WinSCP logo

WinSCP Recorded Package Source

Direct package links and installation notes for Windows

Developer Tools · v6.5.6 · Free (GPL-3.0-or-later)

Free SFTP, SCP and FTP client for Windows

Source record, not a product review. Automated checks can confirm URL availability but not package safety, installation behavior, or offline operation. Catalog maintained by .
License: Free (GPL-3.0-or-later)
Size: 12 MB (Setup EXE)
Platforms: Windows

Download summary

WinSCP is a developer tool for Windows, published by Martin Přikryl. A direct package URL is recorded below. The host may be the publisher, a release repository, a CDN, or another distribution source documented by the publisher. Some packages still fetch optional components during setup. The recorded publisher site is winscp.net. We do not host or modify installer files.

Sources and identity

External references used to identify the product and publisher. These links do not prove that we installed the package.

Wikipedia article Source on GitHub SHA-256 listed in catalog

Publisher documentation

These references support the package and behavior notes. Documentation checks are separate from the recorded URL-check date and do not represent an installation test.

Choose a package

Choose Setup components or a complete MSI deployment

Use the Setup EXE when you need its component and install-mode choices. The MSI installs the complete product, including tools, translations, and extensions, without those choices.

Before an update, close running WinSCP instances and export the required configuration. Portable and MSI packages do not support automatic update installation, so include an explicit update process.

Verify the configuration store before moving a portable copy

Inspect the beginning of a session log: Configuration identifies the registry or INI path, and Local account identifies whose profile is used. Export/Backup configuration from the Login dialog's Tools menu when a transfer is needed.

A non-writable application folder can redirect INI storage into the user profile. The portable ZIP alone is not proof that settings, temporary files, and saved credentials will stay on removable media. Protect the exported configuration as sensitive data.

Validate server identity before scripting transfers

Obtain the intended SSH host-key fingerprint through a trusted administrator channel and compare it on first connection. The server's host key is separate from the user's authentication key.

A host-key change needs investigation before proceeding. After authentication, review synchronization direction and deletion options against recoverable test data before allowing writes to a real destination.

Package guidance is based on the linked documentation. No installation test is claimed.

Publisher SHA-256 reference values

Compared on 11 September 2026 with the publisher’s reference.

WinSCP-6.5.6-Setup.exe
4488c493bafca6af4e7ae54ed39cb71479e65dc192c4d1a471647bf9cb9d6db0
WinSCP-6.5.6.msi
d3ef315e0013479dcbcedf8dd06aec33dfeda9004972e94128144329957b602f
WinSCP-6.5.6-Portable.zip
dd91974a0e56b140846a816d730190e51f093418b6bf851120493ce4b6cb3121

Compare only with the exact named package. A matching hash alone does not establish publisher identity or package safety.

Download options

Recorded package links, store pages, and browser extensions where available.

Scroll the table sideways to compare packages and reach each download link.

Platform Build Architecture Package Action Notes
Windows

EXE

WinSCP 6.5.6 Setup installer

32-bit EXE Download file Regular stable application build; runs on compatible 32-bit and 64-bit Windows
Windows

MSI

WinSCP 6.5.6 MSI package

32-bit MSI Download file Managed-deployment package that installs the complete product without Setup component choices
Windows

Portable

WinSCP 6.5.6 portable ZIP

32-bit ZIP Download file GUI and console executables; INI, temp, random-seed, and fallback paths determine host persistence
Windows

Standard package

WinSCP current stable downloads

Current builds Download page Open page Compare the current stable release with the retained version-specific package references

Verification scope

A direct package URL is recorded above. We have not independently installed every listed build or confirmed that setup remains fully offline.

We do not host software files. Links may resolve to a publisher domain, its release repository, app store, CDN, or a documented distribution host — confirm the final hostname, publisher signature, version, and architecture before deployment. Recorded URLs last checked 11 September 2026; content last updated 11 September 2026.

