Pick your route first
| Route | Works behind CGNAT | Voice assistants and cloud webhooks | Cost |
|---|---|---|---|
| Home Assistant Cloud (Nabu Casa) | Yes | Yes, built in | Monthly subscription |
| VPN (WireGuard, Tailscale) | Tailscale: yes | No | Free |
| Reverse proxy + your own name (this guide) | No – needs a public IP | Yes, with extra set‑up | A domain |
If only you and your household use the phone app, a VPN is simpler and exposes nothing. Carry on here if you want a public HTTPS address – for family members who won’t run a VPN, for webhooks from other services, or because you like having your own name. Check first that your connection isn’t behind CGNAT.
Which port Home Assistant listens on
From Home Assistant 2026.8 the web server settings moved from configuration.yaml into the interface, under Settings → System → Network → HTTP server. At the same time, new Home Assistant OS installs started listening on port 80 instead of 8123. Container installs still use 8123, and upgraded systems keep the port they had. Check the Server port field on that page and use that number wherever this guide says “HA port”.
Upgraded from an older version?
If you still have an http: block in configuration.yaml, Home Assistant imported it on upgrade and raised a repair asking you to remove it. Do that before changing anything here, or you will be editing settings that are ignored.
1. Put a reverse proxy in front
You have two common choices:
- A proxy elsewhere on your network – Caddy or Nginx Proxy Manager on another machine, a NAS or a Proxmox container. The HTTPS guide covers both. Point
ha.yourname.uk.appathttp://<HA address>:<HA port>and make sure WebSockets are allowed (automatic in Caddy; tick Websockets Support in Nginx Proxy Manager). - A proxy app on Home Assistant OS itself – the Nginx Proxy Manager or NGINX SSL proxy apps (add‑ons have been called apps since Home Assistant 2026.2). Handy if HA is your only server.
Then tell Home Assistant to trust the proxy, or it will block every request that comes through it with 400: Bad Request:
- Go to Settings → System → Network and find HTTP server.
- Turn on Trust X‑Forwarded‑For.
- In Trusted proxies, add the proxy’s LAN address, for example
192.168.1.30. For a proxy app running on Home Assistant OS itself, add172.30.33.0/24, the network HA’s apps use. - Save. Home Assistant restarts, and an administrator has to confirm the new settings within five minutes or it rolls them back – so keep the page open.
Watch out
When you enter a range, use the network address (192.168.1.0/24), not a host address with a mask (192.168.1.30/24). Home Assistant’s documentation is explicit about this.
2. Forward the port on your router
Forward TCP 443 – and 80 if your proxy uses the HTTP‑01 certificate method – to the proxy’s LAN address. Do not forward Home Assistant’s own port. Router steps: BT, Virgin Media, Sky, TP‑Link, OpenWrt.
3. Let Home Assistant keep your name up to date
Home Assistant is always on, so it can run the dynamic DNS updater itself with the built‑in RESTful Command integration. In the uk.app dashboard, create a DDNS token for your name (My names → your name → Dynamic DNS), then add it to secrets.yaml:
ukapp_ddns_token: "paste-your-64-character-ddns-token"rest_command:
ukapp_ddns:
url: "https://ddns.uk.app/nic/update?hostname=home.yourname.uk.app"
username: "yourname.uk.app"
password: !secret ukapp_ddns_token
timeout: 20Restart Home Assistant, then create an automation (Settings → Automations & scenes → Create automation, then Edit in YAML) that calls it every five minutes and at start‑up:
alias: Update uk.app dynamic DNS
triggers:
- trigger: time_pattern
minutes: "/5"
- trigger: homeassistant
event: start
actions:
- action: rest_command.ukapp_ddns
mode: singleThe request leaves your house through your broadband, so the service records your public IP. Each call returns good <ip> when it changed the record and nochg <ip> otherwise. Test it from Developer tools → Actions by running rest_command.ukapp_ddns; the response appears below.
In the uk.app DNS settings, add a CNAME record ha → home.yourname.uk.app, so the proxy name follows the same address.
Tip
If you run Home Assistant behind a commercial VPN for outbound traffic, don’t use this method – it would publish the VPN’s address. Run the updater on your router instead.
4. Tell Home Assistant its external address
- In Settings → System → Network, under Home Assistant URL, set Internet to
https://ha.yourname.uk.app. - Leave Local network on automatic, or set it to
http://<HA address>:<HA port>. - In the Companion app on your phone, open the app’s settings, choose your server, and set its external (internet) URL to the same address. Add your home Wi‑Fi name so the app uses the local address at home.
5. Lock it down
- Turn on multi‑factor authentication for every user who signs in from outside: click your name at the bottom of the sidebar, open Security, and enable Authenticator app.
- In Settings → System → Network → HTTP server, turn on Enable IP banning and set a low number of Login attempts before ban, such as 5. Banned addresses land in
ip_bans.yaml; delete a line there to lift a ban. This only works properly once trusted proxies are set, or HA would ban the proxy itself. - Don’t put anything private in the
wwwfolder: files served under/local/need no login. - Keep Home Assistant and its apps updated; security fixes arrive in regular releases.
6. Check it from outside
- Does the name point home? Look up
ha.yourname.uk.appwith the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one. - Is the port open from the internet? Run the open port checker against port 443. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
- Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
- Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.
If it doesn’t work
- 400: Bad Request – the proxy isn’t in Trusted proxies, or Trust X‑Forwarded‑For is off. Check the Home Assistant log: it names the address it refused.
- The page loads but stays on “Connection lost” – WebSockets aren’t passing through the proxy.
- Works on mobile data, not at home – your router doesn’t do NAT loopback. Let the Companion app use the internal URL on your home Wi‑Fi.
- Certificate warnings – the proxy hasn’t got a certificate for the exact name. Check with the SSL checker.
- Port shows as closed – check double NAT and CGNAT.