Skip to content

rclone Bridge ​

AeroFTP stands on the shoulders of a giant. rclone is the gold standard in file transfer and cloud synchronization - a project that has redefined what a command-line tool can do. With 70+ backends, a thriving community, and over a decade of relentless development, rclone has set the bar for every tool in this space, including ours.

This integration is our way of building a bridge, not a wall. If you use rclone, AeroFTP welcomes you with open arms. Your configuration, your remotes, your workflow - bring it all.

What this does ​

AeroFTP and rclone are fully interoperable. Import and export server profiles freely between the two tools through the shared rclone.conf format.

This bridge page covers profile interoperability through rclone.conf. If you need compatibility guidance for existing encrypted rclone crypt remotes, see rclone crypt interoperability.

Import (rclone to AeroFTP) ​

  • Reads your rclone.conf directly (auto-detected or manually selected)
  • Maps rclone remote types to AeroFTP protocols
  • Upgrades credential security: rclone stores passwords using reversible obfuscation (AES-256-CTR with a published key). AeroFTP de-obfuscates them and stores them in an AES-256-GCM encrypted vault with Argon2id key derivation - a significant security improvement with zero effort on your part
  • Available in the GUI (Settings > Export/Import > Import from rclone) and CLI (aeroftp-cli import rclone)

Export (AeroFTP to rclone) ​

  • Exports your server profiles to a standard rclone.conf file
  • Passwords are obfuscated using rclone's own scheme for full compatibility
  • OAuth profiles are exported too, for every provider with a matching rclone backend: Google Drive, Dropbox, OneDrive, Box, pCloud, Yandex Disk, Zoho WorkDrive and Jottacloud. Each remote is written with its client_id, client_secret and token, so it is usable and refreshable without re-authorising
  • Use it to share configurations, set up rclone on a server, or simply keep a portable backup
  • Available in the GUI (Settings > Export/Import > Export to rclone)

The OAuth export needs all three credentials in the vault, which is the case for a profile you authorised in AeroFTP with your own OAuth app. When one of them is missing, the remote is still written and a comment tells you to run rclone config reconnect <remote>: before use, rather than emitting a silently broken half-remote. Jottacloud is the one exception in shape: it carries an OIDC refresh token that rclone exchanges on first use, so no interactive re-login is needed there either.

Keep in mind that AeroFTP and rclone use different redirect URIs. Register both under the same app in the provider's developer console so one client_id and client_secret pair works in both tools.

Since v4.2.1 the export also covers Internxt (email + obscured password; rclone derives the rest on rclone config reconnect <remote>: - note that some Internxt plans, the free one included, do not allow rclone access), and Drime, Cloudinary and ImageKit export to and import from rclone.conf in both directions. The providers with no rclone export today are 4shared, kDrive, FileLu and Proton Drive; those entries are emitted as # manual setup required comments instead (FileLu and Proton Drive hold credentials rclone cannot use: rclone's FileLu backend signs in with the separate FileLu Rclone key, and Proton Drive is reached through Proton's own CLI without a stored password).

No vendor lock-in. Your data, your choice.

Re-import profiles imported before v4.2.1

Before v4.2.1, keys rclone writes in plain text (S3, Azure Blob, Swift and B2 keys, and the Drime, Cloudinary and ImageKit secrets) went through the reveal codec on import, and a small share was stored corrupted. Since v4.2.1 they are imported exactly as written. A profile imported from rclone that fails to sign in should be imported again.

Supported rclone backends ​

rclone typeAeroFTP protocolCredentialsNotes
ftpFTP / FTPSPassword (revealed + vault stored)tls = true mapped to FTPS
sftpSFTPPassword (revealed + vault stored)SSH key auth requires manual setup in AeroFTP
s3 (AWS)S3Access Key + Secret (vault stored)Region, endpoint, bucket preserved
s3 (Cloudflare R2)S3Access Key + Secret (vault stored)Mapped to Cloudflare R2 provider
s3 (Backblaze B2)S3Access Key + Secret (vault stored)Mapped to Backblaze B2 provider
s3 (DigitalOcean)S3Access Key + Secret (vault stored)Mapped to DigitalOcean Spaces
s3 (Wasabi)S3Access Key + Secret (vault stored)Mapped to Wasabi provider
s3 (MinIO)S3Access Key + Secret (vault stored)Path-style access enabled
s3 (other)S3Access Key + Secret (vault stored)Generic S3-compatible
webdavWebDAVPassword (revealed + vault stored)Nextcloud/ownCloud vendor detected
driveGoogle DriveOAuth (re-auth required)Profile imported, re-authenticate in AeroFTP
dropboxDropboxOAuth (re-auth required)Profile imported, re-authenticate in AeroFTP
onedriveOneDriveOAuth (re-auth required)Profile imported, re-authenticate in AeroFTP
megaMEGAPassword (revealed + vault stored)Native API mode
boxBoxOAuth (re-auth required)Profile imported, re-authenticate in AeroFTP
pcloudpCloudOAuth (re-auth required)Profile imported, re-authenticate in AeroFTP
azureblobAzure Blob StorageAccount Key (vault stored)Container name preserved
swiftOpenStack SwiftPassword/Key (vault stored)Auth URL, region, tenant preserved
yandexdiskYandex DiskOAuth (re-auth required)Profile imported
koofrKoofrPassword (vault stored)Endpoint preserved
jottacloudJottacloudOAuth (re-auth required)Profile imported
b2S3 (Backblaze B2)Account Key (vault stored)Mapped to S3-compatible endpoint
opendriveOpenDrivePassword (vault stored)Username + password
internxtInternxtPassword (revealed + vault stored)Also exported by AeroFTP; needs one rclone config reconnect before use
filenFilenPassword + CLI API key (vault stored)Native API mode
zohoworkdriveZoho WorkDriveOAuth (re-auth required)Profile imported
drimeDrime CloudAPI token (as written)Remotes pinned to a workspace or root folder id are skipped with the reason
cloudinaryCloudinaryCloud name + API key + secret (as written)Remotes on a regional upload_prefix are skipped with the reason
imagekitImageKitURL endpoint + public key + private key (as written)Export needs the public key, which a profile created in AeroFTP does not hold