What WinSCP does

WinSCP is a GPL-licensed Windows file-transfer client supporting SFTP and SCP over SSH, FTP, FTPS, WebDAV/WebDAVS, and Amazon S3. Protocol names are not interchangeable security guarantees: plain FTP and WebDAV do not encrypt transport, while SSH- and TLS-based modes still depend on correct host-key or certificate verification, algorithms, credentials, and server configuration. S3 interoperability beyond Amazon's service depends on the endpoint's compatibility.

The desktop client provides Commander and Explorer layouts, transfers, queueing, directory comparison and synchronization, remote editing, session profiles, and scripting. Synchronization and automation can overwrite or delete data when direction, criteria, masks, or destination paths are wrong; review planned operations, use least-privilege server credentials, and keep recoverable backups. Remote editing downloads a temporary copy and uploads changes rather than editing a server file in place.

This record retains WinSCP 6.5.6 from the stable release line: the interactive Setup EXE, managed-deployment MSI, and portable ZIP. These stable packages use WinSCP's regular 32-bit application build, which runs on compatible 64-bit Windows; experimental native 64-bit packages belong to a different prerelease line. The MSI installs the complete product without the Setup program's component choices. The portable ZIP contains GUI and console executables, but portability is configuration-dependent: it normally uses an INI file when writable, while random-seed, temporary-file, or fallback settings can still touch the host profile or temp locations. Installed WinSCP defaults to the current user's registry.

The SHA-256 values below are published on WinSCP's version-specific download pages. WinSCP also documents Authenticode signing, but this audit did not run the binaries or validate their signatures. First-use SSH host keys should be compared through a trusted channel; accepting an unknown fingerprint without verification permits a man-in-the-middle risk. Saved passwords without a master password are recoverable and are not equivalent to a protected credential vault. No WinSCP account is required, but transfers need reachable servers and their credentials, while update checks require connectivity. Portable and MSI packages do not support WinSCP's automatic update installation.

Reference images

WinSCP Developer Tools preview card
WinSCP — Developer Tools

Captions describe the visible contents. Reference images are not installation-test results and may show older releases or other platforms.

Product features

  • SFTP, SCP, FTP, FTPS, WebDAV/WebDAVS, and Amazon S3 connections
  • Commander and Explorer layouts with queued transfers and remote editing
  • Synchronization and scripting require reviewed paths, credentials, and deletion behavior
  • SSH host keys and TLS certificates must be validated for the selected protocol
  • Setup, MSI, and portable packages have different configuration and update behavior

Installation notes

Grouped by the package types recorded on this page — not a claim that every listed build was independently tested on every supported platform.

Windows Windows archive (ZIP/7Z)

  1. 1

    Extract the recorded file (WinSCP-6.5.6-Portable.zip) into a separate folder and check the publisher's instructions for the executable or setup program inside. ZIP/7Z describes compression, not installation behavior.

  2. 2

    A no-installer build may still store settings, credentials, caches, or Registry entries outside that folder. Check WinSCP's configuration and removal instructions before moving or deleting it.

Windows Windows installer (EXE)

  1. 1

    Download the recorded file (WinSCP-6.5.6-Setup.exe). If it has a digital signature, inspect the signer and validation result in Properties → Digital Signatures. If no signature is present, follow the publisher's documented verification method; a missing signature does not authenticate the file.

  2. 2

    Check any Windows warning before proceeding. A SmartScreen reputation warning is not signature verification; stop if the publisher is unexpected or the file is reported as malicious.

  3. 3

    Follow the publisher's setup prompts to finish; options vary by release, so review each screen rather than clicking through.

Windows Windows installer (MSI)

  1. 1

    Download the recorded file (WinSCP-6.5.6.msi); MSI packages install through Windows Installer. Required privileges depend on the package's supported user or machine scope.

  2. 2

    Run it interactively, or deploy silently with msiexec /i and the vendor's documented properties for managed rollouts.

More Developer Tools Source Guides

View all Developer Tools

Also Popular on OfflineInstallerSetup

Browse all software