Syncthing Explained: Peer-to-Peer File Sync Without a Cloud
Syncthing keeps folders identical across your computers, phone, and servers, syncing directly between your own devices. There is no cloud account, no central server, and no company holding a copy of your files. Every connection is encrypted and authenticated.
It is one of the most popular self-hosted tools because there is nothing to host: install it on two machines, introduce them to each other, and pick folders to share. Our Syncthing app page summarises the project; this guide covers how it works and how to run it well on Linux.
How it works
Device IDs
Each Syncthing install generates a TLS certificate on first run. Its Device ID is derived from that certificate, a long string like:
MFZWI3D-BONSGYC-YLTMRWG-C43ENR5-QXGZDMM-FZWI3DP-BONSGYY-LTMRWAD
Devices only talk to IDs you have explicitly added, and every connection is mutually authenticated with those certificates. Knowing a device ID does not let anyone connect to you; you still have to accept them.
Folders
A folder is a directory shared between two or more devices. Each folder has an ID and a type:
| Type | Behaviour |
|---|---|
| Send and receive | The default. Changes flow in both directions |
| Send only | This device’s version is authoritative. Remote changes are not applied |
| Receive only | Accepts changes but never sends local ones. Local edits are flagged |
| Receive encrypted | For untrusted devices: stores encrypted data it cannot read |
Send-only on a laptop plus receive-only on a server is a common pattern for one-way replication.
Finding each other
Devices discover each other on the local network by broadcast, and across the internet through global discovery servers, which only map device IDs to current addresses. Syncthing then tries a direct connection, using NAT traversal where it can.
If a direct connection is impossible, traffic goes through a relay, run by volunteers. Relays only ever see encrypted traffic, because the TLS session is between your devices. They are slower, so for reliable speed, make sure at least one device is directly reachable, or connect them over a VPN such as WireGuard or Tailscale.
Installing on Linux
sudo apt install syncthing # Debian / Ubuntu
sudo dnf install syncthing # Fedora
sudo pacman -S syncthing # Arch
The project also runs its own apt repository with newer releases than some distros ship.
Run it as a user service
Syncthing should run as your user, not root, so it syncs files with your ownership:
systemctl --user enable --now syncthing.service
systemctl --user status syncthing.service
To keep it running when you are logged out, which you want on a server or a desktop that syncs overnight:
sudo loginctl enable-linger "$USER"
The web GUI
Syncthing is managed through a web interface at http://127.0.0.1:8384. It listens only on localhost by default, which is the right choice. To manage a headless server, tunnel it over SSH rather than exposing it:
ssh -L 8384:127.0.0.1:8384 myserver
# then open http://127.0.0.1:8384 locally
Our SSH tunneling guide explains the -L flag. If you do expose the GUI, set a username and password in its settings first.
Ports
| Port | Protocol | Purpose |
|---|---|---|
| 22000 | TCP and UDP (QUIC) | Sync connections |
| 21027 | UDP | Local discovery |
| 8384 | TCP | Web GUI (localhost only by default) |
sudo ufw allow syncthing # uses the bundled ufw profile
Connecting two devices
- On device A, open Actions > Show ID and copy the ID
- On device B, click Add Remote Device and paste it
- Accept the prompt that appears on device A
- On either device, edit a folder and tick the other device under Sharing
- Accept the folder share on the other side and choose a local path
On a LAN, devices often find each other automatically and offer to connect.
Ignoring files
A .stignore file in the folder root excludes files from sync, using glob patterns:
// .stignore
node_modules
*.tmp
.cache
(?d).DS_Store
(?d) lets Syncthing delete those files if they block removal of a directory. Always ignore build output, caches, and dependency folders; syncing node_modules between machines is slow and pointless.
Versioning
If a file is changed or deleted by a remote device, file versioning can keep the old copy in a .stversions folder. Options range from trash can (keep the last deleted version) to staggered (keep versions at decreasing frequency over time) to external (run your own script).
Enable staggered versioning on at least one always-on device. It turns “I accidentally deleted a folder on my laptop and it vanished everywhere” into a recoverable mistake.
Syncthing is not a backup
This is the one mistake that loses data. Syncthing propagates changes, including deletions, corruption, and ransomware encryption. Versioning helps with recent mistakes, but it is not a backup:
- It only keeps versions of changes that arrived from other devices
- It is on the same devices as your data
- It is not designed for point-in-time restores
Use a real backup tool alongside it. restic or borg backing up one of the synced machines is the standard setup, and our automated backups guide covers scheduling it.
Untrusted devices
A receive encrypted folder lets a device you do not fully trust, such as a VPS or a friend’s server, store and relay your files encrypted with a folder password. It cannot read the contents or filenames. That gives you an always-on node that improves sync between your laptop and phone without exposing the data.
Syncthing or Nextcloud?
Nextcloud is a server you host, with clients that sync to it, plus web access, public share links, calendars, contacts, and office editing. Syncthing has no server, no web access to files, and no sharing with people outside your devices.
If you want your files on all your devices, Syncthing is simpler, lighter, and has almost nothing to maintain. If you want a private cloud for yourself or a group, Nextcloud does far more. Many people run both.
Frequently Asked Questions
What is Syncthing?
Syncthing is an open source continuous file synchronization program. It keeps chosen folders identical across your devices by syncing directly between them over encrypted connections, without a central server, cloud account, or third party holding your data.
Is Syncthing a backup?
No. Syncthing mirrors changes, so if a file is deleted, corrupted or encrypted by ransomware on one device, that change spreads to the others. File versioning helps recover recent mistakes, but a real backup needs separate, versioned copies made with a tool such as restic or borg.
Does Syncthing work over the internet?
Yes. Devices find each other through global discovery servers and connect directly, using NAT traversal where possible. If a direct connection is impossible, traffic goes through a community relay. Relays only see encrypted data, because the connection is end-to-end encrypted between your devices.
How do I run Syncthing in the background on Linux?
Enable the systemd user service with systemctl —user enable —now syncthing.service. It starts when you log in. To keep it running when you are logged out, for example on a server, run loginctl enable-linger for your user.
What is an untrusted device in Syncthing?
An untrusted device receives your files encrypted with a folder password, so it stores and relays the data without being able to read it. It is useful for an always-on server or a VPS that should hold a copy but should not have access to the contents.
How is Syncthing different from Nextcloud?
Nextcloud is a server you host that clients sync to, and it adds web access, sharing links, calendars and collaboration. Syncthing has no server and no web interface for files: every device is an equal peer. Syncthing is simpler for pure sync, while Nextcloud does much more.