<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.domoticz.com/index.php?action=history&amp;feed=atom&amp;title=Security</id>
	<title>Security - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.domoticz.com/index.php?action=history&amp;feed=atom&amp;title=Security"/>
	<link rel="alternate" type="text/html" href="https://wiki.domoticz.com/index.php?title=Security&amp;action=history"/>
	<updated>2026-09-18T23:34:38Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://wiki.domoticz.com/index.php?title=Security&amp;diff=19155&amp;oldid=prev</id>
		<title>Gizmocuz: /* Security Panel */</title>
		<link rel="alternate" type="text/html" href="https://wiki.domoticz.com/index.php?title=Security&amp;diff=19155&amp;oldid=prev"/>
		<updated>2026-03-28T06:47:07Z</updated>

		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Security Panel&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 06:47, 28 March 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l136&quot;&gt;Line 136:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 136:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;After this the security panel can be renamed, activated and used in scripting.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;After this the security panel can be renamed, activated and used in scripting.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Make sure accept new devices is enabled under settings and to check the devices tab for the security device.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;For information how to setup an alarm system with existing sensor see page [[Alarm Setup]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;For information how to setup an alarm system with existing sensor see page [[Alarm Setup]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Gizmocuz</name></author>
	</entry>
	<entry>
		<id>https://wiki.domoticz.com/index.php?title=Security&amp;diff=19154&amp;oldid=prev</id>
		<title>Gizmocuz at 19:54, 27 March 2026</title>
		<link rel="alternate" type="text/html" href="https://wiki.domoticz.com/index.php?title=Security&amp;diff=19154&amp;oldid=prev"/>
		<updated>2026-03-27T19:54:05Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 19:54, 27 March 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&#039;&#039;&#039;&#039;&#039;&amp;lt;big&amp;gt;This page is about Domoticz version &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;2023&lt;/del&gt;.1 (which has significant security related changes to previous versions)&amp;lt;/big&amp;gt;&#039;&#039;&#039;&#039;&#039;&amp;lt;br /&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&#039;&#039;&#039;&#039;&#039;&amp;lt;big&amp;gt;This page is about Domoticz version &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;2026&lt;/ins&gt;.1 (which has significant security related changes to previous versions)&amp;lt;/big&amp;gt;&#039;&#039;&#039;&#039;&#039;&amp;lt;br /&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===Introduction===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===Introduction===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Any Domoticz installation &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;comes with &lt;/del&gt;a &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;default User (&#039;&#039;admin&#039;&#039;) and Password (&#039;&#039;domoticz&#039;&#039;) &lt;/del&gt;so you can login as an administrator and start configuring your Domoticz setup.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Any &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;new &lt;/ins&gt;Domoticz installation &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;will ask you for &lt;/ins&gt;a &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;administrator user/password &lt;/ins&gt;so you can login as an administrator and start configuring your Domoticz setup.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;A key step in setting up Domoticz is considering how to properly secure your setup.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;A key step in setting up Domoticz is considering how to properly secure your setup.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;IMPORTANT&#039;&#039;&#039;: &#039;&#039;First thing to do is changing the default password of the &#039;admin&#039; user into something else! Otherwise everyone knows your admin password just by reading this page. Goto menu &#039;&#039;&#039;Setup - Users&#039;&#039;&#039; to change the admin password.&#039;&#039;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;There are a number of &amp;#039;components&amp;#039; involved when it comes to Domoticz security:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;There are a number of &amp;#039;components&amp;#039; involved when it comes to Domoticz security:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*Users (see page [[User Management|User management]])&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*Users (see page [[User Management|User management]])&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*Trusted networks&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*Trusted networks&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l21&quot;&gt;Line 21:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 18:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;And there are a few more security specific settings that can be configured to further fine-tune Domoticz security.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;And there are a few more security specific settings that can be configured to further fine-tune Domoticz security.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;br /&amp;gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===Basic Security setup===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===Basic Security setup===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Gizmocuz</name></author>
