A secure foundation
Review network security and safe updates.
You want to check the temperature at home or turn on a lamp from your phone while you are away. Before changing your router, choose an access method and decide how to verify it. This guide walks through Home Assistant Cloud and helps you choose a private VPN if you already maintain your own network.
The goal is a connection that works away from home Wi-Fi, requires your own login and can be removed again. Home Assistant must already work locally. The Cloud setup needs neither a new automation nor a public IP address.
| Your need | A suitable starting point | Your maintenance responsibility |
|---|---|---|
| Simple access for the household’s phones | Home Assistant Cloud | Subscription, user accounts and app connection |
| Private access from selected devices | VPN, such as Tailscale | VPN clients, access policies and an available host at home |
| Your own domain and existing proxy | Reverse proxy with HTTPS | Certificate, proxy, firewall and correct trust settings |
Home Assistant’s official remote access guide recommends Cloud as the easiest option for most people. Cloud provides access without opening an inbound router port. A VPN is another option, but the phone must be connected when you use the home address reachable through that VPN.
Check local access before changing remote access. Keep your working local address and a current backup. Use a strong, unique password and give household members separate accounts; grant administrator privileges only to people maintaining the installation. See Home Assistant’s security checklist.
Open your user profile’s Security tab and enable multi-factor authentication with an authenticator app. Store the setup’s secret key securely; keep both the key and QR code out of screenshots you share. Test sign-in in a separate private browser window while keeping your original session open. Home Assistant documents the setup in its MFA guide.
Have local access and your Cloud account ready. Check current pricing and terms at Nabu Casa instead of relying on a subscription price quoted in an older guide.
Sign in locally
Open Settings → Home Assistant Cloud and sign in to your Cloud account.
Enable remote access
Turn on Remote access. Wait if the connection or certificate is still being prepared.
Save the displayed address
Copy the Cloud address from that page. Use the exact HTTPS address shown.
Try the address in a browser
Open it in a new private window and sign in as your Home Assistant user.
Continue with the test below
Access over home Wi-Fi does not yet prove the phone works remotely.
The process and optional external activation setting are documented in Nabu Casa’s official instructions. Choose external activation deliberately if you want to re-enable a disabled connection from your Cloud account. Ordinary use with remote access already enabled does not require that extra setting.
Use a simple check you can repeat after changes:
Avoid door locks, garage doors and heating appliances as your first test. A page loading proves network access; a changed dashboard indicator alone does not prove the physical device responded.
Once the browser works, open Settings → Companion app and the relevant server’s connection settings. Select the Cloud connection if offered, or enter the external address you tested. Internal addresses and choosing a connection by Wi-Fi name may require additional permissions. Follow the Companion app networking guide and repeat the mobile-data test in the app. Menu names can differ between iOS and Android.
A private VPN makes sense if you already have a maintained, always-on Tailscale host. Your phone and home device must belong to your private Tailscale network, called a tailnet. Use this checklist for that route:
Home Assistant sign-in is still required. A subnet router provides a network route; it does not automatically make Home Assistant an HTTPS server. Tailscale encryption protects the VPN connection as far as the subnet router; HTTP on the remaining LAN segment is still HTTP. Use HTTPS there too if your network’s risks require it. Do not bypass browser certificate warnings.
| Symptom | First check | Next step |
|---|---|---|
| Works on Wi-Fi but fails on mobile data | Is the phone using a local address? | Test the Cloud address or VPN connection in the browser |
| Browser works but app fails | The server’s app settings | Correct the external address or Cloud selection; retest |
| Sign-in is refused | The specific Home Assistant user | Check the account, MFA and whether local-only sign-in is enabled |
| VPN connects but the page does not open | Destination, access policy and any subnet route | Check each part; avoid granting the whole LAN for troubleshooting |
| Certificate warning | Address and certificate hostname | Correct the cause instead of accepting the warning |
| Cloud is offline | Local Home Assistant and home internet | Restore local access first and inspect Cloud status |
If you previously configured trusted_networks, confirm that ordinary Home
Assistant sign-in remains available. The Cloud address cannot use that login
method; see Nabu Casa’s explanation.
Do not trust the entire VPN network simply to skip sign-in.
Record the access method, who can use it and the last successful mobile-data test. Repeat the test after replacing a phone, changing a router or updating user accounts. If a phone is lost, remove its access from both the relevant VPN service and Home Assistant sessions/tokens; a change in one place may not be sufficient. Home Assistant’s account profile shows the relevant token settings.
Keep local access as your recovery path. Disable Cloud remote access or the relevant VPN access when you stop using it. Old port forwards are a separate access route: review only rules for your own Home Assistant and remove them after testing the replacement and identifying what those rules serve.
A secure foundation
Review network security and safe updates.
Messages to your phone
Continue with mobile notifications and test delivery separately.
Sources and instructions reviewed on September 30, 2026. Test your own network and phones using the checklist above.
SmartBolig // AI Core
Get help with troubleshooting, architecture and concrete configuration. I use broad AI knowledge and find SmartBolig guides when they improve the answer.
Start with a useful question