scp Command in Linux: Secure File Transfer Examples

When you need to copy files to or from a remote server over SSH, scp does the job with a single command. It encrypts both the transferred data and the authentication credentials, so nothing extra is needed if SSH access is already in place.
This guide explains how to use the scp command with practical examples and detailed explanations of the most common options.
Before You Begin
Before using scp, keep the following in mind:
- SCP relies on SSH for data transfer. You need either an SSH key or a password to authenticate on the remote system.
- The colon (
:) is howscpdistinguishes between local and remote paths. A path without a colon is treated as local. - You must have read permission on the source and write permission on the destination.
- SCP overwrites files without warning when the source and destination share the same name.
- When transferring large files, run the
scpcommand inside ascreenortmuxsession to keep the transfer running if your terminal disconnects.
SCP Command Syntax
The general syntax of the scp command is:
scp [OPTIONS] [[user@]host:]source [[user@]host:]destination[[user@]host:]source- Source path. Include the username and hostname (or IP address) when the file is on a remote machine.[[user@]host:]destination- Destination path. Same format as the source.
Local paths can be absolute or relative. Remote paths must include the host and colon.
The most commonly used scp options are:
-P- Remote host SSH port (uppercase P)-p- Preserve modification time, access time, and mode-r- Copy directories recursively-C- Compress data during transfer-q- Suppress the progress meter and non-error messages-v- Print debugging messages about the connection and authentication process-i- Path to the SSH private key (identity file)-l- Limit bandwidth in Kbit/s-o- Pass an SSH option (e.g.,-o ConnectTimeout=10)-3- Route traffic between two remote hosts through the local machine, which has been the default since OpenSSH 8.7-R- Copy directly between two remote hosts instead of through the local machine-O- Force the legacy SCP protocol instead of SFTP
Copy a Local File to a Remote System
To copy a file from the local machine to a remote server, run:
scp file.txt remote_username@10.10.0.2:/remote/directoryIn this example, file.txt is the local file, remote_username is the user on the remote server, and 10.10.0.2 is the server IP address. The file is copied to /remote/directory on the remote host. If you omit the remote directory, the file is copied to the remote user’s home directory.
You will be prompted to enter the user password, and the transfer process will start:
remote_username@10.10.0.2's password:
file.txt 100% 14KB 82.1KB/s 00:00To save the file under a different name on the remote host, specify the new filename in the destination path:
scp file.txt remote_username@10.10.0.2:/remote/directory/newfilename.txtIf SSH on the remote host is listening on a port other than the default 22, use the -P option:
scp -P 2322 file.txt remote_username@10.10.0.2:/remote/directoryTo copy a directory and all its contents, use the -r flag for recursive copy:
scp -r /local/directory remote_username@10.10.0.2:/remote/directoryTo copy several files in one command, list them all before the destination:
scp file1.txt file2.txt notes.md remote_username@10.10.0.2:/remote/directory/When you want to copy multiple local files that match a pattern, let the local shell expand the wildcard before scp runs. In the following example, all .txt files from the local Projects directory are copied to the remote Projects directory:
scp "$HOME"/Projects/*.txt remote_username@10.10.0.2:/home/user/Projects/To preserve file metadata (modification time, access time, and mode), use the -p option:
scp -p file.txt remote_username@10.10.0.2:/remote/directory/To use a specific SSH key for authentication, pass it with the -i option:
scp -i ~/.ssh/id_ed25519 file.txt remote_username@10.10.0.2:/remote/directory/Copy a Remote File to the Local System
To copy a file from a remote server to the local machine, use the remote location as the source and the local path as the destination:
scp remote_username@10.10.0.2:/remote/file.txt /local/directoryIf you have not set up passwordless SSH login , you will be prompted to enter the user password, and the download starts:
remote_username@10.10.0.2's password:
file.txt 100% 14KB 91.4KB/s 00:00The progress line reports the same fields as an upload. The 100% confirms that the whole file arrived, and the 00:00 at the end is the elapsed time rather than an estimate of the time left.
