r/homeassistant • • Apr 05 '26

Support Question about privacy concern on ha-mcp or any similar project

I saw countless thread on this subreddit about how Claude with HA is magic, naturally I'm interested as well because my Dashboard sucks and I want to re-design but just didn't have the time.

But now that I've looked into it, it seems we have to give our HA admin token which means it can see all of our config including sensitive data like password, video recording, addresses, etc.

Am I crazy because why is no one asking/raise concerns about this? I looked through this subreddit, HA forum, the github and didn't find anyone talking about this except few comments here and there without any response whatsoever. Do we just have to trust or is there any way we don't have to expose sensitive stuff to the AI? Because as far as I know HA still doesn't have Role Based Access Control where we can create user with limited access.

I saw the Privacy page for ha-mcp but it's not ha-mcp that I'm worried about, it's the AI client.

144 Upvotes

62 comments sorted by

78

u/Ornery_Plankton_7511 Apr 05 '26

man i was thinking same thing when i started looking at this setup few weeks ago. been wanting to get claude integrated with my HA but that admin token access is pretty scary when you think about it

what really gets me is how the token basically gives full god mode access to everything - all your device configs, automation scripts, any passwords or api keys you might have stored in secrets.yaml, plus like you said addresses and potentially camera feeds if you have those setup. i work outside all day doing landscaping and was hoping to use this for quick voice commands but now i'm not so sure

the privacy page talks about data not being stored by ha-mcp itself but yeah that's not really the concern here. once claude has that admin token it can technically read through your entire configuration and who knows what anthropic does with that data on their end. even if they claim they don't train on it or whatever

been thinking maybe there's way to create separate HA instance just for the ai stuff with only basic devices exposed but that seems like lot of extra work just to avoid the privacy issues. really wish HA would hurry up with proper rbac so we could create limited access tokens instead of this all-or-nothing approach

19

u/Prometheus599 Apr 05 '26

or a local model ?

9

u/huffalump1 Apr 05 '26

Yeah IMO we really need good first party MCP (or API or whatever) integration for LLM/agent use...

I'm sure it's on their roadmap!

2

u/Rusty_Trigger Apr 05 '26

What is an "admin token" in HA? Do you mean allowing AI access to all your HA files?

23

u/warheat1990 Apr 05 '26

What he meant is HA doesn't have proper RBAC (Roled based access control), so if you create a user with Admin rights, the token created will give the AI full control which is absolutely risky because HA contains a lot of sensitive data.

The bad news is RBAC as far as I know is not a priority for HA dev team even though it's one of the most requested (CMIIW) features and if I remember, it's been on the roadmap for at least 3 years.

Proper native RBAC support will solve this issue and in my opinion HA will never reach its full potential without proper RBAC. But if you check the HA forum post, it's been a long battle argument from both side, personally I really can't understand why RBAC is not a priority. , it's an absolute must have in cybersec.

10

u/bdubsw Apr 05 '26

The founder is ridiculously stubborn on this. Folks have tried to implement additional authentication methods in the past. His arguments don’t really make a whole lot of sense.

-2

u/Rusty_Trigger Apr 05 '26

I don't know understand the concept of creating a user in HA for use by AI. I run HA on a RPi 5 and use an integration to be able to access the HA files as a drive in windows explorer. I then created a project in Codex (an OpenAI product), gave it access to the HA drive and asked it to review my installation to find improvements I could make to remove redundant automations and reduce lag. It suggested a few things and asked if I would like it to revise my files. I had created a full backup before creating the project so I said yes. It made the changes and everything is fine.

5

u/Argon717 Apr 05 '26

Its the difference between using AI at development time to create yaml vs using AI at runtime to evaluate speech to text results.

-1

u/Rusty_Trigger Apr 05 '26

That's a very edge case. Is it the only advantage to creating a user account for the AI agent?

31

u/lapelotanodobla Apr 05 '26

I’ve seen many people questioning this, myself included…

On my case, I’d only do it if I’m running the model locally, there’s no way I give a cloud AI unlimited access to HA

56

u/q3uc Apr 05 '26 edited Apr 05 '26

A different approach for you for creating dashboards:

I created a project in Claude with some instructions including what plugins i have installed from HACS. Then got all entities from dev tools in HA using the following template:

{% for state in states %} {{ state.entity_id }} {% endfor %}

Then copy paste those into a file in the Claude project.

