Chapter 11 of 12
Troubleshooting & Known Limitations
A quick-lookup table for common symptoms, plus a short list of things that are current, deliberate limitations rather than bugs. Every row links back to the use case with the full explanation and step-by-step fix.
Troubleshooting Index
Purpose
- Jump straight to the right use case for a symptom you're seeing, instead of reading the whole guide top to bottom.
- Blank/white screen on launch Front-end regression after an update — restart the app fully (full quit, not just closing the window); see Getting Started.
- "Permission denied (publickey)" Wrong key/passphrase, or the public key isn't in the server's authorized_keys — see SSH: Password & Key-Based Authentication.
- Unexpected host-key / certificate trust prompt Expected on a genuinely new host; suspicious on one you've connected to before — see SSH: Host Key Trust (TOFU) & Certificate Revocation.
- RDP black screen after connect Usually an NLA/Domain field mismatch — see RDP: Basic RDP Connection.
- A saved host "disappeared" Almost always a different active Profile, or a Host-visibility group filter — see Getting Started: Profiles and Session Management: Organizing Connections with Groups.
- Group credential/bastion inheritance not applying Host has no group, the wrong group, or its own explicit value already set (which always wins) — see SSH: Groups & Inherited Credentials.
- AI Assistant says "not configured" after adding a key Reopen the panel once (availability re-checks per open, not cached); confirm Enable is checked and a real model ID is set — see Automation: AI Assistant.
- Garbled/escape-code text in a terminal export or preview A too-narrow ANSI-stripping pattern — fixed in current builds; confirm you're up to date — see Session Management: Recording, Exporting, Searching & Command History.
- Locked out of Personal Vault / Team Vault / Cloud Vault Each tier's master password / device keys / recovery code is non-recoverable by design — see Vault System & Password Manager.
- Monitor graphs empty or mixed between hosts Confirm the shell supports the underlying probe commands; per-session history isolation is fixed in current builds — see Monitoring & Diagnostics: Monitor.
- Audit Log "Verify integrity" reports a break Take this seriously — investigate what touched the underlying log file rather than dismissing it — see Monitoring & Diagnostics: The Tamper-Evident Audit Log.
- Deployed/deauthorized a key and now can't connect Always deploy the new key before removing the old one — see Monitoring & Diagnostics: Key Lifecycle.
- MCP tool call refused Tripped the policy denylist deliberately — see Automation: MCP Server.
Known Limitations
Purpose
Things that are current, intentional constraints of this build — not bugs to report, though worth knowing before you rely on them.
- PKCS#11 hardware-token auth is RSA-only in the current release — ECDSA tokens aren't yet supported.
- Windows Hello / Secure Enclave SSH keys use RSA 2048 on Windows (a real, tested limitation of the current Windows NGC API surface) and ECDSA P-256 on macOS Secure Enclave — the two platforms deliberately use different algorithms for this reason.
- Multi-monitor RDP is explicitly experimental — behavior may be inconsistent across setups.
- "Follow server sshd log" is POSIX-target-only — not available for Windows RDP/SSH targets.
- Password Manager entries are Personal-Vault-only for now — not yet shared through Team Vault, Self Hosting Vault, or Cloud Vault.
- Team Vault, Self Hosting Vault, and Cloud Vault are all non-recoverable by design if every device and recovery code is lost — this is the intended tradeoff of genuine zero-knowledge encryption, not an oversight.
- Cloud Vault (hosted) is in beta with manually-toggled paying-tier access rather than live billing.
- The macOS Secure Enclave and Touch ID code paths are implemented against documented Apple APIs but, at the time of writing, verified primarily on Windows — if something behaves unexpectedly on macOS specifically, it's worth reporting with details.