"SFTP server" is now just "Server"
The machines you migrate to and from are called servers throughout the product, and the firewall address you need to allow is on screen where you need it.
The protocol was leaking into the product's vocabulary. A machine you own is a Server now — in the migration form, on the Credentials page (the tab is Servers), on the landing page, in the plan comparison and throughout the docs. The API is untouched: sourceType: "ssh", sshServerId and the rest are unchanged, and the API reference still documents them as they are.
Alongside it: jobs always connect out from one fixed address, and that address is now shown where you'd want it — in the migration form, in the Add Server dialog and in the migration guide. You can allow a single IP on your SSH port instead of opening it to the internet.