Setting up an automated file transfer can quickly become frustrating when your workflow stalls with a "Bad Gateway" or authentication error. If you are struggling with fixing an SFTP Connection Failure in Power Automate, you are not alone. The SFTP-SSH connector operates with strict security requirements, meaning minor configuration mismatches in private keys, firewall rules, or host fingerprints will completely block access. this guide explains the diagnostic checks and configuration changes needed to establish a stable, secure connection to your server.
Convert and Verify Your Private Key Format

while working on fixing an SFTP Connection Failure in Power Automate, the most common culprit is an unsupported private key format. The native SFTP-SSH connector does not support the widely used PuTTY Private Key (.ppk) format. It specifically requires keys to be in the OpenSSH format, and heavily prefers the RSA algorithm. If you paste a .ppk file's contents into the connection setup, the authentication will immediately fail.
To resolve this, you must convert your existing key into the OpenSSH format. Open the PuTTYgen application on your computer and click the Load button to import your current .ppk file. Once the key is loaded, navigate to the top menu, select Conversions, and click Export OpenSSH key. Save this new file to your local drive without a .ppk extension. Open the newly created file in a plain text editor, such as Notepad. The contents should begin with -----BEGIN RSA PRIVATE KEY----- and end with -----END RSA PRIVATE KEY-----.
Copy the entire block of text, including the begin and end markers. Return to your Power Automate connection setup, select the SSH Private Key authentication type, and paste the copied text into the SSH Private Key field. Test the connection; if the key format was the issue, the connector will now successfully authenticate with your server.
Whitelist Microsoft Azure IP Addresses
Another critical step in fixing an SFTP Connection Failure in Power Automate involves network security and firewalls. Power Automate operates from Microsoft Azure datacenters. If your SFTP server resides behind a strict corporate firewall, it will automatically reject incoming connection requests from unrecognized Azure IP addresses, typically resulting in a timeout or gateway error.
You must configure your server's firewall to allow traffic from the specific IP ranges used by Power Automate in your region. First, log into the Power Platform admin center to confirm the physical region where your environment is hosted (for example, United States or Europe). Next, download the official Azure IP Ranges and Service Tags JSON file from the Microsoft Download Center. Search the document for the service tags PowerAutomate and AzureConnectors associated with your specific region.
Provide these IP ranges to your network administrator or add them directly to your SFTP server's firewall whitelist for port 22 (or your custom SSH port). Once the firewall rules are updated and propagated, trigger your Power Automate flow again. A successful test will confirm that the Azure datacenters are no longer being blocked by your network infrastructure.
Validate the SSH Host Key Fingerprint
If you have verified your keys and IPs but are still trying to fix an SFTP Connection Failure in Power Automate, the issue often lies with host key validation. By default, the connector requires you to provide the SSH Host Key Fingerprint to prevent man-in-the-middle attacks. If this fingerprint is missing, formatted incorrectly, or mismatched with the server's actual key, the connection will be refused.
You need to retrieve the exact fingerprint from your SFTP server. If you have terminal access to the Linux server hosting the SFTP service, run the command ssh-keygen -l -E md5 -f /etc/ssh/ssh_host_rsa_key.pub. This will output a string containing the MD5 hash of the host key. Alternatively, you can use a desktop client like WinSCP; when you connect to the server for the first time, WinSCP will display a warning window that includes the server's fingerprint.
Copy the MD5 fingerprint string (which looks like a series of two-digit hexadecimal numbers separated by colons, e.g., 00:11:22:33...). In the Power Automate connection settings, paste this exact string into the SSH Host Key Fingerprint field. Save your configuration and re-test the connection to verify that the connector now trusts the destination server.
Managing Automated Documents with WPS Office

While WPS Office cannot change Microsoft Power Automate configurations, adjust Azure firewall settings, or manage your SSH keys, it becomes a highly valuable tool once your automated file transfer is functioning. After you successfully learn fixing an SFTP Connection Failure in Power Automate, your workflow will likely begin downloading bulk CSV files, daily Excel reports, or PDF invoices directly to your local drive or cloud storage.
Instead of relying on heavy, resource-intensive software to review these automated exports, you can use WPS Office to efficiently handle the final document tasks. If your flow downloads data logs from the SFTP server, open the resulting files in WPS Spreadsheet. You can use its built-in data validation and PivotTable features to quickly audit the automated data for errors. If your workflow retrieves batches of PDF invoices, use the WPS PDF toolkit to merge them into a single monthly report or extract specific text using its OCR capabilities. By pairing a stable Power Automate flow with the lightweight, cross-platform performance of WPS Office, you ensure that both the data transfer and the subsequent document analysis run seamlessly.
FAQs About Fixing an SFTP Connection Failure in Power Automate
Why does the SFTP-SSH connector return a "Bad Gateway" error?
A "Bad Gateway" error typically indicates a network timeout. This happens when the SFTP server's firewall blocks the incoming connection from Microsoft's Azure datacenters, or if the server name and port are routed incorrectly. To resolve it, ensure that the Power Automate IP addresses for your specific region are whitelisted on your SFTP firewall.
Can I use an Ed25519 SSH key with Power Automate?
Currently, the Power Automate SFTP-SSH connector relies on an underlying library that has limited support for newer cryptographic formats like Ed25519. It strongly prefers RSA keys formatted for OpenSSH. If your server mandates Ed25519, you may experience persistent authentication failures until you generate an RSA key pair instead.
How do I specify a custom port for the SFTP connection?
If your SFTP server does not use the default port 22, you can specify your custom port directly in the server address field. Simply append a colon followed by the port number to your hostname. For example, enter sftp.yourdomain.com:2222 in the Server Address field during the connection setup.
Why does my flow fail when transferring very large files?
The standard SFTP-SSH connector has strict message size limits, typically capping standard file operations at 50 MB. If you need to transfer larger files, you must enable "Chunking" in the settings of your specific Power Automate action. Clicking the ellipsis (...) on the SFTP action, selecting Settings, and turning on the Chunking toggle allows the connector to process files up to 1 GB by breaking them into smaller, manageable requests.




