Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Use scp [options] source ... target to copy files between your computer and a remote host over SSH. A local path appears by itself; a remote path has the form user@host:path. For example, scp ./report.txt [email protected]:/srv/incoming/ uploads a local file. This guide covers the 16 command patterns developers use most, including directories, keys, ports, jump hosts, remote-to-remote copies, compatibility, and troubleshooting.
Examples assume an OpenSSH client, a reachable SSH server, permission to read the source and write the destination, and destination directories that already exist. The commands are illustrative and were not executed as part of this guide.
How scp works
scp is the OpenSSH secure-copy command. Its source and target operands can refer to local or remote paths, and authentication, encryption, host-key checking, and transport are provided by SSH. Since OpenSSH 9.0, scp uses the SFTP protocol for transfers by default; the command name and most familiar syntax remain unchanged. Request the older SCP protocol explicitly with -O when a legacy server or path behavior requires it.
Check your installed implementation with scp -V (where supported) and read the local manual with man scp. The OpenSSH manuals document OpenSSH behavior; third-party clients can differ.
#1 Best Overall
16 common scp commands
1. Upload one local file
scp ./report.txt [email protected]:/srv/incoming/
The local file is the source and the remote directory is the target. SSH prompts for Alice’s credentials unless keys or an agent provide authentication. If the target names a directory, the original filename is placed inside it.
2. Download one remote file
scp [email protected]:/srv/incoming/report.txt ./
This copies the remote file into the current local directory. Replace ./ with a local filename when you want to rename it, such as ./report-copy.txt.
3. Upload a directory tree
scp -r ./site [email protected]:/srv/www/
-r recursively copies directories. The OpenSSH manual notes that symbolic links encountered during traversal are followed, so review links before copying a tree that might leave the intended directory.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →4. Preserve file attributes
scp -p ./report.txt [email protected]:/srv/incoming/
Lowercase -p preserves modification time, access time, and file mode bits. It does not mean “port”; uppercase -P sets the SSH port.
5. Connect on a non-default port
scp -P 2222 ./report.txt [email protected]:/srv/incoming/
-P selects TCP port 2222 instead of the default SSH port. Port numbers are case-sensitive in the option spelling: -p and -P do different jobs.
6. Select a private key
scp -i ~/.ssh/work_key ./report.txt [email protected]:/srv/incoming/
-i selects the private identity file for public-key authentication. Protect the file permissions (normally readable only by your user), and ensure the matching public key is authorized on the server.
7. Reach an internal host through a jump host
scp -J bastion.example.com ./report.txt [email protected]:/srv/incoming/
-J enables ProxyJump. The SSH client connects through bastion.example.com to reach the internal destination. Multiple jump hosts can be comma-separated when your network requires more than one hop.
8. Limit bandwidth
scp -l 800 ./archive.tar [email protected]:/srv/incoming/
-l limits the transfer to 800 Kbit/s. This can prevent a large copy from consuming an entire shared link; the value is in kilobits per second, not kilobytes.
9. Request SSH compression
scp -C ./archive.tar [email protected]:/srv/incoming/
-C asks SSH to compress the stream. It may help compressible text over a constrained connection, while already-compressed archives, images, and video may see little benefit or extra CPU work. The manual does not promise a speed increase, so measure in your own environment.
10. Suppress progress and diagnostics
scp -q ./large-file.bin [email protected]:/srv/incoming/
-q disables the progress meter and warning or diagnostic messages described by the manual. Use it only in scripts or quiet logs; removing diagnostics makes failures harder to investigate.
11. Copy between two remote hosts through your local machine
scp -3 alice@host-a:/data/file bob@host-b:/backup/
-3 makes the local client relay the data. Your computer therefore carries the traffic and must authenticate to both hosts. This is useful when host A cannot directly reach host B, but it consumes local bandwidth and storage buffers.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall12. Combine recursion and attribute preservation
scp -p -r ./site [email protected]:/srv/www/
Options can be combined or written separately. Here, -r copies the tree and -p preserves source times, access times, and mode bits.
13. Request the legacy SCP protocol
scp -O ./report.txt [email protected]:/srv/incoming/
OpenSSH 9.0 and later use SFTP by default. -O explicitly selects the older SCP protocol. Try it when a server lacks SFTP support or when a legacy wildcard or tilde expansion behavior is required. Do not use it merely because the command is named scp; the default is normally the more compatible modern path.
14. Pass an SSH configuration option
scp -o ConnectTimeout=10 ./report.txt [email protected]:/srv/incoming/
-o accepts an option in ssh_config syntax. This example stops connection establishment after 10 seconds. Other SSH options, such as host-key policy or proxy settings, can be supplied the same way, subject to your organization’s security policy.
15. Make an ambiguous remote path explicit
scp [email protected]:/var/tmp/report.txt ./
A colon separates host from path. If a filename itself contains a colon, use an explicit absolute or relative path so scp does not mistake part of the name for a host separator. Shell quoting may also be necessary for spaces, wildcard characters, dollar signs, or other metacharacters; exact quoting rules depend on your shell and on whether SFTP or legacy SCP mode is selected.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →16. Copy directly between remote hosts
scp -R alice@host-a:/data/file bob@host-b:/backup/
-R asks the origin host to make the connection to the destination. The origin must authenticate to the destination without an interactive password, typically through an appropriate key and agent setup. This differs fundamentally from -3: with -3, your local computer carries the bytes; with -R, host A initiates the second connection. Network reachability and credential policy determine whether either mode works.
