Skip to content

SSH says the host key has changed

Understand the SSH warning about a changed host key, check that the server is really Avaloi, then remove the old entry from known_hosts and connect again.

Parts of this feature are still being built. The Not yet section lists them.

SSH keeps a record of each server's host key in a file called known_hosts on your computer. When the key the server shows does not match the record, SSH stops and warns you. This usually means the server was rebuilt or moved, which is normal after a restore or a node change. It can also mean someone is intercepting the connection. Check before you accept the new key.

What you see

  • "WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!" and a line that says the connection is refused.
  • An SFTP client that refuses to connect and mentions the host key.
  • The warning started after a restore, a clone of the environment, or an environment moved to another server.

Check these first

  1. Confirm the host and the user. Open SSH and SFTP for the environment and copy the host name and the port exactly as shown. A typo sends you to a different machine, which also gives this warning.
  2. Check the environment history. Open Activity for the site. If there was a restore, a move, or a rebuild in the last few days, the new key is expected.
  3. Check the connection from an allowed address. If you set allowed IP addresses for SSH, your address must be on the list. A blocked address gets a refusal, not a key warning, so this check rules out the other common cause.

Fix it

  • If the change is expected, remove the old entry for that host from your known_hosts file. On Windows the file is usually C:\Users\<you>\.ssh\known_hosts. Delete only the line for the Avaloi host, then connect again and accept the new key.
  • If you cannot tell whether the change is expected, do not accept the key. Ask support to confirm the key for the environment before you connect.
  • If the SFTP client keeps its own list of host keys, remove the entry there too.

Not yet

  • The dashboard does not yet show the host key fingerprint next to the connection details. Until it does, support can confirm the fingerprint for you on request.

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.