SSH key authentication is TitlePage's preferred way to connect over SFTP, whether you deliver ONIX files to TitlePage or receive ONIX or CSV files from TitlePage. It avoids using a reusable password and is supported by most modern SFTP clients and publishing systems. This article explains how to create your SFTP key, store it securely, and configure your connection.
Who this is for
This article is for anyone setting up a TitlePage SFTP connection using SSH key authentication, including publishers, distributors, and service providers who deliver ONIX files to TitlePage, and organisations such as bookstores who receive ONIX or CSV files from TitlePage.
Publisher folders and Data Editor access
A publisher folder is the secure SFTP location assigned to one publisher. ONIX files for that publisher are delivered to that folder. Publisher folders are kept separate so that files and access are correctly limited to the relevant publisher.
You can manage an SFTP account or deliver files for a publisher only when you have the Data Editor role for that publisher. Some people, such as service providers, are also a Data Editor for one or more client publishers. Each publisher you are authorised to work with appears as a separate publisher folder and SFTP account row.
Always check the publisher name and directory value before creating an account, downloading a key, or configuring a connection. Do not use one publisher's SFTP account to deliver files for another publisher.
The Data Editor role is separate from Company Admin, and being a Company Admin does not automatically grant it. If you cannot see View SFTP accounts in Security Centre, you do not currently have Data Editor access for a publisher or do not currently have MFA setup. A Company Admin for the relevant publisher can assign the Data Editor role to any user on the organisation's staff roster, following the APA Company Admin account guide. Role changes are then processed by the TitlePage team, typically within three business days. If you are unable to have the role assigned, contact the APA.
If you deliver files for a client publisher, its Company Admin must give you Data Editor access for that client publisher too. After the role is added, sign out and sign in again if the SFTP page does not appear straight away.
Before you begin
You need:
- a TitlePage account with the Data Editor role for the publisher folder you need
- an SFTP client or publishing system that supports SSH private-key authentication
- your publisher folder's SFTP username, shown in Security Centre
- a safe place to store the private key file
- an account protected by multi-factor authentication (MFA), which is required for this high-privilege role
Create your SFTP key
- Sign in to the TitlePage Security Centre (https://security.publishers.asn.au/).
- Select View SFTP accounts.
- Find the row for the publisher folder you need. Check the publisher name and directory value before continuing. If you have access to more than one publisher, select the folder for the publisher whose ONIX files you will deliver.
- Select Activate account.
- Read the confirmation screen. It explains that activation creates the SFTP account and a one-time SSH key pair.
- Select Activate only when you are ready to save the private key.
- Download the private key file. It will normally have a .pem filename extension.
The private key is shown or downloaded only at activation and when a key is regenerated. It cannot be recovered later.
Store the PEM private key securely
The PEM file is the private half of your SSH key pair. It proves that your system is allowed to connect as the relevant SFTP user. Treat it like a password:
- store it in an approved, access-controlled location
- restrict access to people and systems that need to transfer ONIX files
- do not email it, add it to a shared drive, or commit it to source control
- keep a documented record of the system and owner that use it
- if you think it has been exposed, replace it immediately
Do not rename, edit, or convert the file unless your SFTP client or publishing system specifically requires a different key format. Keep the original PEM file securely.
Connection information
Use the values below in your SFTP client or publishing system.
- Protocol: SFTP (SSH)
- Server / host: sftp.titlepage.com
- Port: 22
- Username: The username shown in the relevant Security Centre SFTP-account row
- Authentication method: SSH private key / key file
- Private key file: The PEM file downloaded at activation
Do not use an FTP or FTPS connection type. SFTP is a different protocol.
Configure your client or publishing system
The labels differ between products, but the steps are the same:
- Create a new SFTP connection or destination.
- Set the protocol to SFTP or SSH File Transfer Protocol.
- Enter sftp.titlepage.com as the host and 22 as the port.
- Copy the username from Security Centre for the selected publisher folder.
- Select SSH key, private key, key file, or similar as the sign-in method.
- Browse to the PEM private key file.
- Save the connection without saving the key in an insecure shared location.
Some publishing systems need the key pasted into a secure credential field rather than selected as a file. Use the system's secure-secret function and follow its documentation. Never paste the key into ordinary notes, email, or a support ticket.
Test the connection
- Connect using the configured destination.
- Confirm that the connection succeeds and that you can see the assigned publisher folder.
- If you deliver files, confirm that you can create or upload only an approved test file if APA has asked you to do so. Do not upload unrelated files. If you receive files, confirm that you can see and download the files provided in the folder.
- Check that your system reports a successful transfer.
- If you upload an ONIX file, follow the TitlePage file-naming requirements and check the resulting load report.
Record the test date, the publisher folder, and the system used. Do not record the private key itself.
What is a key fingerprint?
A fingerprint is a short identifier derived from an SSH key. In Security Centre, View key info shows the key ID, fingerprint, and date added. A fingerprint is useful when you need to confirm which key a system is using or when reporting a connection issue to APA.
The fingerprint is not the private key. You can share it with APA support when asked, but do not share the PEM file.
Common problems
- Connection is refused — Confirm the host is sftp.titlepage.com, the protocol is SFTP, and the port is 22.
- Authentication fails — Confirm the username matches the correct publisher row and that the client is using the matching PEM file.
- Client says the key format is unsupported — Check the client's documentation for PEM support or its approved key-conversion method. Keep the original PEM file secure.
- I cannot see View SFTP accounts or Manage SFTP accounts — Ask the relevant publisher's Company Admin to give you the Data Editor role, following the APA Company Admin account guide.
- You can connect but cannot find the expected folder — Check that you activated the intended publisher row and used its username. Contact APA before changing anything.
- A replacement key was generated — Update every authorised client or publishing system to use the new PEM file. The old key should no longer be relied on.
- You suspect the key was exposed — Regenerate the key promptly, update authorised systems, and contact APA if you need help assessing the connection.
Replacing or revoking a key
Security Centre shows Regenerate key and Delete actions for existing SSH-key accounts.
- Use Regenerate key when you need a new key. Plan the change first: the new private key must be downloaded and configured in every authorised system.
- Use Delete only when the connection is no longer required or APA has instructed you to remove it. This stops that account's SFTP access.
These actions affect an active connection. Check the publisher folder and notify affected colleagues or system owners before proceeding.
Access can also stop without either action. Because SSH keys are tied to an individual TitlePage user account, if that user is removed from the organisation or their Data Editor role is removed, the key stops working immediately.
Related articles
- Delivering and receiving files via SFTP: overview
- Delivering ONIX files using password authentication
Need help?
Contact TitlePage / APA support with the publisher name, directory value, username, key fingerprint (if relevant), the client or publishing system you are using, and the exact error message. If you need access, say that you need the Data Editor role for the named publisher. Never include the PEM private key or a password. You can contact TitlePage support for further help.
Comments
0 comments
Article is closed for comments.