Host keys
What a host key is
Every server proves its identity with a host key. When you connect, the server sends its key. Termphin checks it against the keys it already knows. If the key is new, Termphin shows you its fingerprint and asks you to accept it. If the key changed, Termphin refuses to connect until you confirm the change.
This check protects you from connecting to the wrong server. Someone who tricks you into connecting to their machine instead of yours can see everything you type, including passwords.
Pinned keys
The first time you connect to a server, Termphin shows you the key type and fingerprint. If you accept it, Termphin pins the key. Pinned keys are listed in Settings under "Known hosts" - "Host keys this device trusts".
Each entry shows the address and port, the full fingerprint (selectable, so you can compare it against the server), the key type, and when you pinned it. If nothing is pinned yet the list says "No host keys pinned" and "A server's key is pinned here the first time you accept it while connecting."
Why a pin is keyed by address, port, and key type
A pin is keyed by address, port, and key type. This matters because one server can offer several keys of different types. If Termphin only used the address, switching between a server's own keys would look like the key changed.
Changed keys
If a server's key changes - because the server was rebuilt or the key was rotated - Termphin shows a warning. The message says "The key this address presented is not the one Termphin pinned." It also says "Only accept this if you know the server's key changed."
To handle a legitimate change, go to Settings - "Known hosts" and tap "Forget" on the old key. The next time you connect, Termphin will ask you to accept the new key. This is done calmly in Settings, not during a connection.