Choosing the right command pattern
| Need | Pattern | Important consideration |
|---|---|---|
| Local to remote, one file | scp file user@host:/dir/ |
Remote directory must be writable. |
| Remote to local, one file | scp user@host:/path/file ./ |
Local target must be writable. |
| Directory tree | scp -r directory user@host:/dir/ |
Traversal follows encountered symbolic links. |
| Preserve times and modes | -p |
Lowercase only; it is not the port flag. |
| Alternate SSH port | -P number |
Uppercase P. |
| Specific key | -i keyfile |
Matching public key must be authorized remotely. |
| Private network route | -J jump-host |
Jump host must be reachable and permitted. |
| Remote-to-remote via local | -3 |
Local machine relays traffic and authenticates to both. |
| Remote-to-remote from origin | -R |
Origin must connect to destination without a password prompt. |
| Legacy server/protocol | -O |
Use only when SFTP-default behavior is incompatible. |
Authentication, paths, and safety checks
- Verify the host. The first connection may ask you to accept a host key. Confirm its fingerprint through a trusted channel before accepting it.
- Quote local paths. Use shell quotes around names containing spaces or metacharacters, for example
scp './release notes.txt' [email protected]:/srv/incoming/. - Check both permissions. You need read permission on the source and write and execute permission on each destination directory component.
- Mind overwrites. A target filename can replace an existing file according to remote filesystem permissions. Choose a new target or inspect first when data loss matters.
- Use a dry planning step for trees. List the source with
findor your file manager, especially when symlinks could point outside the intended directory. - Prefer configuration for repeat jobs. A host entry in
~/.ssh/configcan hold the hostname, user, port, identity, and jump host, reducing long commands and typos.
Troubleshooting common failures
“Permission denied”
Confirm the remote username, the key selected with -i, and the server’s authorized-key configuration. Then verify source read permission and destination write permission. Run a plain ssh user@host test with the same port and identity before retrying scp.
“Connection timed out” or “No route to host”
Check DNS, firewall rules, VPN access, and the port. If the service uses 2222, add -P 2222. For an internal hostname, add the required -J jump host.
Rank #4
“Connection refused”
The host is reachable but no SSH service is accepting that port, or a firewall is actively rejecting it. Confirm the server’s listening port and whether the account is allowed to use SSH.
Recommended Free Tools
“No such file or directory”
Check spelling, case, and whether the remote path is absolute. A relative remote path is interpreted in the remote account’s context. Confirm the destination directory exists; scp does not create an entire missing directory tree for you.
Wildcards or tildes behave differently
OpenSSH 9.0’s SFTP default can change legacy SCP wildcard and tilde expectations. Quote patterns when you need the remote shell to receive them, or try -O for a server and workflow that specifically depends on legacy SCP expansion. Test against your installed version rather than assuming another implementation behaves identically.
Remote-to-remote copy asks for an unexpected password
With -R, host A—not your laptop—must authenticate to host B. Install or forward a suitable key on host A and verify an interactive-free ssh bob@host-b from host A. With -3, authenticate to both hosts from your local client instead.
The transfer is too slow
Check whether -l accidentally imposed a low Kbit/s ceiling, whether compression is appropriate for the data, and whether the chosen remote-to-remote mode is forcing traffic through a slower machine. Avoid assuming -C always improves speed; its effect depends on data and connection conditions.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minutePerformance, reliability, and scripting notes
For repeatable automation, use explicit hostnames, identities, ports, and timeouts, and capture the exit status. Keep diagnostic output enabled until the workflow is stable; add -q only when a quiet log is genuinely useful. Large transfers should be protected by an appropriate retry strategy outside scp, because a dropped SSH session normally requires rerunning the command. Consider destination free space, local relay bandwidth for -3, and the origin-to-destination route for -R. The manuals define command behavior but do not provide a universal speed benchmark, so measure with your files and network.
Best Value
Or skip the browser setup
If your goal is an automated screenshot rather than file transfer, ScreenshotNeo provides a one-request website screenshot API. It removes cookie banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, with the response identifying the page verdict and billing status. Its MCP server includes take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients.
Use the ScreenshotNeo API documentation for options and authentication. A cURL request is:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python and Node.js equivalents:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots, and every feature is on every plan. Create a free ScreenshotNeo account.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Frequently Asked Questions
Is scp available on Windows?
Yes, current Windows installations can use the OpenSSH client from PowerShell or Windows Terminal; the exact package and key-file location depend on the Windows edition and how OpenSSH was installed.
Can scp resume an interrupted transfer?
The basic scp command does not provide a general resume workflow. A rerun may overwrite the destination; for restartable synchronization, evaluate a tool designed for that behavior and follow its documentation.
What does the colon in user@host:path mean?
It separates the remote host specification from the path. A path without that remote form is treated as local, which is why filenames containing colons need explicit handling.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

