VNC is one protocol with several ways to sign in, and each server offers its own list. A connection works when the viewer and the server share one. On iPhone and iPad SSHive handles four: the classic VNC password, a challenge that protects the password but not the screen; RSA-AES, RealVNC's method, which encrypts the whole session; UltraVNC MS-Logon II, for Windows accounts on an UltraVNC server; and Apple Screen Sharing, the method macOS uses. It does not handle VeNCrypt, the TLS-based method that some Linux servers, wayvnc for one, can be set to require.
That explains most refused connections. A Mac answers with Screen Sharing, RealVNC Server with RSA-AES, and TigerVNC or x11vnc usually accept a VNC password. When a server insists on VeNCrypt, either change that on the server or connect from the Mac app, whose VNC viewer handles VeNCrypt with X.509 certificates.
SSH is how you protect a plain VNC session. In an SSH profile for the same machine, add a local tunnel (-L) from a port on the iPhone, 5901 for instance, to localhost:5900 on the server. Connect the SSH profile, then open a VNC profile pointed at 127.0.0.1, port 5901. The screen now travels inside the SSH connection, and the VNC port never has to be open to the network.
For control, SSHive starts in trackpad mode rather than tapping where you touch: on a phone, a fingertip hides the very button you are aiming at, while a cursor nudged with small swipes lands where you meant. Switch to direct touch once the desktop is zoomed in far enough to aim with a finger.