Connect for the first time
The six checks from server access to Keycloak login.
Use a server and Keycloak deployment you own or are authorized to administer. You need an SSH hostname, SSH port and username, an SSH private key with any passphrase, and the server-side private HTTP port and base path used by Keycloak.
Create the connection profile, import the key with the Android file picker, and leave Advanced mode off for a standard connection. Confirm the target details before connecting. The app does not create an SSH account, install Keycloak, or recover an administrator password.
The first connection stops for host verification. Compare the displayed SSH fingerprint with an independent trusted server console or administrator before approving it. Reconnect after approval, open the Keycloak console, then use your own Keycloak login and MFA.
Successful SSH authentication does not grant Keycloak permissions. The normal console can change server records according to your Keycloak roles. Use a test realm first, maintain backups, and stop the tunnel when finished.