What SSH Access Means on Shared Hosting
SSH access on shared hosting differs from access on a VDS: instead of a full shell with root rights, the user lands in a jailshell — an isolated environment limited to their home directory. This protects other clients on the same server: you cannot see other users' files or change system settings.
That level of access is enough for git deployment, running composer, wp-cli, npm build scripts, and ordinary file work through rsync or scp — anything that does not require changing the kernel version or installing system packages.
How to Enable SSH Access in cPanel
Under "Security", open "SSH Access" → "Manage SSH Keys". If the option is missing from the interface, hosting support enables SSH for the account on request through a support ticket — on most plans the feature is available right away, but it may be turned off by default for security reasons.
Connection details: the hostname or server IP, your cPanel username, and the SSH port — usually a nonstandard one, different from 22. The exact port is listed under "SSH Access" or in the email with the account details.
Connecting with an SSH Key
Do not use a password for SSH — a key pair is more reliable and immune to brute-forcing. Generate a pair on your own machine:
ssh-keygen -t ed25519 -C "deploy@example.com" -f ~/.ssh/zevshost_key
Add the public key (the file with the .pub extension) in cPanel through "Manage SSH Keys" → "Import Key", pasting its full content. After importing, click "Authorize" next to the key — without this step the server keeps asking for a password.
Connecting with an explicit key and port:
ssh -i ~/.ssh/zevshost_key -p 2222 username@example.com
What Jailshell Allows and What It Does Not
| Action | Allowed |
|---|---|
| Working with files inside your own directory | Yes |
| git clone, composer, npm, wp-cli | Yes |
| rsync and scp between servers | Yes |
| sudo and installing system packages | No |
| Viewing other users' processes | No |
| Changing the PHP version from the console | No, only via MultiPHP Manager |
The PHP version for CLI scripts in jailshell follows the value set in MultiPHP Manager for the domain — the php -v command only checks the current version, it does not change it.
Common Commands for Everyday Work
Checking disk usage and site structure after connecting:
cd ~/public_html
du -sh * | sort -rh | head -10
Updating a PHP project's dependencies and running a scheduled task through cron manually to test it:
composer install --no-dev --optimize-autoloader
php artisan schedule:run
Summary: a Checklist for Safe SSH Work
- Disable password login wherever the panel allows it, and use a key only.
- Keep the private key outside the repository and never send it over messaging apps.
- Use the nonstandard SSH port from the account details email, not port 22.
- Remember: jailshell does not grant root — some software installation commands will not work.
- Use MultiPHP Manager to change PHP, not shell environment variables.