23 rclone types mapped to AeroFTP protocols, covering the most widely used cloud and server backends.

What about unsupported backends? ​

rclone supports 70+ backends. We currently map 23 of them. Remotes with unsupported types (e.g., fichier, compress, union, chunker) are listed in the import dialog with their type name so you know exactly what was skipped and why.

The bridge works both ways, though. AeroFTP natively supports several providers that rclone does not integrate, including GitHub and GitLab (repository and release browsing), KDrive (Infomaniak), and 4shared. We are also the first file manager to offer native integration with Immich, the open-source, self-hosted photo and video management platform. As a fellow open-source project, supporting Immich felt like a natural fit. These providers are exclusive to AeroFTP and are not part of the rclone import/export mapping.

We are actively adding support for more backends. If your favorite rclone remote type is missing, open an issue and we will prioritize it.

GUI usage ​

  1. Open Settings > Export/Import
  2. In the rclone section, click Import from rclone
  3. AeroFTP auto-detects your rclone.conf - or click Browse to select it manually
  4. Review the list of detected remotes, deselect any you don't need
  5. Click Import - credentials are stored in your encrypted vault

For export, select Export to rclone, choose which servers to include, and save the .conf file.

CLI usage ​

bash
# Auto-detect rclone.conf and scan
aeroftp-cli import rclone

# Specify path explicitly
aeroftp-cli import rclone ~/.config/rclone/rclone.conf

# JSON output for scripting and automation
aeroftp-cli import rclone --json

Filter file conversion ​

Beyond the server profiles in rclone.conf, rclone users often maintain --filter-from files with +/- rules that drive rclone copy / rclone sync operations. AeroFTP can convert those files into .aeroignore (gitignore syntax) so the same rules apply to aeroftp-cli sync, copy, and AeroCloud:

bash
# Convert and inspect on stdout
aeroftp-cli import rclone-filter ~/.config/rclone/filter.txt

# Write to .aeroignore in your project root
aeroftp-cli import rclone-filter filter.txt -o /project/.aeroignore

# Pipe-friendly (read filter from stdin)
cat my-filter.txt | aeroftp-cli import rclone-filter -

# Machine-readable (status + warnings)
aeroftp-cli import rclone-filter filter.txt --json

The converter handles the first-match-wins → last-match-wins semantic gap automatically by reversing the rule order: a rule that appeared first in the rclone filter file ends up last in the generated .aeroignore, where it wins under gitignore's last-match-wins rule. + pattern includes become !pattern re-includes.

Two non-fatal warnings may be reported:

  • ! reset directive: rclone clears all rules above the reset at runtime; the converter keeps them and surfaces a warning so you can prune them manually if needed.
  • {a,b} brace alternation: gitignore does not support brace expansion. The pattern is preserved as-is; expand manually if needed.

See the import rclone-filter reference for full options, JSON envelope, and exit codes.

Security comparison ​

AspectrcloneAeroFTP
Password storageAES-256-CTR with published key (reversible)AES-256-GCM + Argon2id vault (authenticated encryption)
Config file permissionsUser responsibilityAutomatic 0600 + encrypted at rest
OAuth tokensStored in rclone.conf (plaintext JSON)Stored in encrypted vault
Master passwordNot availableOptional Argon2id-protected vault lock
Memory zeroizationNot guaranteedPasswords cleared from RAM after use

When you import from rclone, your credentials are automatically upgraded to the stronger security model. No extra steps needed.


rclone is a trademark of Nick Craig-Wood. AeroFTP is not affiliated with or endorsed by the rclone project. We are simply grateful users who built a bridge.

aeroftp.app - Released under the GPL-3.0 License. AeroFTP Reviews