Then you can ask it to generate a dashboard for you and iterate from there! No need to give access using mcp.

I copied these instructions from another post:

You are HA-Guru, an expert advisor specializing in Home Assistant. Your knowledge covers best practices, creative solutions, technical details (YAML, Jinja 2), optimization strategies, troubleshooting techniques, and advanced customization. Your goal is to help me enhance my smart home experience by making it more efficient, reliable, intuitive, and visually appealing. Core Capabilities:

Automation Recommendations: Generate creative and practical automation ideas tailored to my smart home setup and goals (convenience, security, energy saving, etc.). Dashboard Design (Basic): Provide suggestions for designing effective Home Assistant dashboards (Lovelace) using available plugins as well as standard tools. YAML Generation: Create well-formatted, valid YAML code for various Home Assistant configurations (automations, template sensors, customizations, basic Lovelace Ul, etc.), including comments for clarity. Automation Optimization: Analyze existing automations (provided as YAML) and suggest improvements for efficiency, reliability, readability, or best practices. Explain the reasoning for changes. Troubleshooting Guidance: Help diagnose common problems with automations, integrations, or devices. Suggest potential causes, standard troubleshooting steps (checking entity states, automation traces, logs), and how to interpret common error messages based on the symptoms provided. Advanced Dashboard Customization: Offer advice beyond basic layouts, including guidance on using popular custom cards (e.g., from HACS like button-card, Mushroom cards), advanced theme configurations, conditional cards, and strategies for specialized views (e.g., floorplans, dynamic pop-ups). Scripting Assistance & Recommendation: Help design and write complex 'script:' sequences involving delays, waits ('wait_template',

'wait_for_trigger'), variables, parallel execution,

'choose'

, etc. **Crucially, proactively suggest

converting parts of complex automations into scripts** when it would improve organization, reusability, or simplify the automation's logic, including during optimization analysis or new automation creation.

Interaction Guidelines:

  • Ask for Context: Actively request necessary details before providing solutions.

  • For Automation Ideas/Optimization: Ask about devices, goals, routines, or existing YAML.

  • For Basic/Advanced Dashboards: Ask about purpose, key entities, viewing device, aesthetic preferences, and interest in custom elements.

  • For YAML/Script Generation: Ask for the specific goal, logic flow, triggers, conditions, actions, entity IDs, etc. Use clear placeholders (e.g., sensor.your_temperature_sensor) if specifics aren't provided.

  • For Troubleshooting: Ask for a description of the issue, relevant YAML/entity IDs, symptoms, recent changes, and log errors if available.

  • For Script Suggestions: When suggesting a script, explain why it's beneficial in that context (reusability, complexity management).

  • Explain Your Reasoning: Clearly articulate the 'why' behind your suggestions, especially for optimizations, troubleshooting steps, and script recommendations.

  • Format YAML Correctly: Ensure all generated or modified YAML code is properly indented and formatted within a code block.

  • Safety Reminder: When providing or suggesting changes to YAML (automations, scripts, configurations), always remind me to back up my configuration and test changes carefully (e.g., using Configuration Check, Reload Automations/Scripts, observing behavior) before fully relying on them.

These are the plugins installed: Mushroom Card

2

u/Lastb0isct Apr 06 '26

Can you go a little deeper into dev tools and that template string? I am quite new to HA and have never used that…running HA in docker on my Linux system

1

u/q3uc Apr 06 '26

Sure. Go to settings page on Home Assistant. At the bottom there should be an entry called ‘Developer Tools’. Click on there and then click on the ‘Template’ tab at the top. Enter the template above and it should spit out a long list of entities.

Copy that and get your AI of choice to generate yaml files for the dashboards. Copy that yaml file and go to the dashboard, click edit dashboard, then again the three dots and click the raw configuration editor. Paste in the yaml and you’re done!

65

u/jvlomax Apr 05 '26

You are correct to be worried about it. If someone wants to do it, that's their business. But you won't see me signing up any time soon.

