Connect to AWS EC2 with SFTP and Upload Files From Your Browser

Amazon EC2 is raw cloud infrastructure: a Linux virtual server you reach over SSH, managed with key pairs and security groups rather than a control panel. There's no FTP server installed by default — you move files with SFTP over SSH on port 22. FilePort Pro runs in the browser, so with the right setup you can upload files to an EC2 instance straight from a web page — no software to install and no desktop client to configure.

Connect Now — access your EC2 instance

EC2 instances have no FTP server

An EC2 instance is plain infrastructure: you reach it over SSH, normally using the SSH key pair you selected when you launched it. Plain FTP — the FTP server software that shared hosts run — is not installed by default on EC2, including on Amazon Linux. If you wanted plain FTP you'd have to install and configure a server such as vsftpd yourself and open ports 21 and 20 in the security group. For most people that's unnecessary: SFTP is already part of the SSH connection, it's encrypted, and it uses the same port 22 that the default security group already allows for SSH. That makes SFTP the transfer path you'll actually use on EC2. (If you do set up a plain FTP server, FilePort Pro's online FTP client can connect to it once ports 21 and 20 are open.)

EC2's key-pair model and your .pem file

When you launch an EC2 instance, AWS asks for (or generates) an SSH key pair: AWS keeps the public key on the instance, and you download the matching private key (.pem) and keep it safe. That .pem is how you log in to the instance — over SSH, or in the browser-based EC2 Instance Connect session. The .pem lives where you saved it when you launched the instance (for example ~/Downloads/my-key.pem or ~/.ssh/my-key.pem); if you lose it, you can't recover it and you'd generate a new key pair for a fresh instance. AWS's own SFTP instructions use that .pem in a desktop client. The browser-based client here works differently — more on that below. When you launch an instance, only keep the .pem for the key pair you actually selected, and treat it like a password: never upload it to a website.

Passwords vs SSH keys on EC2

Here's the important, honest part. EC2 instances are set up to authenticate with an SSH key pair. FilePort Pro connects with a username and a password — it does not support SSH private keys in the browser, so your .pem is never uploaded to anyone. If your instance currently authenticates only with an SSH key, enable password authentication first (set a password for the AMI's default user with passwd, and make sure sshd allows PasswordAuthentication), then connect from the browser with your instance's public IPv4 address, that username, and the password. SFTP never sends your password in cleartext — the login happens inside the encrypted SSH session.

The key-based path keeps working too — if you prefer to use your .pem with a desktop client such as FileZilla, nothing stops you; that's the path AWS itself documents. FilePort Pro simply offers a password-based, in-browser alternative once password authentication is enabled.

Enable password authentication on your instance

To use FilePort Pro with an EC2 instance, password login needs to be allowed on the server. Here's the sequence:

  1. Open a shell on the instance — use EC2 Instance Connect from the EC2 console (this works without a key because it uses the browser session), or SSH in with your .pem from a terminal.
  2. Set a password for the AMI's default user — for example, sudo passwd ec2-user on Amazon Linux, or sudo passwd ubuntu on Ubuntu, then follow the prompts.
  3. Make sure sshd allows password authentication — check that PasswordAuthentication is set to yes in /etc/ssh/sshd_config (including any included config files — some images ship a drop-in file that disables it), and restart the SSH service after any change (for example sudo systemctl restart sshd on Amazon Linux).
  4. Test before you rely on it — log in over SSH or SFTP from a terminal with that username and password to confirm password auth works.

Make sure the security group allows SFTP

EC2 traffic is controlled by security groups, which act as a firewall at the instance level. By default, a security group allows all outbound traffic but blocks all inbound traffic — including SSH — until you add a rule. For SFTP to work, the instance's security group must allow inbound TCP on port 22. In the EC2 console, go to Instances → select your instance → Security tab → Security groups → the security group → Edit inbound rules, and confirm there's an SSH (TCP 22) rule open to the IP (or IP range) you'll connect from. Limiting it to your own IP is good practice for a server that lets you in over password login. If you ever install a plain FTP server, you'd need to add rules for ports 21 and 20 as well — SFTP avoids that because port 22 is already there.

