SSH, SFTP and the Mac
What we had to work out while building a mounting app for macOS, written down properly. Exact errors, exact causes, and sources you can check.
sshmount.com collects what we have had to work out about SSH, SFTP and the way macOS treats files that are not on your Mac. It is written by OnePasswordManager Ltd, who make a paid macOS app called SSHMount. Nothing is sold here. The pages are the kind of thing we wanted to exist while building the app and mostly could not find: an exact error message with an exact cause, a manual page quoted rather than paraphrased, and a comparison that admits when somebody else's product is the better buy.
Where to start
-
SSH keys on macOS
The key files belong to OpenSSH, the Keychain belongs to Apple, and the agent sits between them. Which of the three is failing is most of the fix — including the two settings that explain why your Mac asks for the same passphrase forever.
-
SSH and SFTP errors
One page per exact message, with what the software is actually reporting. Permission denied (publickey) has three different causes that produce identical text, and host key verification failed is the one error where the standard fix is sometimes the wrong move.
-
macOS files on remote servers
Extended attributes, case sensitivity and filename encoding all change meaning at the boundary. Including the two different kinds of stray file a Mac leaves behind, and why the famous fix only ever covered one of them.
-
SFTP clients for Mac
Eight tools compared on how they feel to use daily, by people who make one of them and say so. Transmit, ForkLift, Cyberduck, Mountain Duck, CloudMounter, SSHive, rclone — with the cases where each of them wins.
What this site is, said plainly
sshmount.com is a vendor publication. We make SSHMount, and a site about the problems SSHMount addresses is obviously not disinterested. We think that is fine as long as it is stated and as long as the writing survives being read by someone who has no intention of buying anything — so the rule here is that every page has to solve the reader's problem on its own, using tools already on their Mac, whether or not our app is ever mentioned. Where we do mention it, it is disclosed in the same paragraph. Where a competitor is the better answer, the page says which one and why. The full editorial policy is here, including what we will not do: no invented ratings, no testimonials, no review counts, no prices we cannot stand behind.
Looking for the app, or for a different sshmount?
The SSHMount application — what it does, what it requires, what it costs — is documented on sshmount.it, which is a separate site. And if you arrived here searching for a command-line tool, there are several unrelated open-source projects with this name, including a Rust crate and a handful of shell scripts. This page links straight to each of them, because sending you to the thing you actually wanted is more useful than keeping you here.
How the pages are written
Claims are checked against primary sources and linked at the foot of each page: the manual pages Apple ships with macOS, the OpenSSH project's own release notes, and each vendor's own documentation. Quotations are exact. Where something is not published — a licence model a vendor does not state, a behaviour Apple has not documented — the page says so instead of filling the gap with a guess. Every article carries the date it was last checked, and that date comes from the content itself rather than from the last deployment, so a page that has not changed does not pretend to be fresh.