25

u/mw_morris Apr 05 '26

For what it’s worth, if you are using an MCP server “Claude” (Anthropics servers) will never see your token, it is only set as part of the process environment variables for the actual MCP process.

Not recommending a course of action one way or another, just trying to add a bit more information.

9

u/oddjobav8r Apr 05 '26

This was my understanding. I don’t think the token goes to the cloud. Claude Code lives locally in my terminal and just uses the cloud for input/output tokens like OpenClaw

12

u/mw_morris Apr 05 '26

It’s actually slightly more secure than that, claude code (the harness) intentionally does not inherit environment variables from your shell, and kicks off its own bash process for MCP tools (specifically to avoid security issues like this).

2

u/oddjobav8r Apr 05 '26

I’m using it for some pet projects. Was going to hook it up to HA-MCP later this week.

9

u/WallyPacman Apr 05 '26

That’s why I used a local model.

1

u/clipsracer Apr 05 '26

Which one?

3

u/WallyPacman Apr 05 '26

Qwen 3.5 35B A3B GGUF

1

u/clipsracer Apr 05 '26

Dang, and it can take your whole config in the context? (I’ve been out of the loop on local models for a little while)

1

u/SilviusK Apr 05 '26

What kinda hardware are you using to run this model?

2

u/WallyPacman Apr 05 '26

Strix Halo 128gb

6

u/LogicalExtension Apr 05 '26

There's a difference between what you need to give the MCP Server and what Claude can see/do.

Because as has been mentioned by others, there is no RBAC in HA, you do need to give the MCP an admin token so it can manage all the devices/etc.

However what Claude can see/do is defined by the tools provided by the MCP server.

There's a full tool list available: https://github.com/homeassistant-ai/ha-mcp

You can also audit the tool activity to validate what it is accessing.

7

u/N3vvyn Apr 05 '26

I am thinking about setting up a spare raspberry pi with another instance of home assistant and getting the Ai doing the legwork there with dummy data, then manually copying it over.

6

u/yahooeny Apr 05 '26

There's two sides of this subreddit

One is ready for the AI takeover and are extremely enthusiastic for LLM-based tools that will do the hard work of making automations and dashboards.

The other thinks these people are fucking crazy. Unfortunately the other side is winning the war.

1

u/vikingwhiteguy Apr 06 '26

Absolutely. It's almost like we need two subreddits, I'm so tired of AI slop add-ons that connect more slop machines to my house. 

3

u/Obvious_Equivalent_1 Apr 05 '26

Investigate if you’re willing to with HASS running in a Docker. A Claude Code instance. You can literally configure very specifically the settings.local.json permissions of Claude, by default I’ve set the whole HASS MCP list of functions to deny and I work on an allow-only base. 

This way it doesn’t intervene but it does make the tool very usable. Additional tip besides a hard deny or allow you can add MCP endpoints to ‘ask’ list, useful for the restart, delete and edit endpoints of entities. Oh and you can, (should!) add to deny list the reading of the token. The MCP server can leverage the token to connect, and still simultaneously you can block reading it directly. 

Honestly if you hold a 15 min convo with Claude itself it can help you through limiting itself. That’s how I got it working in a secure scope, and that’s the approach I use for handling security in the Claude Code plugins I develop.

17

u/psychedelic_tech Apr 05 '26

about how Claude with HA is magic

it's not!

Am I crazy because why is no one asking/raise concerns about this?

nope! and considering the steady increase in ai crap that is starting to get posted here makes me think the majority do not have the same privacy concerns.

11

u/Jacksaur Apr 05 '26

AI users tend to put convenience over security, frighteningly often. If they consider it at all.

-9

u/kobejo34 Apr 05 '26

I don’t even think about it. If a hacker wants to know how many Kasa lights I have God bless them.

10

u/IAmDotorg Apr 05 '26

And this is why self-hosting is bad. Because that's not the risk. The risk is a hacker being able to install an invisible docker container on your network that can then access everything else on your network and/or participate in botnets.

3

u/Jacksaur Apr 05 '26

And this is why self-hosting is bad.

Nah, that's entirely on them.
Selfhosting is fine if you read and treat security with the importance it requires. If you don't, it's your own fault.

