Home AssistantSAFE
A MCP server for Home Assistant
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The server uses the MCP protocol to share access to a local Home Assistant instance with an LLM application.
A powerful bridge between your Home Assistant instance and Language Learning Models (LLMs), enabling natural language control and monitoring of your smart home devices through the Model Context Protocol (MCP). This server provides a comprehensive API for managing your entire Home Assistant ecosystem, from device control to system administration.
Features
- 🎮 Device Control: Control any Home Assistant device through natural language
- 🔄 Real-time Updates: Get instant updates through Server-Sent Events (SSE)
- 🤖 Automation Management: Create, update, and manage automations
- 📊 State Monitoring: Track and query device states
- 🔐 Secure: Token-based authentication and rate limiting
- 📱 Mobile Ready: Works with any HTTP-capable client
Real-time Updates with SSE
The server includes a powerful Server-Sent Events (SSE) system that provides real-time updates from your Home Assistant instance. This allows you to:
- 🔄 Get instant state changes for any device
- 📡 Monitor automation triggers and executions
- 🎯 Subscribe to specific domains or entities
- 📊 Track service calls and script executions
Quick SSE Example
const eventSource = new EventSource(
'http://localhost:3000/subscribe_events?token=YOUR_TOKEN&domain=light'
);
eventSource.onmessage = (event) => {
const data = JSON.parse(event.data);
console.log('Update received:', data);
944eed6f9e83OBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add homeassistant-mcp --env CLAUDE_API_KEY=${CLAUDE_API_KEY} --env HASS_TOKEN=${HASS_TOKEN} --env TEST_HASS_TOKEN=${TEST_HASS_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"homeassistant-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CLAUDE_API_KEY": "${CLAUDE_API_KEY}",
"HASS_TOKEN": "${HASS_TOKEN}",
"TEST_HASS_TOKEN": "${TEST_HASS_TOKEN}"
}
}
}
}Exposed tools (14)
12 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
HACS | read | Home Assistant Community Store |
addon | write | Manage Home Assistant add-ons |
automation | read | Manage Home Assistant automations |
automation_config | read | Advanced automation configuration and management |
control | read | Control Home Assistant devices and services |
get_history | read | Get state history for Home Assistant entities |
get_sse_stats | read | Get SSE connection statistics |
list_devices | read | List all available Home Assistant devices |
notify | write | Send notifications through Home Assistant |
package | read | Manage HACS packages and custom components |
scene | read | Manage and activate Home Assistant scenes |
simple_tool | read | A simple tool |
subscribe_events | read | Subscribe to Home Assistant events via Server-Sent Events (SSE) |
test_tool | read | A test tool |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
const HASS_HOST = process.env.HASS_HOST || 'http://192.168.178.63:8123';
import { IntentClassifier } from '../../../src/ai/nlp/intent-classifier.js';import { DomainSchema } from '../../src/schemas.js';import { ContextManager, ResourceType, RelationType, ResourceState } from '../../src/context/index.js';import { HassInstanceImpl } from '../../src/hass/index.js';import * as HomeAssistant from '../../src/types/hass.js';
@digital-alchemy/core, @digital-alchemy/hass, ajv, dotenv, express, express-rate-limit, helmet, litemcp
Gates applied: no_behavioural_pass.
944eed6f9e83full audit observations/trust-audit/mcp-server/tevonsb__home-assistant-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 944eed6f9e83 | SAFE | B | 89 | first audit |
Questions
What is the Home Assistant MCP server?
A MCP server for Home Assistant
What tools does Home Assistant expose?
14 in total: 12 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Home Assistant safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Home Assistant need?
It reads CLAUDE_API_KEY, HASS_TOKEN and TEST_HASS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (944eed6f9e83), read on 2026-09-29. The repository is watched and re-audited when it changes.