{"id":9570,"date":"2026-06-03T06:43:33","date_gmt":"2026-06-03T04:43:33","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=9570"},"modified":"2026-06-08T09:25:23","modified_gmt":"2026-06-08T07:25:23","slug":"how-to-create-a-read-only-ftp-account","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-create-a-read-only-ftp-account\/","title":{"rendered":"How to Create a Read-Only FTP Account"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">In some situations, you may want to provide FTP access to a user without allowing them to upload, modify, or delete files. This can be useful when granting access for auditing, troubleshooting, or viewing website content.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can create a read-only FTP account by configuring permissions using a <code>.ftpaccess<\/code> file.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-create-a-read-only-ftp-account\/#Before_You_Begin\" >Before You Begin<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-create-a-read-only-ftp-account\/#Step_1_Create_the_ftpaccess_File\" >Step 1: Create the .ftpaccess File<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-create-a-read-only-ftp-account\/#Step_2_Add_Read-Only_Rules\" >Step 2: Add Read-Only Rules<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-create-a-read-only-ftp-account\/#How_the_Configuration_Works\" >How the Configuration Works<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-create-a-read-only-ftp-account\/#Allow_Read_Operations\" >Allow Read Operations<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-create-a-read-only-ftp-account\/#Block_Write_Operations\" >Block Write Operations<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-create-a-read-only-ftp-account\/#Hide_the_Configuration_File\" >Hide the Configuration File<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-create-a-read-only-ftp-account\/#Testing_the_Configuration\" >Testing the Configuration<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-create-a-read-only-ftp-account\/#Important_Notes\" >Important Notes<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-create-a-read-only-ftp-account\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Before_You_Begin\"><\/span>Before You Begin<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-881385346\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">First, create the FTP account and assign it access to the desired directory.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once the account has been created, connect to the server using FTP and navigate to the directory assigned to that FTP user.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_1_Create_the_ftpaccess_File\"><\/span>Step 1: Create the <code>.ftpaccess<\/code> File<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Inside the directory assigned to the FTP account, create a file named:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.ftpaccess<\/code><\/pre>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> The filename begins with a dot (<code>.<\/code>).<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_2_Add_Read-Only_Rules\"><\/span>Step 2: Add Read-Only Rules<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Insert the following configuration into the file:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;Limit CWD PWD DIRS READ&gt;<br>AllowUser ftp_username<br>&lt;\/Limit&gt;<br><br>&lt;Limit ALL&gt;<br>DenyUser ftp_username<br>&lt;\/Limit&gt;<br><br>HideFiles \"(\\.ftpaccess)\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Replace:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ftp_username<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">with the actual FTP username.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_the_Configuration_Works\"><\/span>How the Configuration Works<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Allow_Read_Operations\"><\/span>Allow Read Operations<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;Limit CWD PWD DIRS READ&gt;<br>AllowUser ftp_username<br>&lt;\/Limit&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This rule allows the user to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Browse directories<\/li>\n\n\n\n<li>View file listings<\/li>\n\n\n\n<li>Read and download files<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Block_Write_Operations\"><\/span>Block Write Operations<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;Limit ALL&gt;<br>DenyUser ftp_username<br>&lt;\/Limit&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This prevents the user from performing actions such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Uploading files<\/li>\n\n\n\n<li>Modifying files<\/li>\n\n\n\n<li>Renaming files<\/li>\n\n\n\n<li>Deleting files<\/li>\n\n\n\n<li>Creating directories<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Hide_the_Configuration_File\"><\/span>Hide the Configuration File<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>HideFiles \"(\\.ftpaccess)\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This prevents the <code>.ftpaccess<\/code> file itself from appearing in directory listings.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Testing_the_Configuration\"><\/span>Testing the Configuration<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">After saving the file:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Connect using the FTP account.<\/li>\n\n\n\n<li>Verify that files can be viewed and downloaded.<\/li>\n\n\n\n<li>Attempt to upload or delete a file.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">If the configuration is correct:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Download operations will work normally.<\/li>\n\n\n\n<li>Upload, rename, and delete operations will be denied.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Important_Notes\"><\/span>Important Notes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The <code>.ftpaccess<\/code> file only affects the directory in which it is placed and its subdirectories.<\/li>\n\n\n\n<li>Make sure the FTP account has been assigned to the correct directory before applying the rules.<\/li>\n\n\n\n<li>If multiple FTP users require read-only access, add separate <code>AllowUser<\/code> entries for each account.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To create a read-only FTP account, place a <code>.ftpaccess<\/code> file in the directory assigned to the FTP user and configure rules that allow read operations while denying all write actions. This enables users to browse and download files without being able to modify the contents of the server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[23],"manual_kb_tag":[835,1592,5202,5203,5204,5205,5206,5207,5208,5209],"class_list":["post-9570","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-ftp","manual_kb_tag-ftp-server","manual_kb_tag-file-permissions","manual_kb_tag-readonly-account","manual_kb_tag-read-only-access","manual_kb_tag-ftp-account","manual_kb_tag-ftp-access","manual_kb_tag-ftp-permissions","manual_kb_tag-ftp-configuration","manual_kb_tag-ftp-configuration-file","manual_kb_tag-deny-write-permissions"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9570","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":2,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9570\/revisions"}],"predecessor-version":[{"id":9571,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9570\/revisions\/9571"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=9570"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=9570"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=9570"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}