Skip to main content
Selora Homes Selora Homes

Local HTTPS Support for Home Assistant

Add HTTPS support for local Home Assistant access to encrypt traffic on the local network.

Roadmap Home-Assistant Security Homeowners

Summary

By default, Home Assistant listens on port 80 (HTTP), which means sensitive data — including authentication credentials and long-lived tokens — flows in clear text on the local network. While Remote Access via Selora is always encrypted, local access remains unencrypted.

This roadmap item adds native HTTPS support for local Home Assistant access, ensuring all traffic on the local network is encrypted. This is especially important for customers who may use long-lived tokens in companion apps or automations.

Problems Addressed

  1. Local traffic exposure: Authentication and API traffic are sent in clear text on the local network, which can be intercepted.
  2. No access when internet is down: Relying solely on Remote Access means customers lose access to their Home Assistant if the internet is down, despite being on the same local network.
  3. Matter over Thread pairing requirement: Matter over Thread pairing requires being on the same network in the companion app, which is impractical if the only secure path is via Remote Access.

Solution

Enable HTTPS locally for Home Assistant instances managed by Selora, using automatically generated and managed TLS certificates for local access. The companion app will prefer local HTTPS when on the same network, falling back to Remote Access when needed.

Benefits

  • Encrypted local traffic: Authentication and long-lived tokens are protected even on the local network.
  • Resilient local access: Customers retain full access during internet outages.
  • Matter/Thread support: Enables local pairing workflows required by Matter over Thread.

Type to search across cities, counties, and installers

↑↓ navigate open
⌘K search