When something goes wrong

"Host key changed" warning

The server's fingerprint is not the one the app remembered. Sometimes that is harmless (the server was reinstalled) and sometimes someone is intercepting the connection. Do not just accept it. Ask your hosting provider or check the fingerprint in the provider's web console. Only if it matches, choose to replace the old key.

"Authentication failed"

  • Wrong username or password — check the identity under Settings → Identities.
  • The server accepts only keys — switch the identity to a key.
  • Using a key with a passphrase — enter the passphrase.
  • The username is right but the account is locked or has no permission to log in; ask the server's owner.

Forgot the master password

Use the recovery code shown when you created the vault: unlock screen → I forgot my password. Without the password and the recovery code, the data cannot be recovered — by design. Restoring from a .krbackup file requires the backup's password.

A tunnel does not work

  • The server may forbid tunnels (AllowTcpForwarding no); its owner can change it.
  • The target address is seen from the server: 127.0.0.1 means the server itself. A database in Docker must publish its port on the server.

Black screen or refused in Desktop

The server has no running desktop session, the password is wrong (the VNC limit is 8 characters), or the port differs. The Desktop tab shows the exact next step.

The relay "is not reachable"

Almost always DNS (the domain does not yet point at the server) or ports 80 and 443 are closed in the server's firewall. Fix that and press Install relay again.

Helper cannot connect to Assist

  • The ID or code was typed wrong or has expired — Assist shows a fresh code; ask for the new one.
  • You declined or ignored the question — the helper has to try again.
  • No internet on the Assist computer.

Still stuck

Write to us through the contact form on the website and include what you were trying to do and what the screen said.