	</entry>
	<entry>
		<id>https://wiki.domoticz.com/index.php?title=Security&amp;diff=19134&amp;oldid=prev</id>
		<title>Walter vl: /* Applications */</title>
		<link rel="alternate" type="text/html" href="https://wiki.domoticz.com/index.php?title=Security&amp;diff=19134&amp;oldid=prev"/>
		<updated>2026-03-13T15:18:59Z</updated>

		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Applications&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 15:18, 13 March 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l164&quot;&gt;Line 164:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 164:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The actual client Applications have no need to know either the &amp;#039;application secret&amp;#039; and/or public key as they just pass on the Token received from Domoticz during the Authorization process.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The actual client Applications have no need to know either the &amp;#039;application secret&amp;#039; and/or public key as they just pass on the Token received from Domoticz during the Authorization process.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;More information can be found by reading the [https://github.com/domoticz/domoticz/blob/development/SECURITY_SETUP.md SECURITY_SETUP.md] file in the Domoticz sourcecode repository on GitHub.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;br /&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;br /&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l171&quot;&gt;Line 171:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 172:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;As Domoticz uses OAuth2 and OpenID Connect (OIDC), any Identity services that supports these protocols could be used in theory.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;As Domoticz uses OAuth2 and OpenID Connect (OIDC), any Identity services that supports these protocols could be used in theory.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;More information can be found by reading the [https://github.com/domoticz/domoticz/blob/development/SECURITY_SETUP.md SECURITY_SETUP.md] file in the Domoticz sourcecode repository on GitHub.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;br /&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;br /&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l177&quot;&gt;Line 177:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 179:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Also, each script or integration should become its own &amp;#039;&amp;#039;application&amp;#039;&amp;#039; ensuring that the credentials used, are only used by the specified application. And in case the credentials for an application have been compromised/leaked, just &amp;#039;&amp;#039;disabling&amp;#039;&amp;#039; the application is sufficient to prevent abuse.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Also, each script or integration should become its own &amp;#039;&amp;#039;application&amp;#039;&amp;#039; ensuring that the credentials used, are only used by the specified application. And in case the credentials for an application have been compromised/leaked, just &amp;#039;&amp;#039;disabling&amp;#039;&amp;#039; the application is sufficient to prevent abuse.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;br /&amp;gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===More information===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===More information===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;More information can be found by reading the [https://github.com/domoticz/domoticz/blob/development/SECURITY_SETUP.md SECURITY_SETUP.md] file in the Domoticz sourcecode repository on GitHub.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;More information can be found by reading the [https://github.com/domoticz/domoticz/blob/development/SECURITY_SETUP.md SECURITY_SETUP.md] file in the Domoticz sourcecode repository on GitHub.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;br /&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;br /&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Walter vl</name></author>
	</entry>
	<entry>
		<id>https://wiki.domoticz.com/index.php?title=Security&amp;diff=18692&amp;oldid=prev</id>
		<title>Walter vl: /* API Protection */</title>
		<link rel="alternate" type="text/html" href="https://wiki.domoticz.com/index.php?title=Security&amp;diff=18692&amp;oldid=prev"/>
