Vome · Remote access
Docs Remote access Guide

End-to-end encrypted remote access

Reach your Home Assistant from anywhere at an address only your Home Assistant can read. The connection stays encrypted from your phone all the way into your home; Vome passes it on without holding a key to it. No open ports, no certificates to manage, nothing to install beyond the Vome integration.

Rolling out now. It is switched on for homes one at a time while we watch it. Ask support if you would like yours early.

1 Your usual address

On yourname.home.vome.io, Vome's edge holds the certificate. Your browser's connection is encrypted to us; we open it, check the door (your Vome sign-in or door password), and send the request down your home's own encrypted link. Both legs are encrypted, but on our server, between them, your traffic is readable. We do not look, and we keep no copy of what passes, only who reached your home and when, for your access log. But "we do not look" is a promise, not something you can check.

Your usual address: Vome opens the traffic in the middle

Away from home Vome, in Finland Your house TLS to Vome Your home's link Your phone. Your phone or laptop, on mobile data or someone else's Wi-Fi. Your phone myhome.home.vome.io Encrypted to Vome Vome's edge. On your usual address Vome's edge holds the certificate: it decrypts each request, checks the door, and sends it on to your home. Vome's edge Holds the certificate Opens it: could read it Home Assistant. Your Home Assistant, with the Vome integration. On the end-to-end address it holds the certificate and the only key, and checks the door itself. Home Assistant With the Vome integration Vome checked the door
Sealed, or in your hands Readable here Encrypted on both legs, but readable on our server between them.

2 The end-to-end address

Switch it on and your home also answers at yourname.e2e.vome.io. There, Vome's router holds no key. It reads one thing, the name your browser asked for, which every encrypted connection announces in the clear so it can be routed, and passes the still-encrypted connection down your home's link. Your Home Assistant, through the Vome integration, holds the certificate and the only key, and is the first and only place the connection is opened.

End-to-end: only your Home Assistant can read it

Away from home Vome, in Finland Your house Sealed Still sealed Your phone. Your phone or laptop, on mobile data or someone else's Wi-Fi. Your phone myhome.e2e.vome.io Encrypted to your home Vome's router. On your end-to-end address Vome's router holds no key. It reads only the name the browser asked for, then passes the still-encrypted bytes down your home's own link. Vome's router Holds no key Reads the name only Home Assistant. Your Home Assistant, with the Vome integration. On the end-to-end address it holds the certificate and the only key, and checks the door itself. Home Assistant With the Vome integration Opens it, checks the door
Sealed, or in your hands Readable here One encrypted connection from your phone to your home. Vome passes it on.

3 What Vome sees, and what it cannot

On the end-to-end addressVome sees it?
The name asked for (yourname.e2e.vome.io)Yes, to route it
The address of whoever connects, when, and how much was sentYes: your access log is made of it
The pages, dashboards and camera pictures you openNo
Your Home Assistant username and passwordNo
What you switch on or off, and your automations' trafficNo
The key that could open any of itNo: it is made in your home and never leaves

4 Who checks the door

5 The certificate

Your Home Assistant gets its own certificate from Let's Encrypt, the free certificate authority most of the web uses. Let's Encrypt checks that your home really answers at its name by connecting to it through Vome's router, which passes that check through unopened as well. Your Home Assistant makes the key, keeps it, and renews the certificate a month before it expires.

The certificate: made in your house, renewed there too

Let's Encrypt Vome, in Finland Your house Are you myhome? Answered by home Let's Encrypt. Let's Encrypt, the free certificate authority most of the web uses. It checks that your Home Assistant really answers at its name before issuing it a certificate. Let's Encrypt Issues the certificate Checks it is really you Vome's router. On your end-to-end address Vome's router holds no key. It reads only the name the browser asked for, then passes the still-encrypted bytes down your home's own link. Vome's router Holds no key Passes the check on Home Assistant. Your Home Assistant, with the Vome integration. On the end-to-end address it holds the certificate and the only key, and checks the door itself. Home Assistant With the Vome integration Makes and keeps the key
Sealed, or in your hands Readable here Let's Encrypt checks the name through Vome's router; the key never leaves home.

6 Switching it on

  1. Make sure your Home Assistant has the Vome integration 0.9.47 or newer and a Vome address (the free one is enough).
  2. On your server page on vome.io, switch on End-to-end encrypted address. Your Home Assistant agrees to Let's Encrypt's Subscriber Agreement on your behalf when it asks for the certificate.
  3. Within a few minutes your home answers at yourname.e2e.vome.io. Your usual address keeps working alongside it.
  4. Switch it off on the same page and the address stops within a minute.

What it does not change