{
    "mode": "man",
    "parameter": "sftp-server",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/sftp-server/8/json",
    "generated": "2026-09-20T04:08:09Z",
    "synopsis": "sftp-server [-ehR] [-d startdirectory] [-f logfacility] [-l loglevel] [-P deniedrequests]\n[-p allowedrequests] [-u umask]\nsftp-server -Q protocolfeature",
    "sections": {
        "NAME": {
            "content": "sftp-server — OpenSSH SFTP server subsystem\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "sftp-server [-ehR] [-d startdirectory] [-f logfacility] [-l loglevel] [-P deniedrequests]\n[-p allowedrequests] [-u umask]\nsftp-server -Q protocolfeature\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "sftp-server  is  a program that speaks the server side of SFTP protocol to stdout and expects\nclient requests from stdin.  sftp-server is not intended to  be  called  directly,  but  from\nsshd(8) using the Subsystem option.\n\nCommand-line  flags  to  sftp-server  should  be specified in the Subsystem declaration.  See\nsshdconfig(5) for more information.\n\nValid options are:\n",
            "subsections": [
                {
                    "name": "-d _",
                    "content": "Specifies an alternate starting directory for users.  The pathname  may  contain  the\nfollowing tokens that are expanded at runtime: %% is replaced by a literal '%', %d is\nreplaced by the home directory of the user being authenticated, and %u is replaced by\nthe  username  of  that user.  The default is to use the user's home directory.  This\noption is useful in conjunction with the sshdconfig(5) ChrootDirectory option.\n",
                    "flag": "-d"
                },
                {
                    "name": "-e",
                    "content": "bugging.\n",
                    "flag": "-e"
                },
                {
                    "name": "-f _",
                    "content": "Specifies the facility code that is used when logging messages from sftp-server.  The\npossible  values are: DAEMON, USER, AUTH, LOCAL0, LOCAL1, LOCAL2, LOCAL3, LOCAL4, LO‐\nCAL5, LOCAL6, LOCAL7.  The default is AUTH.\n",
                    "flag": "-f"
                },
                {
                    "name": "-h",
                    "content": "",
                    "flag": "-h"
                },
                {
                    "name": "-l _",
                    "content": "Specifies which messages will be logged by sftp-server.   The  possible  values  are:\nQUIET, FATAL, ERROR, INFO, VERBOSE, DEBUG, DEBUG1, DEBUG2, and DEBUG3.  INFO and VER‐\nBOSE  log  transactions that sftp-server performs on behalf of the client.  DEBUG and\nDEBUG1 are equivalent.  DEBUG2 and DEBUG3 each specify  higher  levels  of  debugging\noutput.  The default is ERROR.\n",
                    "flag": "-l"
                },
                {
                    "name": "-P _",
                    "content": "Specifies  a  comma-separated  list  of SFTP protocol requests that are banned by the\nserver.  sftp-server will reply to any denied request with a failure.   The  -Q  flag\ncan  be  used  to  determine the supported request types.  If both denied and allowed\nlists are specified, then the denied list is applied before the allowed list.\n",
                    "flag": "-P"
                },
                {
                    "name": "-p _",
                    "content": "Specifies a comma-separated list of SFTP protocol requests that are permitted by  the\nserver.   All  request  types  that  are  not  on the allowed list will be logged and\nreplied to with a failure message.\n\nCare must be taken when using this feature to ensure that requests made implicitly by\nSFTP clients are permitted.\n",
                    "flag": "-p"
                },
                {
                    "name": "-Q _",
                    "content": "Queries protocol features supported by sftp-server.  At present the only feature that\nmay be queried is “requests”, which may be used to deny or  allow  specific  requests\n(flags -P and -p respectively).\n",
                    "flag": "-Q"
                },
                {
                    "name": "-R",
                    "content": "for writing, as well as other operations that change the  state  of  the  filesystem,\nwill be denied.\n",
                    "flag": "-R"
                },
                {
                    "name": "-u _",
                    "content": "Sets  an  explicit umask(2) to be applied to newly-created files and directories, in‐\nstead of the user's default mask.\n\nOn some systems, sftp-server must be able to access /dev/log for logging to work, and use  of\nsftp-server  in a chroot configuration therefore requires that syslogd(8) establish a logging\nsocket inside the chroot directory.\n",
                    "flag": "-u"
                }
            ]
        },
        "SEE ALSO": {
            "content": "sftp(1), ssh(1), sshdconfig(5), sshd(8)\n\nT. Ylonen and S. Lehtinen,  SSH  File  Transfer  Protocol,  draft-ietf-secsh-filexfer-02.txt,\nOctober 2001, work in progress material.\n",
            "subsections": []
        },
        "HISTORY": {
            "content": "sftp-server first appeared in OpenBSD 2.8.\n",
            "subsections": []
        },
        "AUTHORS": {
            "content": "Markus Friedl <markus@openbsd.org>\n\nDebian                                      July 27, 2021                             SFTP-SERVER(8)",
            "subsections": []
        }
    },
    "summary": "sftp-server — OpenSSH SFTP server subsystem",
    "flags": [
        {
            "flag": "-d",
            "long": null,
            "arg": null,
            "description": "Specifies an alternate starting directory for users. The pathname may contain the following tokens that are expanded at runtime: %% is replaced by a literal '%', %d is replaced by the home directory of the user being authenticated, and %u is replaced by the username of that user. The default is to use the user's home directory. This option is useful in conjunction with the sshdconfig(5) ChrootDirectory option."
