How to SSH into a Mac, on your network or from anywhere
How to SSH into a Mac: turn on Remote Login, find its address, log in with a key instead of your password, and reach it from outside your network.
What it takes to SSH into a Mac
To SSH into a Mac you need one setting and one command. Every Mac ships with an SSH server, but it stays off until you turn on Remote Login. After that, any computer on the same network can open a terminal on the Mac with your usual account name and password.
That password is the part to change. This page covers switching SSH on, finding the address, replacing the password with a key, and what changes once you leave the house.
Turn on Remote Login
Remote Login is the Mac's name for its SSH server. Apple keeps it in Sharing, next to Screen Sharing and File Sharing. When it is on, the Sharing pane also shows the exact command to connect with, so copy it from there rather than guessing.
- Open System Settings, choose General in the sidebar, then Sharing.
- Turn on Remote Login, then click the info button beside it.
- Under Allow access for, choose Only these users and add just the accounts that need it. All users means every account on the Mac.
- Leave Allow full disk access for remote users off unless you need it. Without it, remote sessions stay out of the places macOS protects for privacy.
Or from the Mac's own Terminal. Apple's manual page says this needs Full Disk Access, so grant it to Terminal first.
sudo systemsetup -setremotelogin onFind the Mac's address
On the same network, the Mac answers to its local name, which ends in .local. That name survives the router handing out a new address, so use it instead of the number. The numeric address works too, but it can change after a restart unless you reserve it in the router.
The first time you connect, SSH shows the Mac's fingerprint and asks whether to trust it. Say yes on your own network. From then on it warns you if that fingerprint ever changes.
The Mac's local name. Add .local to what this prints.
scutil --get LocalHostNameIts numeric address on the first network port. Try en1 if this prints nothing.
ipconfig getifaddr en0Then, from the other computer
ssh you@your-mac.localLog in with a key instead of your password
Remote Login accepts your macOS password, and that same password unlocks your keychain and approves software installs. A key is better on both counts. There is nothing to type or guess, and it opens only this one door.
1. Make a key on the computer you connect from
ssh-keygen -t ed255192. Copy the public half to the Mac. macOS includes ssh-copy-id.
ssh-copy-id you@your-mac.local3. Connect again. It should not ask for your password.
ssh you@your-mac.localIf it still asks for a password
Check the permissions on ~/.ssh on both machines. OpenSSH ignores a key that other users could read, and falls back to the password without saying why.
SSH keys, a config file and the four errors you will actually hit ↗
Switch password logins off
Once the key works, stop the Mac accepting passwords over SSH. macOS reads extra settings from /etc/ssh/sshd_config.d/ in name order, and the first value set for an option wins. So a file whose name sorts early is the safe place for this.
Turn off two settings, not one. macOS switches on PAM, which offers password logins through keyboard-interactive authentication. If you only turn off PasswordAuthentication, the password prompt still appears.
Write both settings to a file of their own
printf 'PasswordAuthentication no\nKbdInteractiveAuthentication no\n' | sudo tee /etc/ssh/sshd_config.d/010-keys-only.confCheck what the SSH server will actually use. Both lines should end in no.
sudo sshd -T | grep -E '^(passwordauthentication|kbdinteractiveauthentication)'No restart needed
macOS starts a fresh SSH server for each connection, so the next login reads the new file. Keep your current session open and test from a second terminal before you close it. After a major macOS update, run the check again; it takes a second.
SSH into a Mac from outside your network
Everything so far works on one network. From outside, the .local name means nothing and your router is in the way. There are two honest ways through to macOS itself.
The remote access guide covers both in full, including how to tell whether your provider has put you behind carrier-grade NAT.
- A mesh VPNTailscale or something like it, on the Mac and on each device you connect from. Nothing is exposed to the internet, and it works behind carrier-grade NAT. This is the right default for reaching macOS.
- Forward port 22It works only if your provider gives you a real public address, and it is only safe with password logins off. An open SSH port gets tried by bots all day.
Keep it awake to keep it reachable
SSH needs the Mac awake, and a sleeping Mac answers nothing. So on a Mac that works as a server, set it never to sleep and to restart by itself after a power cut. Otherwise the day you need it is the day it is asleep.
Never sleep, and come back after a power cut
sudo pmset -a sleep 0 disksleep 0 autorestart 1When you want a server, not a Mac
SSH into macOS gives you your Mac: your files, your account and your apps. That is exactly right for looking after the Mac. It is a poor place to run a public service, though, because anything listening on the internet runs with your account's reach.
If a server is what you are really after, put a Linux machine on the Mac and SSH into that instead. It has its own disk and users, software documentation expects it, and a mistake there costs you the VM rather than your Mac.