SFTP Server Apps
SFTP Server apps connect Studio to an SFTP server so Action Flows can pick up, deliver, and tidy up files that partners, banks, or legacy systems exchange over SFTP. The app holds the connection settings and credentials; Actions use its tools from Agent steps, Tool Call steps, and Code steps.
For a general overview of all app types, see Tenant Admin > Apps.
What an SFTP Server App Provides
- Tools
- Download_Sftp_File downloads a file into the run as a runtime file that later steps and tools can reference, for example to OCR it, attach it to an email, or write it to Azure Storage.
- Upload_Sftp_File uploads text, Base64 content, or an existing runtime file (a downloaded file, an OCR result, a generated PDF) to the server.
- List_Sftp_Directory lists files and folders, optionally filtered by a name pattern such as
*.pdf, and optionally recursing into subfolders. - Move_Sftp_File moves or renames a file, typically to an archive folder after processing.
- Delete_Sftp_File deletes a single file. Folders cannot be deleted.
- Input
- Read_Sftp_File reads one file as binary input content for steps such as OCR.
- Triggers: None. Pair the app with a Manual, Scheduled, or other trigger. A Scheduled Action that lists a folder and processes new files is the most common pattern.
Creating an SFTP Server App
- Go to Tenant Admin > Apps and select New.
- Choose SFTP Server.
- Enter a name, then the connection settings:
- SFTP host – host name or IP address, without a scheme or path.
- Port – defaults to 22.
- Root folder – every path used by the app's tools and input is relative to this folder, and paths cannot leave it. Leave it empty to use the server's root or the user's home folder when the server confines users to their home.
- Host key fingerprint – optional, see below.
- Save the app, then select Configure Credentials.
Credentials
SFTP apps authenticate with a username and one of:
- Username & Password
- SSH Private Key – paste the private key in PEM or OpenSSH format (
-----BEGIN ... PRIVATE KEY-----). Add the key passphrase only if the key is encrypted. RSA, ECDSA, and Ed25519 keys are supported.
Credentials are stored in Key Vault and never shown again. Rotate them by opening Configure Credentials and saving new values.
Testing the Connection and Pinning the Host Key
After credentials are saved, select Test on the app. Studio connects, authenticates, lists the root folder, and reports the server's SSH host key fingerprint, for example SHA256:nThbg6kX….
Pinning the fingerprint is optional but recommended for production servers:
- Run Test and copy the fingerprint from the result.
- Paste it into Host key fingerprint and save the app.
From then on Studio refuses to connect if the server presents a different key, which protects against impersonation. If the server's key legitimately changes, update the pinned fingerprint.
Paths and Limits
- Paths use forward slashes and are relative to the app's root folder.
inbox/invoice.pdfand/inbox/invoice.pdfmean the same file...segments that would leave the root are rejected. - Files are limited to 25 MB per upload or download. The limit is stated in the tool descriptions so agents do not attempt larger files.
- Directory listings return up to 200 entries by default and at most 1000; the result reports whether it was truncated.
- Upload and move create missing destination folders by default. Upload replaces existing files by default; move does not, unless
overwriteis set.
Example: Process Files Dropped by a Partner
- Scheduled trigger every 15 minutes.
- Tool Call step with List_Sftp_Directory on
inboxwith pattern*.pdf. - Agent step that, for each listed file, calls Download_Sftp_File, sends the runtime file to an OCR or extraction step, and posts the result to the target system.
- Tool Call step with Move_Sftp_File from
inbox/<file>toarchive/<yyyy-MM>/<file>.
Downloaded files behave like any other runtime file: reference them as latest, runtimeFile:<id>, a selector such as { "sourceToolName": "Download_Sftp_File" }, or by passing the runtimeFile object returned by the download tool. See Inputs and Tools for all reference forms.
Things to Know
- The SFTP app has no trigger of its own. Use a Scheduled trigger and List_Sftp_Directory to detect new files.
- The tool results report paths relative to the root folder, never the server's absolute path.
- Error messages name the path and the reason (not found, permission denied, host key mismatch, size limit) so Agent steps can react to them.
- Local development: the Docker Compose environment includes an
sftpservice. Create an app with hostsftp, port22, root folder/upload, and credentialsdooap/dooap. Its host key changes whenever the container is recreated, so do not pin a fingerprint locally.