		<updated>2024-07-29T12:21:27Z</updated>

		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;API Protection&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;lt;big&amp;gt;This page is about Domoticz version 2023.1 (which has significant security related changes to previous versions)&amp;lt;/big&amp;gt;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;lt;br /&amp;gt;&lt;br /&gt;
===Introduction===&lt;br /&gt;
Any Domoticz installation comes with a default User (&amp;#039;&amp;#039;admin&amp;#039;&amp;#039;) and Password (&amp;#039;&amp;#039;domoticz&amp;#039;&amp;#039;) so you can login as an administrator and start configuring your Domoticz setup.&lt;br /&gt;
&lt;br /&gt;
A key step in setting up Domoticz is considering how to properly secure your setup.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;IMPORTANT&amp;#039;&amp;#039;&amp;#039;: &amp;#039;&amp;#039;First thing to do is changing the default password of the &amp;#039;admin&amp;#039; user into something else! Otherwise everyone knows your admin password just by reading this page. Goto menu &amp;#039;&amp;#039;&amp;#039;Setup - Users&amp;#039;&amp;#039;&amp;#039; to change the admin password.&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
There are a number of &amp;#039;components&amp;#039; involved when it comes to Domoticz security:&lt;br /&gt;
&lt;br /&gt;
*Users (see page [[User Management|User management]])&lt;br /&gt;
*Trusted networks&lt;br /&gt;
*Applications (in security context often referred to as &amp;#039;&amp;#039;Clients&amp;#039;&amp;#039;)&lt;br /&gt;
*Domoticz itself, which has 3 parts&lt;br /&gt;
**The Domoticz &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;User Interface&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; (or &amp;#039;&amp;#039;website&amp;#039;&amp;#039;. This is the standard &amp;#039;&amp;#039;Application&amp;#039;&amp;#039; that comes with every installation)&lt;br /&gt;
**The Domoticz &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Resource server&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; (or core server that does all the magic)&lt;br /&gt;
**The Domoticz &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;IAM server&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; (the part responsible for Identity &amp;amp; Access Management)&lt;br /&gt;
&lt;br /&gt;
        &amp;#039;&amp;#039;(technically build-in the core server at the moment)&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
And there are a few more security specific settings that can be configured to further fine-tune Domoticz security.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Basic Security setup===&lt;br /&gt;
In a basic setup, the following steps are sufficient for a proper- and secure functioning Domoticz.&lt;br /&gt;
&lt;br /&gt;
====Users====&lt;br /&gt;
Create one or more [[User Management|Users]] to allow different people to control Domoticz. Assign the proper &amp;lt;u&amp;gt;rights&amp;lt;/u&amp;gt; to each User.&lt;br /&gt;
&lt;br /&gt;
Domoticz comes with 3 different &amp;#039;&amp;#039;rights&amp;#039;&amp;#039; (often called &amp;#039;roles&amp;#039;). These are:&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;admin&amp;#039;&amp;#039;; with admin rights you can control every aspect of Domoticz including all settings, configurations and user/rights management.&lt;br /&gt;
*&amp;#039;&amp;#039;user&amp;#039;&amp;#039;; this is the role for most Users as it gives them control to access all devices and if possible control them, like turning a light on or off.&lt;br /&gt;
*&amp;#039;&amp;#039;viewer&amp;#039;&amp;#039;; this is the most restrictive role as it only allows to &amp;#039;view&amp;#039; devices but not control them. So such a user can &amp;#039;read&amp;#039; the temperature target for a thermostat, but can not change the thermostat target temperature.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In general, you do not need multiple admins. Maybe a second User with admin privileges can be used as a backup admin User in case you forgot the credentials of the first admin. Your Users should either get &amp;#039;user&amp;#039; or &amp;#039;viewer&amp;#039; privileges.&lt;br /&gt;
&lt;br /&gt;
For more info and instructions see the [[User Management|Setup Users page]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;TIP&amp;lt;/u&amp;gt;: For the main User, create 2 accounts. One called for example &amp;#039;mike&amp;#039; (if he is called Mike) with &amp;#039;user&amp;#039; privileges. And a second one called &amp;#039;mikeadmin&amp;#039; with &amp;#039;admin&amp;#039; privileges. This way, &amp;#039;mike&amp;#039; can login to Domoticz as a normal user, and leave his phone unprotected at the table without the risk that someone else abuses his &amp;#039;admin&amp;#039; rights. When &amp;#039;mike&amp;#039; needs to perform actions that require &amp;#039;admin&amp;#039; privileges, he can login using his &amp;#039;mikeadmin&amp;#039; account. And logout once he is done and go back using his normal &amp;#039;mike&amp;#039; User account.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;TIP2&amp;lt;/u&amp;gt;: Create a new &amp;#039;&amp;#039;admin&amp;#039;&amp;#039; User (for example &amp;#039;mikeadmin&amp;#039;) and &amp;lt;u&amp;gt;disable&amp;lt;/u&amp;gt; the default User called &amp;#039;admin&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
