Client certificates
Using mutual TLS so the server can authenticate the app.
Some installations require the client to present a certificate as well as a password. The app supports this, but only on the phone.
Setting one up
Install the certificate in Android first (Settings → Security → Encryption & credentials), then choose it in the app when the server asks for it. The app never holds the private key itself — Android does, and only releases it to the connection.
Why the watch cannot do this
A Wear OS watch has no certificate store of its own, so it cannot present one. When your server requires a certificate, pair the watch from the phone instead: the phone completes the handshake and passes the resulting token to the watch.