# ConnectBot: the original Android SSH client, and what its two APK variants mean for you

> ConnectBot is an Apache-2.0 SSH client for Android built on a fork of Trilead SSH-2 and a separate terminal emulator library. It installs from Google Play or as a google/oss APK from GitHub, and the two download paths have different signature rules.

**connectbot/connectbot** — ConnectBot is the first SSH client for Android.

- Repository: https://github.com/connectbot/connectbot
- Website: https://connectbot.org
- Stars: 3,480 · Forks: 736
- Language: Kotlin
- License: Apache-2.0
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/connectbot-connectbot

## What ConnectBot actually is, and who reaches for it

ConnectBot is a Secure Shell client for Android. The README describes it in one line: a client that connects to remote servers over a cryptographically secure link. It is written in Kotlin, licensed Apache-2.0, and the source lives at github.com/connectbot/connectbot with the project homepage at connectbot.org.

The audience is narrow and specific. This is for someone holding an Android phone or tablet who needs a terminal session on a machine that only speaks SSH, and who does not want that session to depend on a desktop, a browser tab, or a vendor account. The README offers no hosted service, no sync backend and no team features, so the tool assumes you already have a host, a port and a credential and just need a client.

The project's age shows in its dependencies rather than its UI. The app is assembled from two libraries: ConnectBot Terminal, the terminal emulator, and a fork of Trilead SSH-2, described in the README as heavily modified from Christian Plattner's original Java library. Both are maintained by the same author, Kenny Root. That is a meaningful architectural fact: the SSH transport and the terminal rendering are not upstream projects with their own release cadence, they are parts of one maintainer's stack, and the recent release list shows dependency bumps such as termlib moving from 0.3.4 to 0.3.5.

## How the SSH stack, terminal library and app fit together

The data flow is conventional for a terminal app but worth stating plainly because it explains the APK sizes. A keystroke enters the Android input layer, the app hands it to the terminal emulator from ConnectBot Terminal, the emulator produces the byte sequence the remote shell expects, and the SSH library encrypts and sends it over the socket. Output travels the other way: the SSH library decrypts, the terminal emulator interprets escape sequences, and the app renders the result.

The split matters because the terminal emulator is a separate repository. Keyboard quirks, escape sequence handling and rendering fixes land in termlib and then arrive in the app through a version bump. The release history shows exactly this pattern, with a commit titled chore(deps): bump org.connectbot:termlib from 0.3.4 to 0.3.5. If you file a bug about how a key behaves, the fix may not be in the app repository at all.

The cryptography provider is the other architectural fork in the road, and it is the reason two APK variants exist. The google variant relies on Google Play Services to handle upgrading the cryptography provider. The oss variant bundles the cryptography provider inside the APK, which the README says increases its size by a few megabytes. That is the whole trade: a smaller download that depends on Play Services, or a larger, self-contained one.

## Installing ConnectBot: Play Store versus the oss APK

The README calls the Play Store the easiest route, and the package is org.connectbot. If you install from a downloaded APK instead, the README notes that Play can still upgrade your installed version to the latest one. The consequence is the part people miss: once Play has upgraded the app, you can no longer install a version from the GitHub releases, because of key rotation that upgrades the package signature to a more secure algorithm. Decide your install channel before you install, not after.

For a sideloaded build, pick the variant deliberately. The google build uses Google Play Services for cryptography provider upgrades and stays smaller. The oss build carries the provider inside the APK and is a few megabytes larger.

Building from source is documented for both Android Studio and the command line. The README says to import the project from the GitHub URL in Android Studio's project creation screen. On the command line, the only prerequisite named is the SDK location:

```bash
export ANDROID_SDK_HOME=/path/to/your/android/sdk
./gradlew build
```

The README states that ANDROID_SDK_HOME must be set before invoking the Gradle wrapper, and that ./gradlew build is the build command. It also says that running ./gradlew build should cover all the checks in the GitHub Actions workflow, so a local build is the normal verification step. If you want to run the CI workflow itself, the README points at nektos/act, which requires Docker to be installed and running:

```bash
act -W .github/workflows/ci.yml
```

The workflow file is .github/workflows/ci.yml. Note what the README does not provide: no signing instructions for producing your own release APK, no published minimum Android version, and no step-by-step first-connection walkthrough. The first real use is the obvious one, adding a host and connecting, but the README does not spell out the screens.

## Where ConnectBot is the wrong tool

ConnectBot is a terminal client, and the README describes nothing beyond that. There is no file-transfer UI documented, no SFTP browser, no port-forwarding manager described in the README, and no configuration sync between devices. If your workflow is moving files to a server, or keeping the same host list on a phone and a laptop, this project gives you no documented answer.