TIP3: You cannot switch users when the client is mentioned in the Trusted Network setting. Domoticz will then automatically login with the first admin account.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;Pro-tip&amp;lt;/u&amp;gt;: You can see the &amp;#039;&amp;#039;Active User&amp;#039;&amp;#039; on the &amp;#039;About&amp;#039; screen:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
[[File:Domoticz_about.png|alt=Domoticz about screen]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Advanced Security setup===&lt;br /&gt;
Domoticz has support for multiple Identification &amp;amp; Authorization methods. These are:&lt;br /&gt;
&lt;br /&gt;
*Login via a Browser with Username/Password (and as long as the session is alive, using a cookie, Domoticz remembers who you are)&lt;br /&gt;
*Retrieve an &amp;#039;Access Token&amp;#039; (JWT Token) from the IAM server and provide this &amp;#039;&amp;#039;Bearer&amp;#039;&amp;#039; token with each request&lt;br /&gt;
*Provide valid credentials via &amp;#039;Basic-Auth&amp;#039; with each API request. &amp;#039;&amp;#039;&amp;lt;u&amp;gt;Only accepted for API calls!&amp;lt;/u&amp;gt;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;NOTE&amp;lt;/u&amp;gt;: Somewhere in the future, the first method will be phased-out and the standard Domoticz application will be using the 2nd method. &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====The Security-tab====&lt;br /&gt;
&lt;br /&gt;
An admin user can access the menu &amp;#039;Setup - Settings&amp;#039; screen and one of the Settings-tabs is the &amp;#039;Security&amp;#039;-tab. Which looks as followed:&lt;br /&gt;
&lt;br /&gt;
[[File:Domoticz security tab.png|alt=Security-tab of the Settings screen]]&lt;br /&gt;
&lt;br /&gt;
Here you can fine-tune several aspects.&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====API Protection====&lt;br /&gt;
In the API Protection block, it is possible to enable &amp;#039;&amp;#039;Allow Basic Authentication over plain HTTP&amp;#039;&amp;#039;. By default, Basic-Auth credentials are only accepted when received properly encrypted using HTTPS. But sometimes, especially in local networks, the interaction between for example scripts or devices and Domoticz (API) is not secured via HTTPS and with this setting enabled Domoticz will accept Basic-Auth credentials when received over HTTP.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;u&amp;gt;WARNING&amp;lt;/u&amp;gt;: Be careful with enabling this. Basic-Auth credentials are send in plaintext so can easily be captured and read when not encrypted via HTTPS. Especially if Domoticz is reachable from &amp;#039;&amp;#039;outside&amp;#039;&amp;#039;, for example via the Internet, it becomes easier for hackers to capture these credentials.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;u&amp;gt;NOTE&amp;lt;/u&amp;gt;: Basic-Auth is only accepted for API-calls and not any other requests to Domoticz! This means only calls to &amp;#039;&amp;lt;code&amp;gt;&amp;lt;nowiki&amp;gt;/json.htm&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;&amp;#039; (the current API entrypoint) will look for credentials provided via Basic-Auth.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;NOTE&amp;lt;/u&amp;gt;: API URLs with username and password as parameters (eg &amp;lt;code&amp;gt;&amp;lt;nowiki&amp;gt;https://IP:PORT/json.htm?username=userBASE64&amp;amp;password=PWDBASE64&amp;amp;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt; ) are &amp;#039;&amp;#039;&amp;#039;not&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;supported&amp;#039;&amp;#039;&amp;#039; anymore!&lt;br /&gt;
&lt;br /&gt;
Use &amp;lt;code&amp;gt;&amp;lt;nowiki&amp;gt;https://username:password@IP:PORT/json.htm&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt; instead. Sending the User/Pass using Basic-Auth is actually safer then using the URL parameters as the user/password is not send as is, but (base64) encoded and not as part of the URL but in a separate header. And when done over HTTPS, everything is encrypted as well.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;NOTE&amp;lt;/u&amp;gt;: API URLs with user/password normally only work with HTTPS when tested on browsers. Current browsers already remove the user/password section from the URL when used over HTTP. Use tools like &amp;#039;curl&amp;#039; or &amp;#039;postman&amp;#039; to test with HTTP. For external access it is advised to use HTTPS as it brings an extra encryption layer. See wiki [[Native HTTPS / SSL support]] and [[Native secure access with Lets Encrypt]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;NOTE&amp;lt;/u&amp;gt;: When using some method other than a browser to connect to Domoticz API it may be necessary to do user Authorization differently. User Authorization over HTTP is done by setting the &amp;quot;Authorization&amp;quot; HTTP request header when sending the request to Domoticz. The value of this header is a base64 encoded string of the username and password. See wiki page [[Domoticz API/JSON URL&amp;#039;s#Authorization|Domoticz API authorisation]] for more details&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Trusted Networks====&lt;br /&gt;