When you want the file in the directory you are already working in, use a single dot as the destination:
scp remote_username@10.10.0.2:/remote/file.txt .To save the downloaded file under a different name, end the destination with a filename instead of a directory:
scp remote_username@10.10.0.2:/remote/file.txt ./report-backup.txtTo copy an entire remote directory, add the -r flag:
scp -r remote_username@10.10.0.2:/remote/directory /local/directoryDownloading files that match a pattern works differently from uploading them. The wildcard has to reach scp unchanged, so quote the whole remote path. Without the quotes, your local shell tries to match the pattern against local files first. With the default SFTP protocol, the local scp client reads the remote directory and matches the filenames itself:
scp remote_username@10.10.0.2:'/var/log/*.log' /local/directoryEscaping the asterisk with a backslash has the same effect:
scp remote_username@10.10.0.2:/var/log/\*.log /local/directoryWhen you add -O, the legacy SCP protocol sends the pattern to the remote shell for expansion. In that mode, scp checks the received filenames against the requested pattern. Differences between shells can cause a wanted file to be rejected. The -T option disables this legacy-protocol check at the cost of trusting the server to send only the requested files. It does not affect the default SFTP matching behavior.
Copy Files Between Two Remote Systems
With scp, you do not need to log in to either server to transfer files between two remote machines. The following command copies /files/file.txt from host1.com to the /files directory on host2.com:
scp user1@host1.com:/files/file.txt user2@host2.com:/filesSince OpenSSH 8.7, the data is routed through your local machine by default, which means neither server sees credentials for the other one. OpenSSH 9.0 and later use SFTP by default and can prompt for both remote accounts. The -3 option requests local routing explicitly and is what older releases required:
scp -3 user1@host1.com:/files/file.txt user2@host2.com:/filesOpenSSH 8.7 and 8.8 use the legacy SCP protocol by default. In legacy local-routing mode, the second connection cannot prompt for a password or passphrase, so it must authenticate non-interactively, usually with an SSH key. The same restriction applies when you combine -3 with -O on a newer release.
To send the data directly between the two remote hosts instead, use the -R option. It connects to the source host and runs scp there, so the source host must be able to authenticate to the destination host on its own, without a password prompt:
scp -R user1@host1.com:/files/file.txt user2@host2.com:/filesUsing a Custom SSH Port
When the remote SSH daemon does not listen on port 22, scp needs the port on the command line. The option is an uppercase -P, which trips people up regularly, because ssh uses a lowercase -p for the same job and scp has already given the lowercase -p to preserving file metadata:
scp -P 2222 backup.sql remote_username@10.10.0.2:/tmp/The option goes in the same place when you are downloading:
scp -P 2222 remote_username@10.10.0.2:/remote/file.txt /local/directoryA single -P applies to every connection the command opens, so a copy between two remote hosts that both listen on 2222 needs the option only once:
scp -P 2222 user1@host1.com:/files/file.txt user2@host2.com:/filesWhen the two hosts listen on different ports, drop -P and write each side as a URI, since that form carries a port of its own:
scp scp://user1@host1.com:2322/files/file.txt scp://user2@host2.com:2244/filesIf you reach the same non-standard port often, set it once in the SSH config file described in the next section and leave -P off the command line entirely.
Using an SSH Config File
If you regularly connect to the same hosts, defining them in the SSH config file
simplifies your scp commands. Create or edit the file at ~/.ssh/config:
Host myserver
HostName 10.10.0.2
User leah
Port 2222
IdentityFile ~/.ssh/id_ed25519With this configuration, you can use the alias instead of the full connection details:
scp file.txt myserver:/remote/directorySetting up SSH key-based authentication removes the password prompt entirely, making transfers faster and easier to script.
Troubleshooting
Permission denied (publickey)
The remote server does not accept your SSH key. Verify that the correct key is offered with -i, or check that the public key is in the remote user’s ~/.ssh/authorized_keys file.
Connection refused
The SSH daemon is not running or is listening on a different port. Confirm the port with -P and ensure the firewall allows SSH traffic.
Not a regular file
You are trying to copy a directory without the -r flag. Add -r to copy directories recursively.
