Diagnose a failed connection
Work from network access through SSH and then Keycloak.
Timeout or unreachable host: confirm the SSH domain, network route, port and firewall with your administrator. Authentication failed: verify the SSH username, private key, passphrase and server authorization. A fingerprint warning must be resolved independently before continuing.
Forwarding denied: review the user’s effective SSH forwarding policy. Connection refused after SSH login: confirm Keycloak is running and reachable at the selected server-loopback HTTP port. A TLS-only listener or incorrect base path is a separate configuration problem.
Blank console or blocked redirect: check the Keycloak hostname, base path and same-origin browser limits. Login denied: check Keycloak credentials, MFA, roles and account status. Advanced mode errors: confirm the connector exists and returns supported bounded JSON.
Record the app version, Android/WebView version, selected mode, approximate time and a redacted error. Reproduce against an isolated test environment when possible. Never include private keys, passwords, tokens, cookies or real user records in a support message.