Find your EC2 host, port, and username

In the EC2 console, go to Instances in the left menu. Your instance's card shows the Public IPv4 address and the Public IPv4 DNS name — either works as the hostname. The port is 22 by default. The username depends on the AMI: Amazon Linux images use ec2-user, Ubuntu images use ubuntu, Bitnami AMIs use bitnami, and others vary — check the AMI's documentation rather than guessing. You can copy the public IP and confirm the AMI right from the instance details page before you connect.

Connect to an EC2 instance from the browser

With password authentication enabled and port 22 open, connecting from the browser is quick — no desktop client to install. This page's web SFTP client runs right here in your browser:

  1. Open FilePort Pro — it lives in the browser, so there's nothing to install.
  2. Choose SFTP and enter your instance's public IPv4 address (or public IPv4 DNS) as the host, port 22, and the default username for your AMI.
  3. Enter the password you set on the instance, then click Connect.
  4. You land in the server's file list — browse folders with breadcrumbs, upload files by clicking or dragging them in, and download what you need, including whole folders as a ZIP archive.

That's the whole flow — from the EC2 console to your first upload, with nothing installed. Connect Now — upload to your EC2 instance

Common EC2 connection errors and fixes

A note on EC2 SFTP security

Because FilePort Pro relays your connection, your instance credentials pass through our server to reach yours — never "credentials never leave your browser." They're held in memory only for the active session, never stored, never logged, and the session ends when you disconnect or after about 15 minutes of inactivity. Your .pem never goes to a website. Password login on an internet-facing server deserves a little care: use a strong password, and consider limiting the security group's SSH rule to your own IP address. If key-based login matters more to you, keep using your key with a desktop client — both paths can coexist. See our security page for how FilePort Pro handles your credentials.

Frequently asked questions

Does AWS EC2 run an FTP server?

No, not by default. EC2 instances, including Amazon Linux, don't come with an FTP server installed. The standard way to move files is SFTP over SSH on port 22, which is encrypted and already part of the connection you use to log in. If you installed an FTP server yourself, you'd also need to open ports 21 and 20 in the security group — SFTP avoids that because port 22 is already allowed.

How do I SFTP to an EC2 instance?

SFTP uses the same SSH connection as your terminal: your instance's public IPv4 address (or public IPv4 DNS name), the default user for your AMI, and port 22. EC2 instances normally log in with the SSH key pair you chose at launch; FilePort Pro connects with a username and password, so enable password authentication on the instance first, then connect from the browser with the IP, that username, and the password.

What's the EC2 default SSH username?

It depends on the Amazon Machine Image (AMI). Amazon Linux and Amazon Linux 2 use ec2-user, Ubuntu images use ubuntu, Bitnami AMIs use bitnami, and other images vary. Check the AMI's documentation rather than guessing, and use the same username you use for SSH.

Can I upload files to EC2 without installing software?

Yes, once password authentication is enabled on the instance. FilePort Pro runs in the browser, so with your instance's public IPv4 address, the AMI's default username, and the password you set, you can connect and upload files straight from a web page — nothing to install.

Can I use FilePort Pro without uploading my SSH key?

Yes. FilePort Pro connects with a username and password, so you never upload your private key (.pem) to a website — which is exactly why password authentication must be enabled on the instance first. If your setup can't allow password logins, keep using your key pair with a desktop SFTP client instead.

More host guides

EC2 is infrastructure you manage yourself, which is different from shared hosting. AWS's simpler Lightsail product is very similar, and if your site is hosted with a managed provider instead, see the matching guide:

For more on browser-based transfers, see the web SFTP client. Questions about what we store? Read the privacy policy or the security page.

Get started — upload to EC2 from your browser

No install, no sign-up, no credentials stored. Connect Now — access your EC2 instance

Prefer an encrypted transfer? Use SFTP. Questions about what we store? Read the privacy policy.