Host key verification failed
The remote host key does not match the entry in ~/.ssh/known_hosts. This can happen after a server reinstall, but it can also indicate server spoofing. Verify the new fingerprint with the server administrator through a trusted channel. If the change is expected, remove the old key with ssh-keygen -R hostname and try again.
Transfer is slow
Enable compression with -C to speed up transfers over slow connections. You can also limit bandwidth with -l to avoid saturating the link on shared networks.
Cannot expand a path such as host:~user/file
The SFTP protocol has no native way to expand another user’s home directory. OpenSSH 8.7 and later ship an expand-path@openssh.com server extension that handles it, so this fails only against older SFTP servers. Write the path out in full, or add -O to fall back to the legacy protocol.
Transfer fails without a clear reason
Run the same command with -v to print the connection, authentication, and configuration steps that scp hands to SSH. Add -vv or -vvv for more detail.
Quick Reference
For a printable quick reference, see the scp cheatsheet .
| Command | Description |
|---|---|
scp file.txt user@host:/path | Copy local file to remote |
scp file1 file2 user@host:/path | Copy several local files at once |
scp user@host:/path/file.txt . | Copy remote file to the current directory |
scp user@host:/path/file.txt ./new-name.txt | Copy remote file and rename it |
scp user@host:'/path/*.log' . | Copy matching remote files (quote the pattern) |
scp -r dir/ user@host:/path | Copy directory recursively |
scp -P 2222 file.txt user@host:/path | Use custom SSH port |
scp -i ~/.ssh/key file.txt user@host:/path | Use specific SSH key |
scp -p file.txt user@host:/path | Preserve timestamps and mode |
scp -C file.txt user@host:/path | Compress during transfer |
scp -l 5000 file.txt user@host:/path | Limit bandwidth to 5000 Kbit/s |
scp -v file.txt user@host:/path | Print SSH debugging output |
scp -R user1@host1:/f user2@host2:/f | Copy directly between two remotes |
scp -O file.txt user@host:/path | Force legacy SCP protocol |
FAQ
Does scp overwrite existing files?
Yes. SCP overwrites destination files without prompting. There is no built-in confirmation flag, so verify the destination path before running the command.
What is the difference between scp and sftp?
Both use SSH for encryption. SFTP is an interactive file transfer protocol that supports resuming transfers, directory listings, and file removal. SCP is a simpler one-shot copy command. Modern OpenSSH versions run the SFTP protocol internally when you use scp.
Is scp still recommended?
The scp command is still widely available and works the same way from the user’s perspective. Starting with OpenSSH 9.0, it uses the SFTP protocol internally rather than the legacy SCP/RCP protocol. For new scripts or automation, sftp
or rsync
may be a better long-term choice.
Can I resume an interrupted scp transfer?
No. SCP does not support resuming partial transfers. If the connection drops, you must start the transfer over. For resumable transfers, use rsync
with the --partial flag.
How do I copy files without a password prompt?
Set up SSH key-based authentication
between the local and remote machines. Once the public key is installed on the remote host, SCP authenticates automatically.
What does the -O flag do?
The -O flag forces scp to use the legacy SCP/RCP protocol instead of the SFTP protocol. It helps in three cases: the remote server does not implement SFTP at all, a filename wildcard pattern behaves differently under SFTP, or a path with a ~ prefix needs expanding on an older SFTP server.
Conclusion
SCP is a straightforward tool for copying files between local and remote systems over SSH. While modern OpenSSH versions now use the SFTP protocol internally, the scp command remains widely available and works the same way from the user’s perspective.
For advanced workflows, use rsync
for resumable transfers and large directory trees, or follow the --link-dest backup guide
to create dated incremental snapshots. For interactive file management over SSH, use sftp
.
Tags
Linuxize Weekly Newsletter
A quick weekly roundup of new tutorials, news, and tips.
About the authors

Dejan Panovski
Dejan Panovski is the founder of Linuxize, an RHCSA-certified Linux system administrator and DevOps engineer based in Skopje, Macedonia. Author of 1000+ Linux tutorials with 20+ years of experience turning complex Linux tasks into clear, reliable guides.
View author page