scp Command in Linux: Secure File Transfer Examples

By 

•

Updated on

•

10 min read

Use SCP Command to Securely Transfer Files

When you need to copy files to or from a remote server over SSH, scp does the job with a single command. It encrypts both the transferred data and the authentication credentials, so nothing extra is needed if SSH access is already in place.

This guide explains how to use the scp command with practical examples and detailed explanations of the most common options.

Before You Begin

Before using scp, keep the following in mind:

  • SCP relies on SSH for data transfer. You need either an SSH key or a password to authenticate on the remote system.
  • The colon (:) is how scp distinguishes between local and remote paths. A path without a colon is treated as local.
  • You must have read permission on the source and write permission on the destination.
  • SCP overwrites files without warning when the source and destination share the same name.
  • When transferring large files, run the scp command inside a screen or tmux session to keep the transfer running if your terminal disconnects.

SCP Command Syntax

The general syntax of the scp command is:

txt
scp [OPTIONS] [[user@]host:]source [[user@]host:]destination
  • [[user@]host:]source - Source path. Include the username and hostname (or IP address) when the file is on a remote machine.
  • [[user@]host:]destination - Destination path. Same format as the source.

Local paths can be absolute or relative. Remote paths must include the host and colon.

The most commonly used scp options are:

  • -P - Remote host SSH port (uppercase P)
  • -p - Preserve modification time, access time, and mode
  • -r - Copy directories recursively
  • -C - Compress data during transfer
  • -q - Suppress the progress meter and non-error messages
  • -v - Print debugging messages about the connection and authentication process
  • -i - Path to the SSH private key (identity file)
  • -l - Limit bandwidth in Kbit/s
  • -o - Pass an SSH option (e.g., -o ConnectTimeout=10)
  • -3 - Route traffic between two remote hosts through the local machine, which has been the default since OpenSSH 8.7
  • -R - Copy directly between two remote hosts instead of through the local machine
  • -O - Force the legacy SCP protocol instead of SFTP

Copy a Local File to a Remote System

To copy a file from the local machine to a remote server, run:

Terminal
scp file.txt remote_username@10.10.0.2:/remote/directory

In this example, file.txt is the local file, remote_username is the user on the remote server, and 10.10.0.2 is the server IP address. The file is copied to /remote/directory on the remote host. If you omit the remote directory, the file is copied to the remote user’s home directory.

You will be prompted to enter the user password, and the transfer process will start:

output
remote_username@10.10.0.2's password:
file.txt                             100%   14KB  82.1KB/s   00:00

To save the file under a different name on the remote host, specify the new filename in the destination path:

Terminal
scp file.txt remote_username@10.10.0.2:/remote/directory/newfilename.txt

If SSH on the remote host is listening on a port other than the default 22, use the -P option:

Terminal
scp -P 2322 file.txt remote_username@10.10.0.2:/remote/directory

To copy a directory and all its contents, use the -r flag for recursive copy:

Terminal
scp -r /local/directory remote_username@10.10.0.2:/remote/directory

To copy several files in one command, list them all before the destination:

Terminal
scp file1.txt file2.txt notes.md remote_username@10.10.0.2:/remote/directory/

When you want to copy multiple local files that match a pattern, let the local shell expand the wildcard before scp runs. In the following example, all .txt files from the local Projects directory are copied to the remote Projects directory:

Terminal
scp "$HOME"/Projects/*.txt remote_username@10.10.0.2:/home/user/Projects/

To preserve file metadata (modification time, access time, and mode), use the -p option:

Terminal
scp -p file.txt remote_username@10.10.0.2:/remote/directory/

To use a specific SSH key for authentication, pass it with the -i option:

Terminal
scp -i ~/.ssh/id_ed25519 file.txt remote_username@10.10.0.2:/remote/directory/

Copy a Remote File to the Local System

To copy a file from a remote server to the local machine, use the remote location as the source and the local path as the destination:

Terminal
scp remote_username@10.10.0.2:/remote/file.txt /local/directory

If you have not set up passwordless SSH login , you will be prompted to enter the user password, and the download starts:

output
remote_username@10.10.0.2's password:
file.txt                             100%   14KB  91.4KB/s   00:00

The progress line reports the same fields as an upload. The 100% confirms that the whole file arrived, and the 00:00 at the end is the elapsed time rather than an estimate of the time left.