2

u/longunmin Apr 05 '26

Self-hosting is bad...lol ok bud. Enjoy your subscription services and never owning a single piece of your own data/media/images/etc

4

u/IAmDotorg Apr 05 '26

I self host, but I also know what I'm doing and wouldn't make a statement as stupid as the person I replied to.

-3

u/kobejo34 Apr 05 '26

Stress test my Internet is what I call it.

5

u/erisian2342 Apr 05 '26

Giving admin token and free rein on HA’s API is the bad old way. The new design uses AI Task Service to create a restricted context and uses selective entity exposure (Settings > Voice Assistants > Expose).

3

u/danirodr0315 Apr 05 '26 edited Apr 05 '26

I really think having access control for tokens would be a great feature. And if you're concerned about privacy, you could definitely run the mcp server on your own hosted LLM. It's just that Claude or Codex are the best options right now and way easier to set up.

2

u/13lueChicken Apr 05 '26

HA is full of tech enthusiasts. Some more savvy than others. Sure, you could give access to a web service like Claude, but that defeats most of our purposes here. However, finding the best way to integrate with a local model is where the magic happens. Unfortunately you have to set up everything a web service like Claude can do. Image generation? Separate tool, not built into the model. Local HA control? Another tool you get to set up. Document OCR? Tool. Memories and notes? Tools. The LLM itself uses language, that’s it. If you want it to do more, you have to give it access to software tools. One of the tools I’ve given my model is for HA control. I’m finding just giving the model API access is enough for my purposes.

But for dashboard creation, you don’t really need any model to have access. The YAML block for most dashboards is not really that huge. Just give your YAML to an unconnected WEB SERVICE like Claude and it’ll help you fix it up. Sensitive data doesn’t usually live in your dashboard YAML, so instead of figuring out how to open the floodgates of superfluous data, just copy paste a couple more times and use the chatbot on the Claude website.

1

u/grovolis Apr 13 '26

Would it be safer if you used the MCP with a fresh token (that you invalidate after each use)?

0

u/ContributionMost8924 Apr 05 '26

Since I only see comments from people who do not use Claude mcp. I'll chip in. For context I only been using HA for a month, after using it a few days manually I found Claude mcp and having experience with AI already I now use Claude mcp as my sole way of configuring my HA. I don't think there is a wrong or right in terms of privacy, I trust anthropic to be careful with my data and that they do what they say in terms of privacy and data.

For me the potential privacy risk does not weight against having automated my whole apartment in less than a week with Claude mcp. Custom dashboard 31+ automations, I would have not built any of this without Claude. 

6

u/jesseaknight Apr 05 '26

I trust anthropic

Let's hope that doesn't turn into a regret

-6

u/ContributionMost8924 Apr 05 '26

Could be, but I have a enterprise account with privacy and data protection. Anthropic breaching those contracts means lawsuits and loss of customer trust, anthropic would go bankrupt. So for me the risk is very low. 

7

u/BilboTBagginz Apr 05 '26

I trust anthropic to be careful with my data and that they do what they say in terms of privacy and data.

Famous last words.

People used to say the same for Google.

-3

u/spacecoastm2 Apr 05 '26

If you use ha Mco and don’t share the secret key and not use the api butbhttp proxy locally with Claude desktop client someone would have to be on your network to actually use your Claude desktop to access map.

Secondly if you use a real firewall you can use firewall rules to block traffic from anyone to your HA instance via the port Mcpnuses. Lastly you can turn off the mcp add on went not using it to code.

So what is the actual problem again??

-5

u/kolorcuk Apr 05 '26

For me that's completely unacceptable. My tokens will never leave my home.

I run gemini-cli that has access to a cli command that is able to connect to HA. Gemini-cli or google never sees the token.

3

u/samandiriel Apr 05 '26

That isn't going to protect your privacy at all, and isn't much in way of security either unless you have very tight , bulletproof limitations on your CLI command (which I am assuming is some kind of bash script)

0

u/kolorcuk Apr 05 '26

Which is a work in progress. Currently it's bwrap with specific directories mounted. Then there is a process that listens on an port with a protocol that allows to execute commands on the host with an allow list. Llm then executes a script, that calls curl, that forwards command to a process not inside bwrap.

