PricingGet started

← Docs

Managing your site

SSH and WP-CLI on a WordPress site

Every WordPress site comes with real SSH — to live and to its staging copy. You land in the site's files as the user WordPress runs as, with WP-CLI ready, and everything that rides on SSH works: scp, rsync, SFTP, VS Code and Cursor Remote-SSH, and a tunnel to your database.

You log in as www-data — the same user WordPress runs as — so files you create keep the ownership WordPress expects, and the shell can do exactly what your site's own code can: you get your site, not the server, which is still ours to manage, heal and patch. Keys belong to people, and access follows your team: anyone who can open the site in the panel can connect with their own key, and a developer limited to other sites can't. It's on every plan.

  1. Add your public key
    Go to Account → SSH keys and paste your public key — the one-line contents of ~/.ssh/id_ed25519.pub. Ed25519, ECDSA and RSA keys of 2048 bits or more work. One key covers every site and app you have access to. Never paste the private key — the panel refuses it.
  2. Copy the config block
    Open the site and go to its SSH & SFTP tab. Add the block it shows to ~/.ssh/config. If the site has a staging copy, the block includes it as a second alias ending in -staging.
  3. Connect
    Run ssh followed by the alias. You land in /var/www/html — the site's files — with WP-CLI on the path.
  4. Check the host key once
    On the first connection your SSH client shows the server's fingerprint and asks whether to trust it. The tab shows the same fingerprint — compare the two before you answer yes.
~/.ssh/config — the tab shows this filled in with your site's values
Host my-site
  HostName my-site.p.belov.cloud
  Port 2222
  User a1b2c3d4e5f6

Host my-site-staging
  HostName my-site.p.belov.cloud
  Port 2222
  User f6e5d4c3b2a1
Everyday use
ssh my-site                                  # a shell in the site's files
ssh my-site wp plugin list                   # WP-CLI, ready to go
ssh my-site wp cache flush                   # …or any wp command
ssh my-site 'wp search-replace old.example new.example --dry-run'
rsync -av ./my-theme/ my-site:wp-content/themes/my-theme/
sftp my-site                                 # or any SFTP client, with your key

Your database is a command away: wp db cli opens a MySQL shell right on the server. To use TablePlus or DBeaver instead, open a tunnel and connect to localhost:3306 with the user and password WP-CLI prints. The tunnel starts inside your site's container, so it reaches exactly what WordPress can — nothing more.

Database
ssh -t my-site wp db cli                     # a MySQL shell
ssh -N -L 3306:belov-db:3306 my-site         # TablePlus / DBeaver → localhost:3306
ssh my-site wp config get DB_USER            # the credentials
ssh my-site wp config get DB_PASSWORD

VS Code and Cursor connect the same way: Remote-SSH → Connect to Host → pick the alias, and the editor opens the site's files like a local folder, terminal included.

Live means live
/var/www/html is your site itself, so a change there is public the moment you save it. Try risky ones on staging first — the -staging alias — then push to live from the Staging tab. Daily backups cover wp-content and the database; restore points are in the Backups tab.
What persists
Your site's files and database persist, as always. Your home directory (~) is temporary: it lives with the site's server and is cleared when that server is recreated — by a PHP switch or a restore, for example. Shell history, an editor's server and the like simply come back on the next connection.
Kept off the web
Developers clone themes with git and leave a dump behind now and then, so the web server answers 403 for dot-files and folders (.git, .env — everything except .well-known), *.sql dumps, and copies of wp-config.php. Still: write dumps to your home directory, not the web root.
When you disconnect
Whatever you started in that session gets a hangup signal, as on any SSH server; start a long job with nohup if it should outlive the connection. Every session is recorded in the site's Activity, and removing a key or a teammate stops new connections within half a minute.
OpenSSH 10 and post-quantum key exchange
Recent OpenSSH may print a notice that the connection doesn't use post-quantum key exchange. That's accurate — the gateway uses curve25519 for now, like most SSH servers today. To hide the notice, add the line WarnWeakCrypto no-pq-kex to the Host block.

Real SSH with WP-CLI, staging and daily backups come with every WordPress plan — no tier gate.

WordPress pricing →

← All guides