When you want the file in the directory you are already working in, use a single dot as the destination:

Terminal
scp remote_username@10.10.0.2:/remote/file.txt .

To save the downloaded file under a different name, end the destination with a filename instead of a directory:

Terminal
scp remote_username@10.10.0.2:/remote/file.txt ./report-backup.txt

To copy an entire remote directory, add the -r flag:

Terminal
scp -r remote_username@10.10.0.2:/remote/directory /local/directory

Downloading files that match a pattern works differently from uploading them. The wildcard has to reach scp unchanged, so quote the whole remote path. Without the quotes, your local shell tries to match the pattern against local files first. With the default SFTP protocol, the local scp client reads the remote directory and matches the filenames itself:

Terminal
scp remote_username@10.10.0.2:'/var/log/*.log' /local/directory

Escaping the asterisk with a backslash has the same effect:

Terminal
scp remote_username@10.10.0.2:/var/log/\*.log /local/directory

When you add -O, the legacy SCP protocol sends the pattern to the remote shell for expansion. In that mode, scp checks the received filenames against the requested pattern. Differences between shells can cause a wanted file to be rejected. The -T option disables this legacy-protocol check at the cost of trusting the server to send only the requested files. It does not affect the default SFTP matching behavior.

Copy Files Between Two Remote Systems

With scp, you do not need to log in to either server to transfer files between two remote machines. The following command copies /files/file.txt from host1.com to the /files directory on host2.com:

Terminal
scp user1@host1.com:/files/file.txt user2@host2.com:/files

Since OpenSSH 8.7, the data is routed through your local machine by default, which means neither server sees credentials for the other one. OpenSSH 9.0 and later use SFTP by default and can prompt for both remote accounts. The -3 option requests local routing explicitly and is what older releases required:

Terminal
scp -3 user1@host1.com:/files/file.txt user2@host2.com:/files

OpenSSH 8.7 and 8.8 use the legacy SCP protocol by default. In legacy local-routing mode, the second connection cannot prompt for a password or passphrase, so it must authenticate non-interactively, usually with an SSH key. The same restriction applies when you combine -3 with -O on a newer release.

To send the data directly between the two remote hosts instead, use the -R option. It connects to the source host and runs scp there, so the source host must be able to authenticate to the destination host on its own, without a password prompt:

Terminal
scp -R user1@host1.com:/files/file.txt user2@host2.com:/files

Using a Custom SSH Port

When the remote SSH daemon does not listen on port 22, scp needs the port on the command line. The option is an uppercase -P, which trips people up regularly, because ssh uses a lowercase -p for the same job and scp has already given the lowercase -p to preserving file metadata:

Terminal
scp -P 2222 backup.sql remote_username@10.10.0.2:/tmp/

The option goes in the same place when you are downloading:

Terminal
scp -P 2222 remote_username@10.10.0.2:/remote/file.txt /local/directory

A single -P applies to every connection the command opens, so a copy between two remote hosts that both listen on 2222 needs the option only once:

Terminal
scp -P 2222 user1@host1.com:/files/file.txt user2@host2.com:/files

When the two hosts listen on different ports, drop -P and write each side as a URI, since that form carries a port of its own:

Terminal
scp scp://user1@host1.com:2322/files/file.txt scp://user2@host2.com:2244/files

If you reach the same non-standard port often, set it once in the SSH config file described in the next section and leave -P off the command line entirely.

Using an SSH Config File

If you regularly connect to the same hosts, defining them in the SSH config file simplifies your scp commands. Create or edit the file at ~/.ssh/config:

~/.ssh/configssh
Host myserver
    HostName 10.10.0.2
    User leah
    Port 2222
    IdentityFile ~/.ssh/id_ed25519

With this configuration, you can use the alias instead of the full connection details:

Terminal
scp file.txt myserver:/remote/directory

Setting up SSH key-based authentication removes the password prompt entirely, making transfers faster and easier to script.

Troubleshooting

Permission denied (publickey)
The remote server does not accept your SSH key. Verify that the correct key is offered with -i, or check that the public key is in the remote user’s ~/.ssh/authorized_keys file.

