Profile fields and ports
Keep the SSH port separate from the Keycloak HTTP port.
Profile name is your local label. Server/domain is the SSH host, without an https:// prefix or web path. SSH username and port identify the account and SSH listener. Port 22 is a common example, not a required setting.
Keycloak port is the private HTTP listener reachable from the SSH server on 127.0.0.1. Examples include 8080 or 9092. It is not the public HTTPS port. The embedded tunnel rejects TLS-only listeners such as a service on 443 or 8443; use an approved private HTTP listener behind SSH.
Base path must match the deployment: / for the root, or a configured prefix such as /id or /auth. Do not append /admin manually when the app builds the administration address.
Save only a profile you recognize. Changing a host or key can require a new independent fingerprint check. A saved profile is local to this Android installation; there is no ASL profile sync.