MacServe.Log in or sign upSign upGo to panelPanel

How to SSH into a Mac, on your network or from anywhere

How to SSH into a Mac: turn on Remote Login, find its address, log in with a key instead of your password, and reach it from outside your network.

What it takes to SSH into a Mac

To SSH into a Mac you need one setting and one command. Every Mac ships with an SSH server, but it stays off until you turn on Remote Login. After that, any computer on the same network can open a terminal on the Mac with your usual account name and password.

That password is the part to change. This page covers switching SSH on, finding the address, replacing the password with a key, and what changes once you leave the house.

Turn on Remote Login

Remote Login is the Mac's name for its SSH server. Apple keeps it in Sharing, next to Screen Sharing and File Sharing. When it is on, the Sharing pane also shows the exact command to connect with, so copy it from there rather than guessing.

  1. Open System Settings, choose General in the sidebar, then Sharing.
  2. Turn on Remote Login, then click the info button beside it.
  3. Under Allow access for, choose Only these users and add just the accounts that need it. All users means every account on the Mac.
  4. Leave Allow full disk access for remote users off unless you need it. Without it, remote sessions stay out of the places macOS protects for privacy.

Or from the Mac's own Terminal. Apple's manual page says this needs Full Disk Access, so grant it to Terminal first.

sudo systemsetup -setremotelogin on

Apple: allow a remote computer to access your Mac ↗

Find the Mac's address

On the same network, the Mac answers to its local name, which ends in .local. That name survives the router handing out a new address, so use it instead of the number. The numeric address works too, but it can change after a restart unless you reserve it in the router.

The first time you connect, SSH shows the Mac's fingerprint and asks whether to trust it. Say yes on your own network. From then on it warns you if that fingerprint ever changes.

The Mac's local name. Add .local to what this prints.

scutil --get LocalHostName

Its numeric address on the first network port. Try en1 if this prints nothing.

ipconfig getifaddr en0

Then, from the other computer

ssh you@your-mac.local

Log in with a key instead of your password

Remote Login accepts your macOS password, and that same password unlocks your keychain and approves software installs. A key is better on both counts. There is nothing to type or guess, and it opens only this one door.

1. Make a key on the computer you connect from

ssh-keygen -t ed25519

2. Copy the public half to the Mac. macOS includes ssh-copy-id.

ssh-copy-id you@your-mac.local

3. Connect again. It should not ask for your password.

ssh you@your-mac.local

If it still asks for a password

Check the permissions on ~/.ssh on both machines. OpenSSH ignores a key that other users could read, and falls back to the password without saying why.

SSH keys, a config file and the four errors you will actually hit ↗

Switch password logins off

Once the key works, stop the Mac accepting passwords over SSH. macOS reads extra settings from /etc/ssh/sshd_config.d/ in name order, and the first value set for an option wins. So a file whose name sorts early is the safe place for this.

Turn off two settings, not one. macOS switches on PAM, which offers password logins through keyboard-interactive authentication. If you only turn off PasswordAuthentication, the password prompt still appears.

Write both settings to a file of their own

printf 'PasswordAuthentication no\nKbdInteractiveAuthentication no\n' | sudo tee /etc/ssh/sshd_config.d/010-keys-only.conf

Check what the SSH server will actually use. Both lines should end in no.

sudo sshd -T | grep -E '^(passwordauthentication|kbdinteractiveauthentication)'

No restart needed

macOS starts a fresh SSH server for each connection, so the next login reads the new file. Keep your current session open and test from a second terminal before you close it. After a major macOS update, run the check again; it takes a second.

SSH into a Mac from outside your network

Everything so far works on one network. From outside, the .local name means nothing and your router is in the way. There are two honest ways through to macOS itself.

The remote access guide covers both in full, including how to tell whether your provider has put you behind carrier-grade NAT.

  • A mesh VPNTailscale or something like it, on the Mac and on each device you connect from. Nothing is exposed to the internet, and it works behind carrier-grade NAT. This is the right default for reaching macOS.
  • Forward port 22It works only if your provider gives you a real public address, and it is only safe with password logins off. An open SSH port gets tried by bots all day.

Mac mini server remote access, from anywhere ↗

Keep it awake to keep it reachable

SSH needs the Mac awake, and a sleeping Mac answers nothing. So on a Mac that works as a server, set it never to sleep and to restart by itself after a power cut. Otherwise the day you need it is the day it is asleep.

Never sleep, and come back after a power cut

sudo pmset -a sleep 0 disksleep 0 autorestart 1

Keeping a Mac awake and online, in full ↗

When you want a server, not a Mac

SSH into macOS gives you your Mac: your files, your account and your apps. That is exactly right for looking after the Mac. It is a poor place to run a public service, though, because anything listening on the internet runs with your account's reach.

If a server is what you are really after, put a Linux machine on the Mac and SSH into that instead. It has its own disk and users, software documentation expects it, and a mistake there costs you the VM rather than your Mac.

Linux on a Mac: a VM, Docker or Asahi ↗

Keep reading

Getting into a Linux server from a MacMac mini server remote access, from anywhereKeeping a Mac awake and online