Guides
SSH glossary: the terms you'll meet in the terminal
Updated October 7, 2026 · 11 min read
SSH has a vocabulary problem. The commands are simple enough, but the words around them — agent, host key, TOFU, ProxyJump, octal — assume you already know the answer. This glossary explains the terms you actually meet when you use an SSH or SFTP client, without sending you off to a specification.
Entries are grouped by topic, and each one is a short, honest definition rather than marketing. Where a term connects to a feature in a client like TerminalX, the link is noted plainly. Read it top to bottom, or jump to the group you need.
Connection basics
- SSHSecure Shell — an encrypted protocol for running commands on a remote machine, and the foundation most of this glossary builds on
- SFTPthe file-transfer subsystem of SSH; same connection, same authentication, but for browsing and moving files
- SCPa simpler, older file-copy command that also rides on SSH
- Telnetan unencrypted remote-shell protocol from before SSH; still common on older network gear
- Seriala direct cable connection to a device, used for switches, routers and embedded boards; settings include baud, data bits, stop bits, parity and flow control
- Moshthe mobile shell — stays connected over flaky links and roaming networks by using UDP alongside SSH
- PTYpseudo-terminal; the kernel device that lets a remote program behave as if it were attached to a real keyboard and screen
- Shellthe program, such as bash or zsh, that reads your commands once you are logged in
Authentication and identity
- Password authenticationlogging in with a password; simple, but weaker than keys and often disabled on servers
- Public-key authenticationthe server holds your public key and you prove ownership of the matching private key
- Ed25519a modern, fast, small elliptic-curve key type; the usual default for new keys today
- RSAthe older, widely supported key type; still common, but long RSA keys are slower and being phased out
- ECDSAanother elliptic-curve key type, supported broadly but with a more complicated history than Ed25519
- Passphrasea password that protects a private key file on disk, so a stolen key is not instantly usable
- SSH agenta background helper that holds unlocked keys in memory and answers authentication requests for you
- Agent forwardingletting a remote server reach back through your local agent, so you can hop onward without copying keys; powerful, and worth using only on hosts you trust
- authorized_keysthe file on a server listing the public keys allowed to log in as a user
- Certificate authenticationa signed certificate that proves your key's identity, often used with short-lived credentials in larger fleets
Host verification
- Host keythe server's own public key; your client checks it to make sure you are talking to the right machine
- Fingerprinta short hash of a key that is easy to compare out of band
- Known hoststhe local record of server keys you have already accepted
- TOFUtrust on first use — accept a server's key the first time, then warn loudly if it ever changes
- Man-in-the-middlean attacker sitting between you and the server; host key checks exist to catch exactly this
TerminalX prompts on first use and again if a known host's key changes, which is TOFU working as intended.
Networking and forwarding
- Jump hostan intermediate server you connect through to reach a machine that is not directly reachable
- Bastionanother name for a hardened jump host, usually the only door into a private network
- ProxyJumpthe OpenSSH option that expresses a jump chain in your config
- Port forwardingtunnelling other traffic over an SSH connection
- Local forwardingsending a local port's traffic through the server, for reaching a remote service on your own machine
- Remote forwardingthe reverse: exposing a service on the far side back toward you
- Dynamic forwardingturning SSH into a SOCKS proxy for arbitrary destinations
- SOCKS5the proxy protocol dynamic forwarding speaks; point a browser or app at the local port to route through your server
- Port knockinghitting a sequence of closed ports to signal a firewall to open SSH for you
Keys, files and permissions
- Public vs private keythe public key is shared and goes to servers; the private key stays on your machine and is never sent
- Keychaina client's store of keys, passwords and certificates, reused across many hosts
- chmodthe command that sets file permissions; a client with an SFTP pane can change them without a shell
- Octal notationpermissions written as digits: 600 is owner read-write only, 644 adds group and public read, 755 adds execute for all
- Recursiveapplying an operation to a folder and everything inside it, such as a recursive delete or chmod
- ~/.ssh/configthe plain-text file where OpenSSH users keep host aliases, keys and jump settings; most GUI clients can import it
Terminal behaviour
- Scrollbackthe buffer of past output above the current screen; search-in-scrollback lets you find a line you scrolled past
- xterm-256colora widely supported terminal type that advertises 256 colours to remote programs
- True color24-bit colour, which some modern tools use for richer output
- Bracketed pastea mode that tells the shell when input was pasted rather than typed, so it does not misread it as commands
- Split panesdividing one window into several terminals, side by side or stacked
- Multiplexera tool like tmux that keeps sessions alive on the server and lets you reattach later
- Command palettea searchable list of app actions, faster than hunting through menus
Security and storage
- Vaultan encrypted store for hosts, keys and credentials; local in TerminalX, cloud-synced in some subscription clients
- Argon2ida modern key-derivation function that turns a master password into an encryption key; slow by design to resist guessing
- XChaCha20-Poly1305the authenticated cipher TerminalX uses to protect the vault, providing both confidentiality and tamper detection
- Zeroizationwiping key material from memory once it is no longer needed
- Auto-locklocking the vault after a period of inactivity so a left-open app does not expose your secrets
- Zero-knowledgea design where a server only ever holds encrypted data it cannot read; TerminalX goes further and has no server at all
- Telemetryusage data sent back to a vendor; TerminalX sends none
File transfer operations
- Transfer queuean ordered list of uploads and downloads, each with progress you can watch
- Resumecontinuing an interrupted transfer instead of starting over
- Dual-paneshowing local and remote folders together, which makes drag and drop obvious
- Previewopening a remote file to inspect it before deciding to download
Frequently asked questions
What is the difference between SSH and SFTP?
SSH gives you an interactive shell on a remote machine. SFTP is a subsystem that runs over the same SSH connection and handles files. The same host, key and jump host work for both, which is why integrated clients show a terminal and a file pane together.
What does TOFU mean?
Trust on first use. The first time you connect, your client accepts and remembers the server's host key. Every later connection compares against that record; if the key changes, you get a warning, because it could mean a rebuilt server or an interception attempt.
What does chmod 600 mean on a key file?
It grants read and write to the owner and nothing to anyone else. SSH refuses private keys that other users can read, so 600 is the usual setting. 644 allows read by others, and 755 adds execute for everyone — common for folders and scripts, not for keys.
What is an SSH agent for?
It keeps your unlocked private keys in memory and answers authentication for you, so you type a passphrase once per session instead of once per connection. Agent forwarding extends that to servers you hop through, which is convenient but only safe on hosts you trust.
What is a jump host?
A server you connect through to reach a machine that is not directly reachable, usually because it sits on a private network behind a bastion. The SSH connection is tunnelled through the jump host, so your keys and host checks still apply end to end.
Keep reading
The best SSH clients for Mac, Windows and Linux
A practical roundup of the best SSH clients for Mac, Windows and Linux in 2026, from built-in terminals to GUI apps, and how to choose the one that fits.
The best SFTP clients for Mac, Windows and Linux
The best SFTP clients for Mac, Windows and Linux in 2026, compared on dual-pane workflow, drag and drop, permissions, and how they fit with SSH.
SSH on Windows: built-in tools and GUI clients
How SSH works on Windows in 2026: built-in OpenSSH, Windows Terminal, WSL and PuTTY, plus where a GUI client like TerminalX fits and how to install it.
TerminalX vs Termius: one-time price vs subscription
A fair, row-by-row comparison of TerminalX and Termius: price model, account, vault, offline use, runtime, protocols and imports, with honest caveats.