host, and then every SFTP action on it (browsing, uploads, downloads, editing, rename, permissions, and file steps in runbooks) fails with “File transfer is blocked for this host by a policy or the host's own settings.”

    • Per host: in the host's form, Session → Data-copy controls → Block file transfer (SFTP) on this host.
    • For a group of hosts: the Block file transfer (SFTP) rule in a policy. When two policies disagree, the blocking one wins.

    This is enforced by MangoSSH, not by the server. Someone with the host's password can still use another SFTP client. When the credential itself must stay out of people's hands, use the PAM Broker.

    Uploads, downloads, renames and deletes in the SSH browser are written to the audit log with the host, user and path.

    Troubleshooting

    SymptomLikely cause
    “SFTP subsystem request failed”The server has no SFTP subsystem enabled. Check the Subsystem sftp line in sshd_config.
    “looks like a binary file” when opening a fileThe editor only opens text. Use Copy to Local, or Open With… on Windows.
    “File is larger than … bytes”The editor stops at 4 MB. Download the file and edit it locally.
    Save fails with permission denied, but the file is writableSaving writes a temporary file in the same folder. You need write permission on the folder too.
    A name.mangossh-bak file appearsA save was interrupted during the swap. It holds the previous content; compare it with the file and delete whichever you do not need.
    Deleting a remote folder failsIt is not empty. Delete its contents first, or run rm -r in the terminal.
    FTP connects but the remote list is emptyMangoSSH reads Unix-style (ls -l) listings and skips lines in other formats. Set the server to Unix listing style, or try toggling Passive (PASV) if the server is behind NAT.
    Quick SFTP: “Host key mismatch”The server's key changed since the first connection. If you know why, use Forget Host Key in a saved host's Properties…, then connect again.
    A device cannot reach the TFTP serverA firewall on this machine is blocking UDP. On Linux, a port below 1024 may also need elevated rights; use a higher port on both ends if the server will not start.