Hosting Cost
Advanced Server & Infrastructure Concepts

What Is SSH?

Marcus Feld, Infrastructure Editor
Marcus Feld

Infrastructure Editor

Disclosure: Some links on this page are affiliate links — if you sign up through one, we may earn a commission at no extra cost to you. It never changes our ratings, rankings or verdicts: we don't sell hosting and take no pay-for-placement.

Who it's for

  • Developers setting up a VPS for the first time
  • Site owners deciding between shared and self-managed hosting
  • Anyone who's seen 'SSH access included' on a hosting plan and wants to know what it means

By Marcus Feld, Infrastructure Editor (former data-center systems engineer)

What Is SSH?

SSH, short for Secure Shell, is an encrypted network protocol that lets someone log into a remote server’s command line from their own computer, as if they were sitting directly at the machine. Every command typed and every response returned travels over an encrypted connection, which is why SSH became the standard way to administer servers over the open internet.

Its Role in the Server Infrastructure Stack

SSH is the access layer of server infrastructure. It doesn’t serve websites or store files itself, but it’s how administrators reach every other layer: installing web server software, configuring the operating system, managing databases, and troubleshooting problems that a control panel can’t fix. On a VPS or dedicated server, SSH is typically the only way to get true command-line control.

a phone held up photographing a monitor showing a dark terminal window with a command prompt and scrolling lines, a keyboard in the foregrou

How SSH Works: Key Pairs and Encrypted Login

A customer opens a terminal application and runs a command referencing the server’s IP address. They authenticate either with a password or, more securely, an SSH key pair — a private key kept on the customer’s computer and a matching public key placed on the server. Once authenticated, every keystroke sent and every line of output returned is encrypted, preventing anyone intercepting the connection from reading commands or passwords in transit.

Alternatives to SSH: Telnet and Web-Based Control Panels

  • Telnet — SSH’s unencrypted predecessor; essentially obsolete for anything internet-facing because it transmits plain text, including passwords.
  • Web-based control panels — cPanel, Plesk, and similar tools offer a graphical way to manage a server without touching the command line, but they don’t provide the same low-level control SSH does.
  • Remote desktop protocols (RDP) — the Windows Server equivalent for graphical remote access, distinct from SSH’s command-line approach.

Trade-Offs

SSH gives precise, scriptable control over every part of a server, but that power comes with responsibility. A misconfigured SSH setup (weak passwords, exposed default ports, outdated software) is one of the most common attack vectors against self-managed servers. Hardening SSH access — disabling password login in favor of keys, changing the default port, restricting login by IP — is a standard part of any secure hosting account checklist, and works alongside correct file permissions to limit what an attacker can do even if they gain access.

a mini home server with blinking LEDs, a router and a USB cable on a shelf, glowing in a dark room

Which Hosting Types Include SSH: VPS, Dedicated, and Root Access

Root access and SSH go hand in hand: VPS hosting and dedicated hosting plans almost always include SSH access as standard, since customers on those plans are expected to manage their own server configuration. Shared hosting plans rarely offer full SSH access — customers there work through a control panel instead, because the server is shared across many accounts and unrestricted command-line access isn’t safe to hand out. Managed hosting plans sometimes include SSH access but reserve deeper system changes for the provider’s support team.

A Concrete Example

A developer needs to install a specific version of Node.js on their VPS to run a custom application, something no control panel button exists for. They open a terminal, connect over SSH using their private key, and run the installation commands directly against the server’s operating system: downloading packages, configuring environment variables, restarting services. Every one of those actions happens through the same encrypted SSH session, and none of it would be possible through a shared-hosting control panel, which deliberately doesn’t expose that level of access.

a rainy window by a desk lamp with a notebook and a pen, grey calm evening light

Common Misconception

People sometimes assume SSH access is inherently risky and best avoided. The risk isn’t SSH itself, it’s leaving it configured with weak defaults. A correctly hardened SSH setup (key-based login only, non-default port, fail2ban or similar login-attempt limiting) is significantly more secure than many of the alternatives it replaces, precisely because every session is encrypted end to end. The danger comes from treating SSH access casually: reusing weak passwords, ignoring failed-login alerts, or leaving default configurations untouched on an internet-facing server.

FAQ

Do I need SSH access for a normal WordPress site? No. Most WordPress site owners never touch SSH — hosting providers and plugins handle server-level tasks. SSH matters when doing custom development, server tuning, or troubleshooting beyond what a control panel exposes.

Is SSH the same as FTP? No. FTP transfers files; SSH gives full command-line control over the server itself. SFTP (SSH File Transfer Protocol) uses the same encrypted connection as SSH but is specifically for file transfer.

Is SSH access safe to enable? Yes, when configured correctly — key-based authentication, a non-default port, and restricted login attempts make SSH significantly safer than leaving default password-based access open.

Why don’t shared hosting plans include SSH? Because many customers share one server, unrestricted command-line access for everyone would create serious security and stability risks. Providers restrict access to a control panel instead.