The install-channel rule is a second real constraint rather than a footnote. If you start with the Play build and later want the GitHub release build, the README says you cannot go back to a GitHub release after Play has upgraded the package signature. That is a one-way door for that device, and it is worth knowing before you hand the phone to someone else to set up.

The dependency structure is a third limitation. Because the SSH library is a heavily modified fork of Trilead SSH-2 maintained in a separate repository, you are trusting one project's maintenance of a protocol implementation rather than a widely used upstream. That is not automatically bad, and the fork exists for a reason, but it means protocol-level questions have one place to be answered, not a broad ecosystem.

Finally, the README is silent on the things a security-minded adopter would ask first: which key types are supported, how host keys are verified and stored, and what happens to saved credentials. The documentation does not answer those, so treat the README as a build and install document, not a security specification.

## ConnectBot versus Termux, and what the comparison actually turns on

People search for connectbot vs termux, and the difference is conceptual rather than a feature checklist. ConnectBot is a client. It opens a session to a remote machine and renders it. Termux is a terminal environment that runs on the device itself. If your goal is to run commands locally on the phone, ConnectBot is the wrong category of tool entirely, and no amount of configuration changes that.

If your goal is to reach a server, the distinction flips. ConnectBot's whole surface is that connection: host entries, keys, sessions. It does not ask you to install a package manager or set up a local filesystem to be useful. That is the trade, and it is why the two tools show up in the same search even though they solve different problems.

The comparison against other Android SSH clients turns on the same axis plus one more. ConnectBot is Apache-2.0 and its source is public, with the SSH library and terminal emulator also public and maintained by the same author. That is the argument for it over a closed client: you can read the transport code and the terminal code. The argument against it is the one above, that a single maintainer carries all three components. The README does not compare ConnectBot to any other client, so any claim about a specific competitor's behaviour has to come from that competitor's documentation, not this one.

## Maintenance, licensing and what an upgrade costs you

The repository is not archived. The most recent push recorded is 2026-09-23, the same day as the newest release tag, git-v1.10.9-126-g754c7f28, whose message is feat: edit profile from edit host screen. The two preceding tags that day were a keyboard fix adding a session picker dialog to modal tracking, and the termlib dependency bump. That is a project shipping small, frequent changes rather than large releases.

The naming convention is worth understanding before you plan an upgrade. Tags look like git-v1.10.9-126-g754c7f28, which is a version plus a commit count and hash, not a clean semantic version. If your process expects to pin a tidy release number, you will be pinning a tag that encodes the exact commit. The CHANGELOG.md at the repository root is the place to read what changed between them.

Licensing is Apache-2.0, which is a permissive licence with a patent grant. That is a statement about the licence text, not legal advice; if you redistribute a modified APK, read the LICENSE file at the repository root and the NOTICE requirements yourself. One practical implication of the fork structure: the SSH library and the terminal emulator are separate repositories, and their licences are separate questions from this one.

The upgrade cost is mostly the install channel. If you are on Play, upgrades are automatic and you never think about it. If you sideload, you own the update loop, and the README's warning about signature rotation means a switch between channels is not a simple reinstall.

## Conclusion

ConnectBot fits engineers who want a plain SSH client on Android with no account and no vendor service in the path, and who are willing to read the release notes for keyboard behaviour. Avoid it if you need a built-in file browser, SFTP UI or cloud sync; the README documents none of those, and its SCP support is not described there either. Before adopting it, check which APK variant you are installing, because the README states that a Play-installed copy cannot later be replaced by a GitHub release build, and confirm the current release tag on the GitHub releases page rather than trusting a store listing.

## FAQ

### What is ConnectBot used for?

It is a Secure Shell client for Android that connects to remote servers over a cryptographically secure link, as the README puts it. You use it to open a terminal session on a remote machine from a phone or tablet.

### How do I use ConnectBot on Android?

Install it from Google Play, or download the google or oss APK from the GitHub releases page, then add a host and connect. The README documents installation and building but does not walk through the host-entry screens, so the first connection is not spelled out there.

### Is ConnectBot safe?

The README describes it as connecting over a cryptographically secure link and notes that the google build uses Google Play Services to handle upgrading the cryptography provider while the oss build includes that provider in the APK. The README does not document key types, host key verification or credential storage, so those questions are not answered by the project's own install documentation.

### What is ConnectBot?

ConnectBot is a Secure Shell client for Android that lets you connect to remote servers over a cryptographically secure link. It is written in Kotlin and licensed Apache-2.0, with its source at github.com/connectbot/connectbot.

## Sources

- [connectbot/connectbot on GitHub](https://github.com/connectbot/connectbot)
- [License: Apache-2.0](https://github.com/connectbot/connectbot/blob/main/LICENSE)
- [Project website](https://connectbot.org)
- [README](https://github.com/connectbot/connectbot/blob/main/README.md)
- [Releases](https://github.com/connectbot/connectbot/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/connectbot-connectbot