By default Domoticz can only be accessed by providing valid credentials. But in some circumstances that might not be possible, for example when a certain device can send data to Domoticz but cannot provide credentials.  &lt;br /&gt;
&lt;br /&gt;
It is possible to receive requests from certain IP addresses that should be considered as &amp;#039;&amp;#039;Trusted&amp;#039;&amp;#039;. When a request comes in &amp;#039;&amp;#039;&amp;lt;u&amp;gt;without&amp;lt;/u&amp;gt;&amp;#039;&amp;#039; any credentials, Domoticz will look at the IP-address of the request and check if it falls within the given &amp;#039;Trusted Network&amp;#039;. &lt;br /&gt;
&lt;br /&gt;
If the request comes from within a Trusted network and does not have any credentials provided, Domoticz will look for the first &amp;#039;admin&amp;#039;-user it has in its Users list, and assumes the identity of that user. Now the request is processed further as if coming from this admin user.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;u&amp;gt;NOTE&amp;lt;/u&amp;gt;: If a request comes in that provides credentials in some way, these credentials will be validated and accepted OR rejected regardless whether the IP-address comes from a Trusted network or not!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;NOTE&amp;lt;/u&amp;gt;: For setups where a (reverse) Proxy is used, the IP address of that Proxy should be in the list of &amp;#039;&amp;#039;Trusted Networks&amp;#039;&amp;#039;. If that is the case, Domoticz will trust the Proxy Header information from the Proxy to determine the &amp;#039;&amp;#039;origin IP address&amp;#039;&amp;#039; of the request. This IP address is than used as the real source of the request, meaning that Domoticz will look at that address to determine how to handle the request, for example if it originates from the Trusted network or not. More info can be found in the section about Proxies.&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;u&amp;gt;Pro-TIP&amp;lt;/u&amp;gt;: A secure Domoticz setup should have no need for any Trusted networks. Only the IP-address(es) of trusted Proxy server(s) should be in the list!&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=====Proxy servers=====&lt;br /&gt;
Special attention is required when using Domoticz behind a [[WebServer Proxy|proxy server]].&lt;br /&gt;
&lt;br /&gt;
It does make sense to run Domoticz behind a Proxy for example to perform SSL offloading and/or safely route internet traffic to Domoticz when a connecting to the Internet is wanted.&lt;br /&gt;
&lt;br /&gt;
Without any special action, Domoticz will see every request coming from the IP-address of the Proxy server and will treat that IP-address as the origin address. Although the request from the Proxy might contain information telling that a Proxy is involved, this information is not used by Domoticz as any request could be extended to contain such information that states it is coming from a Proxy.&lt;br /&gt;
&lt;br /&gt;
Before Domoticz looks at this Proxy information, the IP-address of the Proxy should be specified in the &amp;#039;&amp;#039;Trusted Network&amp;#039;&amp;#039; list. Once the IP-address is in this list, Domoticz will use Proxy information in any request coming from such a trusted IP-address.&lt;br /&gt;
&lt;br /&gt;
Domoticz honours the following Proxy-headers (in order):&lt;br /&gt;
&lt;br /&gt;
*Forwarded&lt;br /&gt;
*X-Forwarder-For&lt;br /&gt;
*X-Real-IP&lt;br /&gt;
&lt;br /&gt;
If it finds one of these headers, it will process them and use that information to further handle the request.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;NOTE&amp;lt;/u&amp;gt;: It will only process 1 header and that is the first it will find (see above order). So when 2 different headers are provided, the 2nd will be ignored. Even when the 2nd could be &amp;#039;&amp;#039;more relevant&amp;#039;&amp;#039;, but Domoticz has no way to determine if one header is more relevant or accurate than another.&lt;br /&gt;
&lt;br /&gt;
See page [[WebServer Proxy]] for example configuration on Apache, Nginx or Synology NAS.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
====Light/Switch Protection====&lt;br /&gt;
If you want that an On/Off device be &amp;quot;protected&amp;quot; (see page [[Managing Devices#Protected|Managing Devices]]), you can create a password that will be required by the system before executing commands, provided that you have ticked the &amp;quot;protected&amp;quot; box during the device editing phase.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Security Panel====&lt;br /&gt;
&lt;br /&gt;
The system has a security panel to specify if you are home/home-armed/away. You can use this as an alarm system. Here you can set the security code to change the arming state.&lt;br /&gt;
&lt;br /&gt;
When you press arm on the security panel the default delay is set on 30 seconds before the alarm system becomes active. This can be modified with the setting Delay.&lt;br /&gt;
&lt;br /&gt;