        },
        {
            "flag": "-e",
            "long": null,
            "arg": null,
            "description": "bugging."
        },
        {
            "flag": "-f",
            "long": null,
            "arg": null,
            "description": "Specifies the facility code that is used when logging messages from sftp-server. The possible values are: DAEMON, USER, AUTH, LOCAL0, LOCAL1, LOCAL2, LOCAL3, LOCAL4, LO‐ CAL5, LOCAL6, LOCAL7. The default is AUTH."
        },
        {
            "flag": "-h",
            "long": null,
            "arg": null,
            "description": ""
        },
        {
            "flag": "-l",
            "long": null,
            "arg": null,
            "description": "Specifies which messages will be logged by sftp-server. The possible values are: QUIET, FATAL, ERROR, INFO, VERBOSE, DEBUG, DEBUG1, DEBUG2, and DEBUG3. INFO and VER‐ BOSE log transactions that sftp-server performs on behalf of the client. DEBUG and DEBUG1 are equivalent. DEBUG2 and DEBUG3 each specify higher levels of debugging output. The default is ERROR."
        },
        {
            "flag": "-P",
            "long": null,
            "arg": null,
            "description": "Specifies a comma-separated list of SFTP protocol requests that are banned by the server. sftp-server will reply to any denied request with a failure. The -Q flag can be used to determine the supported request types. If both denied and allowed lists are specified, then the denied list is applied before the allowed list."
        },
        {
            "flag": "-p",
            "long": null,
            "arg": null,
            "description": "Specifies a comma-separated list of SFTP protocol requests that are permitted by the server. All request types that are not on the allowed list will be logged and replied to with a failure message. Care must be taken when using this feature to ensure that requests made implicitly by SFTP clients are permitted."
        },
        {
            "flag": "-Q",
            "long": null,
            "arg": null,
            "description": "Queries protocol features supported by sftp-server. At present the only feature that may be queried is “requests”, which may be used to deny or allow specific requests (flags -P and -p respectively)."
        },
        {
            "flag": "-R",
            "long": null,
            "arg": null,
            "description": "for writing, as well as other operations that change the state of the filesystem, will be denied."
        },
        {
            "flag": "-u",
            "long": null,
            "arg": null,
            "description": "Sets an explicit umask(2) to be applied to newly-created files and directories, in‐ stead of the user's default mask. On some systems, sftp-server must be able to access /dev/log for logging to work, and use of sftp-server in a chroot configuration therefore requires that syslogd(8) establish a logging socket inside the chroot directory."
        }
    ],
    "examples": [],
    "see_also": [
        {
            "name": "sftp",
            "section": "1",
            "url": "https://www.chedong.com/phpMan.php/man/sftp/1/json"
        },
        {
            "name": "ssh",
            "section": "1",
            "url": "https://www.chedong.com/phpMan.php/man/ssh/1/json"
        },
        {
            "name": "sshdconfig",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/sshdconfig/5/json"
        },
        {
            "name": "sshd",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/sshd/8/json"
        }
    ]
}