Connection refused
The SSH daemon is not running or is listening on a different port. Confirm the port with -P and ensure the firewall allows SSH traffic.

Not a regular file
You are trying to copy a directory without the -r flag. Add -r to copy directories recursively.

Host key verification failed
The remote host key does not match the entry in ~/.ssh/known_hosts. This can happen after a server reinstall, but it can also indicate server spoofing. Verify the new fingerprint with the server administrator through a trusted channel. If the change is expected, remove the old key with ssh-keygen -R hostname and try again.

Transfer is slow
Enable compression with -C to speed up transfers over slow connections. You can also limit bandwidth with -l to avoid saturating the link on shared networks.

Cannot expand a path such as host:~user/file
The SFTP protocol has no native way to expand another user’s home directory. OpenSSH 8.7 and later ship an expand-path@openssh.com server extension that handles it, so this fails only against older SFTP servers. Write the path out in full, or add -O to fall back to the legacy protocol.

Transfer fails without a clear reason
Run the same command with -v to print the connection, authentication, and configuration steps that scp hands to SSH. Add -vv or -vvv for more detail.

Quick Reference

For a printable quick reference, see the scp cheatsheet .

CommandDescription
scp file.txt user@host:/pathCopy local file to remote
scp file1 file2 user@host:/pathCopy several local files at once
scp user@host:/path/file.txt .Copy remote file to the current directory
scp user@host:/path/file.txt ./new-name.txtCopy remote file and rename it
scp user@host:'/path/*.log' .Copy matching remote files (quote the pattern)
scp -r dir/ user@host:/pathCopy directory recursively
scp -P 2222 file.txt user@host:/pathUse custom SSH port
scp -i ~/.ssh/key file.txt user@host:/pathUse specific SSH key
scp -p file.txt user@host:/pathPreserve timestamps and mode
scp -C file.txt user@host:/pathCompress during transfer
scp -l 5000 file.txt user@host:/pathLimit bandwidth to 5000 Kbit/s
scp -v file.txt user@host:/pathPrint SSH debugging output
scp -R user1@host1:/f user2@host2:/fCopy directly between two remotes
scp -O file.txt user@host:/pathForce legacy SCP protocol

FAQ

Does scp overwrite existing files?
Yes. SCP overwrites destination files without prompting. There is no built-in confirmation flag, so verify the destination path before running the command.

What is the difference between scp and sftp?
Both use SSH for encryption. SFTP is an interactive file transfer protocol that supports resuming transfers, directory listings, and file removal. SCP is a simpler one-shot copy command. Modern OpenSSH versions run the SFTP protocol internally when you use scp.

Is scp still recommended?
The scp command is still widely available and works the same way from the user’s perspective. Starting with OpenSSH 9.0, it uses the SFTP protocol internally rather than the legacy SCP/RCP protocol. For new scripts or automation, sftp or rsync may be a better long-term choice.

Can I resume an interrupted scp transfer?
No. SCP does not support resuming partial transfers. If the connection drops, you must start the transfer over. For resumable transfers, use rsync with the --partial flag.

How do I copy files without a password prompt?
Set up SSH key-based authentication between the local and remote machines. Once the public key is installed on the remote host, SCP authenticates automatically.

What does the -O flag do?
The -O flag forces scp to use the legacy SCP/RCP protocol instead of the SFTP protocol. It helps in three cases: the remote server does not implement SFTP at all, a filename wildcard pattern behaves differently under SFTP, or a path with a ~ prefix needs expanding on an older SFTP server.

Conclusion

SCP is a straightforward tool for copying files between local and remote systems over SSH. While modern OpenSSH versions now use the SFTP protocol internally, the scp command remains widely available and works the same way from the user’s perspective.

For advanced workflows, use rsync for resumable transfers and large directory trees, or follow the --link-dest backup guide to create dated incremental snapshots. For interactive file management over SSH, use sftp .

Linuxize Weekly Newsletter

A quick weekly roundup of new tutorials, news, and tips.

About the authors

Dejan Panovski

Dejan Panovski

Dejan Panovski is the founder of Linuxize, an RHCSA-certified Linux system administrator and DevOps engineer based in Skopje, Macedonia. Author of 1000+ Linux tutorials with 20+ years of experience turning complex Linux tasks into clear, reliable guides.

View author page