When the password has been entered in the password field and saved (apply  button) an internal Domoticz device &amp;quot;Domoticz Security Panel&amp;quot; will be created and can be added as switch. To be sure also try to Arm/Disarm the security panel (Menu &amp;#039;&amp;#039;&amp;#039;Settings - More Options - Security panel&amp;#039;&amp;#039;&amp;#039;)&lt;br /&gt;
&lt;br /&gt;
After this the security panel can be renamed, activated and used in scripting.&lt;br /&gt;
&lt;br /&gt;
For information how to setup an alarm system with existing sensor see page [[Alarm Setup]]&lt;br /&gt;
&lt;br /&gt;
====Remote Shared Port====&lt;br /&gt;
If you wish to share your sensors to other users, you can specify the remote port that Domoticz will listen on for remote connections. Consult your router for setting up a firewall/NAT rule to this port or check this [http://www.howtogeek.com/66214/how-to-forward-ports-on-your-router/ howto].&amp;lt;br /&amp;gt;&lt;br /&gt;
===More on security===&lt;br /&gt;
As Domoticz supports OAuth2 and OpenID Connect, it has become easier and more secure to provide granular access for Domoticz to other external tools like Dashboards, Mobile Apps, other home-automation systems, etc.&lt;br /&gt;
&lt;br /&gt;
To see what is supported, please query the OpenID Connect discovery endpoint at &amp;lt;code&amp;gt;https://&amp;lt;yourdomoticzip:port&amp;gt;/.well-known/openid-configuration&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Applications====&lt;br /&gt;
Each &amp;#039;&amp;#039;application&amp;#039;&amp;#039; known to a Domoticz instance needs an &amp;#039;&amp;#039;Application Name&amp;#039;&amp;#039; (ClientID in OIDC/Oauth2 terminology). The actual client application needs to transmit this &amp;#039;&amp;#039;ClientID&amp;#039;&amp;#039; when going through the identification and authorization steps.&lt;br /&gt;
&lt;br /&gt;
As Domoticz can also act as the &amp;#039;&amp;#039;IAM Service (Identity and Access Management)&amp;#039;&amp;#039;, domoticz can give out &amp;#039;&amp;#039;Tokens&amp;#039;&amp;#039; that client applications can use as proof that they are acting on behave of a specific User. For each application, it can give out these Tokens which are specifically intended for use with its corresponding application. These Tokens are cryptographically signed to prevent tampering and have a limited validity. To perform these signing and checking actions, Domoticz needs somekind of &amp;#039;&amp;#039;secret&amp;#039;&amp;#039; (ClientSecret in OAuth2/OIDC terms) for each application.&lt;br /&gt;
&lt;br /&gt;
It can either be an &amp;#039;application secret&amp;#039; (when &amp;#039;isPublic&amp;#039; is off), which is &amp;#039;just&amp;#039; a string acting as a key (or password). So please specify a strong key (use a good password generator)!&lt;br /&gt;
&lt;br /&gt;
Or generate cryptographic public/private key-pair, and store both in a PEM-file, and point Domoticz to this PEM-file by enabling the &amp;#039;IsPublic&amp;#039; setting. &amp;lt;u&amp;gt;&amp;#039;&amp;#039;&amp;lt;-- Recommended way&amp;#039;&amp;#039;&amp;lt;/u&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The actual client Applications have no need to know either the &amp;#039;application secret&amp;#039; and/or public key as they just pass on the Token received from Domoticz during the Authorization process.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====External IAM services (Single-Sign-On)====&lt;br /&gt;
It is possible to use other Identity &amp;amp; Access Management servers or services to manage identities and access to Domoticz. That way there is no need to use the internal IAM service and it becomes possible to implement Single Sign-On across multiple applications including Domoticz.&lt;br /&gt;
&lt;br /&gt;
As Domoticz uses OAuth2 and OpenID Connect (OIDC), any Identity services that supports these protocols could be used in theory.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Scripts and other integrations====&lt;br /&gt;
Instead of using &amp;#039;Basic-Auth&amp;#039; as authorization mechanism, scripts or any other integration should try to use the OAuth2 &amp;#039;&amp;#039;authorization_code&amp;#039;&amp;#039; grant-type flow (preferably with use of the PKCE extension) or fall-back on the &amp;#039;&amp;#039;password&amp;#039;&amp;#039; grant-type. These modern mechanism ensure that only a temporary valid Token has to be exchanged with each request and not the user credentials.&lt;br /&gt;
&lt;br /&gt;
Also, each script or integration should become its own &amp;#039;&amp;#039;application&amp;#039;&amp;#039; ensuring that the credentials used, are only used by the specified application. And in case the credentials for an application have been compromised/leaked, just &amp;#039;&amp;#039;disabling&amp;#039;&amp;#039; the application is sufficient to prevent abuse.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===More information===&lt;br /&gt;
More information can be found by reading the [https://github.com/domoticz/domoticz/blob/development/SECURITY_SETUP.md SECURITY_SETUP.md] file in the Domoticz sourcecode repository on GitHub.&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Walter vl</name></author>
	</entry>
</feed>