Give a program its own Home Assistant login, without anyone seeing the password
ha_provision_service_loginCreate a non-admin Home Assistant login for an MQTT client or program, store its generated password in add-on options or secrets files, and rotate it without exposing it.
Instructions
Create a non-admin Home Assistant login for a program (an MQTT client such as Zigbee2MQTT or an energy manager, an ESPHome device, a bridge), generate its password here, and write it straight into where that program reads it: an add-on's options and/or a secrets file. The password is never returned — not to you and not to the owner — so you never have to choose, see or type one. The Mosquitto add-on accepts Home Assistant logins, so this is all an MQTT client on this home needs.
Ask the owner before calling it: it creates a standing account on their home that outlives the API key that made it. Every delivery target is checked before anything is created; a new login that could be delivered nowhere is deleted again. Use rotate=true to issue a new password to a login this tool created earlier (the old one stops working); it refuses any other account. A program outside Home Assistant with neither add-on options nor a secrets file cannot be reached from here — ask the owner to set its login. Revoke with ha_delete_user. Requires ha:config, plus ha:files for secrets_file targets.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | What the login is for, e.g. 'Zigbee2MQTT'. | |
| role | No | 'read_only' (default) is enough for MQTT; 'user' if the program drives HA itself. | |
| rotate | No | Re-issue the password of an existing login this tool created, and redeliver it. | |
| username | Yes | Login name: lowercase, e.g. 'zigbee2mqtt'. | |
| deliver_to | Yes | Where the program reads its login. At least one. | |
| local_only | No | Accept sign-in from the local network only (default true). | |
| instance_id | Yes | The instance this login is for (as listed by vomehome_list_instances). Checked against the one this session is targeting; refused if they differ. |