- 05 Sep 2025
- 2 Minutes to read
- Print
- DarkLight
SFTP - Frequently Asked Questions
- Updated on 05 Sep 2025
- 2 Minutes to read
- Print
- DarkLight
When are the Relay hosted SFTP folder structures created?
Once your Client Success manager creates the client ID in the Relay CX Portal, the folders are created, but the SSH2 key and PGP key steps must be completed during your implementation.
Can the file be transmitted as SSH and SSH2?
The file must be sent to Relay as an SSH2 file. When this is then uploaded, the Relay CX Portal confirms whether the format is valid. If it is not, it throws an error.
For the encryption keys used for the SFTP service, do the keys require a passphrase?
No, there is no passphrase for the SFTP encryption keys.
What is the file format for the GPG key?
GPG key must have a file extension of .asc.
I am trying to connect to Relay’s SFTP service using Cyberduck, Filezilla, or WinSCP, but I am receiving an invalid connection error. What is the issue?
Relay uses SSH2 for authentication. This does not require a password. Confirm you are not attempting to pass one.
Check that your SSH2 public key has been uploaded to the Relay Customer Experience portal under your client id.
Am I using my private SSH2 key or the public? You should use your private SSH2 key to connect to Relay. The public key is stored on Relay’s side.
I am using the correct SSH2 key to try and connect, but I am still getting a connection key error and/or an error on my local client “Possible DNS Spoofing Detected.” Are there other potential issues?
Some clients also validate against an SSH Server’s host keys.
Check to see if StrictHostKeyChecking is enabled/disabled for your SSH client.
Clear any host key caches.
Update any stored host keys with the current Relay SSH server host key upon trying to make the connection.
I am trying to view the list of files within the /dropoff/onboarding or another folder, but my 3rd party software is crashing.
This is often a user interface issue. If there are thousands of files listed in any one folder, often 3rd party software such as WinSCP fails because it is unable to return such a large list of folder names.
Should I whitelist Relay IP Addresses?
Relay has provided the static IP feature for some clients that still whitelist IP addresses based on their risk tolerance policy, however, with other forms of security and with SAS providers often rotating their IP addresses it is not always employed.
Relay has clients in both scenarios, where some have whitelisted and others have declined.