FTP TUTORIALS & GUIDES

FTP User Accounts Explained
Permissions, Limits, Security Tips

Learn how FTP user accounts work, including usernames, passwords, directory permissions and access controls, so you can securely manage website file transfers and give each user access only to the folders they need.

Updated: June 20, 2026
By: RSH Web Editorial Staff

Hosting from $2.99/mo
  See Plans    Contact Us

Menu

FTP User Accounts Explained

Learn how FTP user accounts work: usernames, passwords, directory limits, quotas, and access control so each person only reaches the folders they need.

FTP user accounts, permissions, limits, and security tips

User Accounts

An FTP account is a login that can upload and download files on the hosting server. In cPanel you can keep the primary account and add extra logins with their own password, home folder, and disk quota. Create an FTP Account

Login

Usually name@yourdomain.com plus a password.

Directory

The account is jailed to that folder and cannot walk above it.

Quota

Optional cap on how much that login can store.

Primary vs extra accounts

Primary cPanel userExtra FTP account
HomeThe whole account home, including public_htmlOnly the directory you assign
SFTPYes, if SSH is enabledNo. Extra FTP users are FTP/FTPS only
Use forSite owner, full file workDesigner, plugin vendor, one-site folder

Permissions in practice

cPanel extra FTP accounts can read and write inside their directory. They do not get a separate “read-only FTP role” in the add-account form. Limit risk by pointing the home at a subfolder such as public_html/uploads, not the whole site.

Unix modes still apply on files the user creates. Typical web values are 644 for files and 755 for directories. Change those in File Manager or an FTP client, not in the FTP Accounts table.

Limits that matter

Directory jail: smallest folder that still lets the person do their job. Multiple FTP Accounts
Quota: stop one login from filling the hosting disk.
Sessions: disconnect leftover logins in FTP Connections.
Password: unique, long, stored in the client’s password manager—not a shared spreadsheet.

SFTP is not the same as “an FTP account with TLS.” SFTP needs SSH. Extra FTP accounts created in cPanel do not automatically work over SFTP. Using SFTP with cPanel

Security habits

  • Prefer FTPS for extra accounts and SFTP for the owner account. Securing FTP Transfers
  • Delete logins when a contractor is finished.
  • Do not share the primary cPanel password as an FTP login.
  • Review accounts after staff or vendor changes.

Frequently Asked Questions

What is an FTP user account in cPanel?

It is a username and password that can connect with FTP or FTPS and work only inside the folder you assign. The complete login is usually name@yourdomain.com. The primary cPanel user can reach the whole home directory. Extra accounts should be jailed to one site or one project folder. Create them with an FTP account in cPanel.

How do I limit what an FTP user can see?

Set the Directory field when you create the account, such as public_html/project. That folder becomes the user’s home, so they cannot browse up into other sites or mail files. Change the path later in FTP Accounts if the job scope changes. Delete the account when the contractor is finished. Multi-user setup is in managing multiple FTP accounts.

What does an FTP quota do?

A quota caps how much disk that FTP user can consume through uploads. Use it so a media folder cannot fill the whole hosting plan. Unlimited is fine for a trusted admin account. If uploads fail after a burst of images, check the quota and the plan’s disk usage in cPanel before you blame the client.

Can extra FTP accounts use SFTP?

Usually no. Extra accounts are for FTP or FTPS. SFTP needs SSH and typically the primary cPanel username. If SFTP fails with the extra login, connect with explicit FTPS instead. Do not assume SSH is on for every hosting plan. See FTP vs SFTP vs FTPS and using SFTP with cPanel.

How do I keep FTP accounts secure?

Use a unique strong password, FTPS or SFTP, and a jailed directory. Do not share the main cPanel password. Remove unused users after a project ends. Prefer a dedicated account for scripts so a leaked backup job cannot rewrite the whole site. Password guidance is in creating a strong password.

How often should I review FTP users?

Review them when staff or vendors change, and at least on a regular cadence such as each quarter. Disable anyone who no longer needs access. Confirm each remaining user still points at the right folder. Check FTP Connections if you see logins you do not recognize. A short primer is what FTP is used for.

How do file permissions relate to the FTP account?

The account decides who can connect and which folder they start in. chmod decides whether a file is readable or writable on disk, commonly 644 for files and 755 for directories. An FTP user can still fail to edit a file if ownership or chmod is wrong. Fix that in File Manager or the client’s Properties dialog, not only in FTP Accounts.

Should every teammate get their own FTP login?

Yes. Separate logins make it easier to revoke access and to limit each person to one folder. Shared passwords linger after someone leaves. Save each login in the client’s Site Manager instead of a group chat. Client options are in choosing an FTP client, with more articles on the blog index.

Tweet  Share  Pin  Email

Add Comment

* Required information
Drag & drop images (max 3)

Comments

No comments yet. Be the first!

From the minds of our master copywriters

Looking for a reliable Hosting provider? RSH Web Services provides you with the best hosting solutions and features, at affordable prices. Looking to personalize your website with cPanel, then we are the one to go with