Connect to AWS Lightsail with SFTP and Upload Files From Your Browser

AWS Lightsail is Amazon's simple-VPS product: a Linux instance you manage over SSH, without cPanel or a built-in file manager. There's no FTP server installed by default — you move files with SFTP over SSH on port 22. FilePort Pro runs in the browser, so with the right setup you can upload files to a Lightsail instance straight from a web page — no software to install and no desktop client to configure.

Connect Now — access your Lightsail instance

Lightsail instances have no FTP server

A Lightsail Linux instance is plain infrastructure: you reach it over SSH, normally using the SSH key pair Lightsail created for the instance. Plain FTP — the FTP server software that shared hosts run — is not installed by default. If you wanted plain FTP you'd have to install and configure a server such as vsftpd yourself and open ports 21 and 20 in the Lightsail firewall. For most people that's unnecessary: SFTP is already part of the SSH connection, it's encrypted, and it uses the same port 22 that the default firewall already allows. That makes SFTP the transfer path you'll actually use on Lightsail. (If you do set up a plain FTP server, FilePort Pro's online FTP client can connect to it once ports 21 and 20 are open.)

Passwords vs SSH keys on a Lightsail instance

Here's the important, honest part. Lightsail instances are set up to authenticate with an SSH key pair — the Lightsail console's own instructions for SFTP use the instance's private key (.pem) in a desktop client. When you create an instance, Lightsail offers to generate a default key pair (or reuse one you've already added) and lets you download the .pem; that key is stored in your AWS account and used by the console's SSH client. FilePort Pro connects with a username and a password — it does not support SSH private keys in the browser. If your Lightsail instance currently authenticates only with an SSH key, enable password authentication first (set a password for the image's default user with passwd, and make sure sshd allows PasswordAuthentication), then connect from the browser with your instance's public IP, that username, and the password. SFTP never sends your password in cleartext — the login happens inside the encrypted SSH session.

The key-based path keeps working too — if you prefer to use your instance's key with a desktop client such as FileZilla, nothing stops you; that's the path AWS itself documents. FilePort Pro simply offers a password-based, in-browser alternative once password authentication is enabled.

Enable password authentication on your instance

To use FilePort Pro with a Lightsail instance, password login needs to be allowed on the server. Here's the sequence:

  1. Open the browser SSH console from the instance's Connect tab in the Lightsail console — this works without a key because it uses the browser session.
  2. Set a password for the image's default user — run passwd while logged in as that user (for example, on an Ubuntu image, sudo passwd ubuntu) and follow the prompts.
  3. Make sure sshd allows password authentication — check that PasswordAuthentication is set to yes in the SSH server configuration, including any included config files (some images ship a drop-in file that disables it), and restart the SSH service after any change.
  4. Test before you rely on it — log in over SSH or SFTP from a terminal with that username and password to confirm password auth works.

Make sure the firewall allows SFTP

Lightsail's firewall is managed per instance under the Networking tab. The default rule set allows SSH on TCP 22 — which is exactly what SFTP needs — and blocks everything else. If you've removed or narrowed that rule, re-add it: confirm an SSH/TCP 22 rule is present and open to the network you'll connect from. If you ever install a plain FTP server, you'd need to add rules for ports 21 and 20 as well — SFTP avoids that because port 22 is already there.

Connect to a Lightsail instance from the browser

With password authentication enabled, connecting from the browser is quick — no desktop client to install. This page's web SFTP client runs right here in your browser:

  1. Open FilePort Pro — it lives in the browser, so there's nothing to install.
  2. Choose SFTP and enter your instance's public IP (or an attached Static IP) as the host, port 22, and the default username for your image.
  3. Enter the password you set on the instance, then click Connect.
  4. You land in the server's file list — browse folders with breadcrumbs, upload files by clicking or dragging them in, and download what you need, including whole folders as a ZIP archive.

That's the whole flow — from the Lightsail console to your first upload, with nothing installed. Connect Now — upload to your Lightsail instance

Find your Lightsail IP and default username

In the Lightsail console, the IP is on the home/Instances view: each instance card shows its public IP right on the card. Click the instance name to open its details page and look at the instance card there for the public IPv4 address. If you want an address that stays the same across restarts, attach a Static IP — in the instance details, go to the Networking tab → Create static IP, attach it to the instance, and use that address as your host. The default SSH username depends on the image — Bitnami-based blueprints use bitnami, Ubuntu images use ubuntu, Amazon Linux images use ec2-user (sometimes shown as amazon), and others vary — so check the instance details or AWS's documentation for your blueprint rather than guessing. You can confirm both the IP and the username from the same details page before you connect.

Common Lightsail connection errors and fixes

A note on Lightsail SFTP security

Because FilePort Pro relays your connection, your instance credentials pass through our server to reach yours — never "credentials never leave your browser." They're held in memory only for the active session, never stored, never logged, and the session ends when you disconnect or after about 15 minutes of inactivity. Password login on an internet-facing server deserves a little care: use a strong password, and consider limiting the firewall's SSH rule to your own IP address if your setup allows. If key-based login matters more to you, keep using your key with a desktop client — both paths can coexist. See our security page for how FilePort Pro handles your credentials.

Frequently asked questions

Does AWS Lightsail run an FTP server?

No, not by default. Lightsail Linux instances don't come with an FTP server installed. The standard way to move files is SFTP over SSH on port 22, which is encrypted and already part of the connection you use to log in. If you installed an FTP server yourself, you'd also need to open ports 21 and 20 in the Lightsail firewall — SFTP avoids that because port 22 is already allowed.

How do I SFTP to a Lightsail instance?

SFTP uses the same SSH connection as your terminal: your instance's public IP (or an attached Static IP), the default user for your image, and port 22. Lightsail instances normally log in with an SSH key pair; FilePort Pro connects with a username and password, so enable password authentication on the instance first, then connect from the browser with the IP, that username, and the password.

What's the Lightsail default SSH username?

It depends on the image. Bitnami-based blueprints use bitnami, Ubuntu images use ubuntu, Amazon Linux images use ec2-user (sometimes shown as amazon), and other images vary. Check the instance details or AWS's documentation for your blueprint rather than guessing.

Can I upload files to Lightsail without installing software?

Yes, once password authentication is enabled on the instance. FilePort Pro runs in the browser, so with your instance's public IP, the image's default username, and the password you set, you can connect and upload files straight from a web page — nothing to install.

Why do I get "Connection refused" or "Connection timed out" to port 22?

Both usually trace back to the firewall. Lightsail drops traffic it has no rule for, so make sure the instance's Networking tab includes an SSH/TCP 22 rule open to the network you're connecting from. "Connection refused" can also mean no SSH daemon is listening or the instance is stopped, while "timed out" usually means the firewall or network is silently dropping packets — add the port-22 rule first and retry.

Can I use FilePort Pro without uploading my SSH key?

Yes. FilePort Pro connects with a username and password, so you never upload your private key (.pem) to a website — which is exactly why password authentication must be enabled on the instance first. If your setup can't allow password logins, keep using your key pair with a desktop SFTP client instead.

More host guides

Lightsail is infrastructure you manage yourself, which is different from shared hosting. If your site is hosted with a managed provider instead, see the matching guide:

For more on browser-based transfers, see the web SFTP client. Questions about what we store? Read the privacy policy or the security page.

Get started — upload to Lightsail from your browser

No install, no sign-up, no credentials stored. Connect Now — access your Lightsail instance

Prefer an encrypted transfer? Use SFTP. Questions about what we store? Read the privacy policy.