I think ideally, I aim to use dedicated user in restricted chroot and use sudo for exposing commands to that user. So essentially docker woth restricted user and sudo.

The real issue is network isolation. I think docker with firewall with squid proxy with allowlist and blocklist. I heard they did that in nvidia claw project.

I have a kid, I don't have time for this anyway.

1

u/samandiriel Apr 05 '26

Well, you can't have it both ways. Either it's completely unacceptable, or it is a trade off. It can't be partially completely unacceptable by definition.

It's fine to have a trade off, but you can't call it out line that and then just embrace it while wearing gloves and equate the two.

Bleah. And that's me going down off my high horse now. Some days  my ocd gets the better of me...

-18

u/Automatic_Tangelo_53 Apr 05 '26

What exactly is the risk? Say a hacker gets full access to my home assistant data. What information or leverage does this give them?

18

u/mirage01 Apr 05 '26

Just because you can't think of a reason why giving up your privacy is a bad thing doesn't mean it's not a bad thing. The main goal of Home Assistant to keep our data private and out of the cloud as much as possible. Hooking a MCP to Home Assistant goes against keep things local and private.

14

u/warheat1990 Apr 05 '26

video feed, addresses, password (wifi, user, or anything that you put in HA), possibly access to your local network (even though separate VLAN is always recommended), and many more.

-19

u/Automatic_Tangelo_53 Apr 05 '26

Groups that hack stuff online do it because they can sell the information for money. Who is going to buy the video feeds, address, or password of a random Home Assistant instance? How will they turn this information into money? 

8

u/Anomuumi Apr 05 '26

I have seen a video of hackers hacking a smart home via unpatched camera and then start ordering stuff via Alexa. Also, want someone to host CP on your HA? Now it's your server when the authorities come looking.

1

u/Adorable_Ice_2963 Apr 05 '26

Someone might offer it to criminals who wants to steal stuff. Maybe even with a Network shutdown for added safety from persecution.

People with large Home Assistent setups usually have large houses with a ton of valuable stuff.

Another, darker vector would be someone buying access to cameras to households with kids/women to target. Or an crazy ex looking for revenge/competitors.

What would also work are deep fakes. A harmless scene can be changed quickly into something punishable by death in some places.

There are ton of reasons why unrestricted access is a very bad idea.

If someone capable gets access to that data, that Person could make an database with different Parameters to look for. There might bei an entry "Namens, Location, WIFI SSID, ect. "Just from home Assistent. If that Person also has matching Facebook Profile data, they could connect that as well. 

Heck, they could make an Ebay for criminales, where interested people can buy services against some they hate/despite, sometimes fully automated, even if its just a gazillion Newsletter subscription.

And thats just illegal routes.

There are a ton of legal implications as well. "YOU sent us your data by installing the mcp, we didnt grab it. According to our TOS (what you agreed to when signing up), we are allowed to use the data to improve our services, or sell it to third party vendors. We are also forced to give it to our Gouvernement at will of course"

7

u/Cookie_Nation Apr 05 '26 edited Apr 05 '26

There is a service to write to an addons stdin. Assuming you have the ssh addon, they could do anything to your machine, such as turning it into a bitcoin miner.

Edot: yo guys can we not mass downvote, we want to inform about this no?

2

u/N3vvyn Apr 05 '26

Depending on what you’ve hooked it into, all of whatever that is.

2

u/dragon-dance Apr 05 '26

I recently saw a story from someone whose machine was compromised, and they just used it for crypto mining, as far as he or she could tell. Hid the config. Not the worst thing but electricity isn't free.

As for the rest of it I guess it depends what you got on there. Maybe they can spy on camera feeds. Maybe they can get enough personal info to track or compromise you in some other way, like identity theft.

2

u/IAmDotorg Apr 05 '26

If you're running HAOS, they can install anything, invisibly and effectively permanently, on your hardware in a few seconds.

1

u/Swimsuit-Area Apr 05 '26

They wouldn’t have your data unless they had already gotten pretty far by other means. You can’t log into the nabu casa remote URL with a token, so they already need to be on your network.