---
service: "Publicasta"
schema_version: "1.0"
article_id: 845
title: "Home Assistant 2026.10 Adds Easier AI Connections: The Security Checks to Make First"
language: "en"
default_language: "en"
canonical_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist?lang=en"
json_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.json?lang=en"
api_url: "https://publicasta.com/api/public/v1/channels/smart_home/articles/home_assistant_2026_10_mcp_security_checklist?lang=en"
channel_url: "https://publicasta.com/api/public/v1/channels/smart_home"
channel_articles: "https://publicasta.com/api/public/v1/channels/smart_home/articles"
search_url: "https://publicasta.com/api/public/v1/search"
documentation_url: "https://publicasta.com/api-docs#reading-publicasta"
openapi_url: "https://publicasta.com/api-docs/openapi.json"
published_at: "2026-10-09T17:07:05+00:00"
updated_at: "2026-10-09T17:07:05+00:00"
translations:
  - language: "ar"
    html_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist?lang=ar"
    markdown_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.md?lang=ar"
    json_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.json?lang=ar"
  - language: "de"
    html_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist?lang=de"
    markdown_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.md?lang=de"
    json_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.json?lang=de"
  - language: "en"
    html_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist?lang=en"
    markdown_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.md?lang=en"
    json_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.json?lang=en"
  - language: "es"
    html_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist?lang=es"
    markdown_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.md?lang=es"
    json_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.json?lang=es"
  - language: "fr"
    html_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist?lang=fr"
    markdown_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.md?lang=fr"
    json_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.json?lang=fr"
  - language: "pl"
    html_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist?lang=pl"
    markdown_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.md?lang=pl"
    json_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.json?lang=pl"
  - language: "ru"
    html_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist?lang=ru"
    markdown_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.md?lang=ru"
    json_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.json?lang=ru"
  - language: "zh"
    html_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist?lang=zh"
    markdown_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.md?lang=zh"
    json_url: "https://publicasta.com/smart_home/home_assistant_2026_10_mcp_security_checklist.json?lang=zh"
---

# Home Assistant 2026.10 Adds Easier AI Connections: The Security Checks to Make First

> Home Assistant 2026.10 makes its MCP connection easier to discover and configure. That convenience also raises a practical question: which parts of your home should an AI client be allowed to see or control?

Home Assistant 2026.10 is a small but meaningful change in how a smart home can connect to outside software. The release adds a clearer AI settings area, makes its Model Context Protocol server easier to turn on, and automatically discovers some applications that run their own MCP server. It also adds useful ordinary maintenance features, including a Modbus connections panel and more informative dashboard cards.

 ![A hand pauses over a smart-home tablet showing generic security and permission controls in a bright living room.](https://publicasta.com/storage/projects/14/pages/845/2026/10/d64d43af-1691-4730-9fb6-2d39989c1129.webp)

 The headline feature is not a new sensor or a new radio standard. It is a shorter path between Home Assistant and an AI application such as Claude, ChatGPT, or Cursor. In the right setup, that can make it easier to ask about devices, read current states, or control a limited set of entities. In the wrong setup, it can turn a broad administrator permission into a remote control for locks, garage doors, alarms, heating and other consequential equipment.

 The sensible response is not to avoid the update. It is to treat the new setup screen as a permission review. If you already use Home Assistant’s MCP integration, 2026.10 is a good reason to inspect what is exposed. If you do not use it, you can install the release without enabling the feature at all.

 ## What changed in Home Assistant 2026.10

 The October release, published on October 7, adds a Model Context Protocol card to the AI page under Settings > System. Home Assistant describes MCP as a way for an external AI application to connect to Home Assistant’s Assist API. The new card can enable the server in one step and shows the connection URLs that need to be copied into a compatible client.

 That is mostly a usability improvement. The MCP server itself was not invented in this release; Home Assistant’s documentation says the integration was introduced earlier. The important change is that users no longer need to hunt through the integrations list, work out which endpoint applies, and manually assemble the connection details before they can begin.

 New setups expose all available LLM APIs by default, including APIs added later, and restrict the connection to administrator accounts by default. Both settings can be changed in the integration configuration. Those defaults are helpful as a starting point, but they are not a substitute for deciding what the connected application should actually be able to do.

 The release also makes the reverse connection easier. Applications that provide their own MCP server can now be discovered automatically by the Home Assistant MCP integration. Connecting one of those applications requires confirmation rather than a longer manual discovery process. That is convenient, but it increases the importance of reading the confirmation screen instead of accepting every discovered service on sight.

 Home Assistant 2026.10 also improves the way some AI tools describe themselves to clients. The developer documentation says LLM tools now return a structured ToolResult and can declare metadata such as whether a tool is read-only, destructive, idempotent, or able to reach outside Home Assistant. These labels give an AI client more information about a tool’s behavior, but they do not make an unsafe permission boundary safe by themselves.

 ## MCP is not the same as giving an AI access to your whole installation

 The word “AI” can make this feature sound broader than it is. The built-in Assist API is designed around the entities and capabilities that Home Assistant exposes. It does not provide general administrative access to the Home Assistant installation. The official developer documentation says that the built-in Assist API cannot perform administrative tasks.

 That is a useful boundary. An AI client connected to Assist may be able to read the temperature, switch a lamp, or activate an exposed script, but that does not mean it can edit automations, rewrite the dashboard, inspect every log, or change the operating system. Those are different capabilities and should not be assumed merely because the client can control a device.

 The boundary can still be wider than many households expect. A connected client can receive a current snapshot of the exposed context, and an exposed entity may contain information about occupancy, security state, energy use or personal routines. A light is usually low consequence. A door lock, garage door, camera, alarm, water shutoff or heater is not.

 The MCP integration documentation says clients can control only the entities available through the selected LLM API and the exposed-entities configuration. This is the practical control to use. The question is not whether an AI client is trustworthy in the abstract. The question is whether the particular set of exposed entities is limited enough that a mistake would be recoverable.

 ## The first check: review the exposed entities

 Before connecting an AI application, open Home Assistant’s voice-assistant or Assist exposure settings and look through the list one device at a time. Remove anything that does not need voice or AI control. Home Assistant’s own best-practices documentation recommends exposing the minimum number of entities because a smaller set improves matching, reduces context, and lowers the chance of an assistant selecting the wrong device.

 Start with low-consequence devices. A desk lamp, a media player, a fan, or a temperature sensor is easier to use as a test than a lock or an alarm. The goal is to prove that the connection works without making the first experiment a safety or security event.

 Then check names and areas. An AI system has to distinguish “bedroom light,” “bedroom fan,” and “bedroom heater.” Clear names and correct room assignments reduce ambiguity. Avoid giving several devices nearly identical names, particularly if they have different consequences. “Front door lock” and “front porch light” are easier to separate than two entities both called “front.”

 Home Assistant’s exposure documentation specifically warns that sensitive devices such as locks and garage doors should not be inadvertently controlled by voice. The same caution applies to an AI client connected through MCP. If an entity does not need to be controlled conversationally, leave it unexposed. A dashboard can remain available for manual control without becoming an AI tool.

 Be careful with scripts. Home Assistant’s Assist guidance notes that scripts exposed to an LLM can become tools rather than ordinary entities. That can be powerful because a well-designed script can represent a complete routine. It also means the script’s description and behavior matter. A script named “night mode” should not silently unlock doors, disable security devices, or switch off safety equipment as a side effect.

 For routines that affect several devices, create a narrow script with a clear purpose and predictable limits. A good example is “turn off downstairs lights.” A much riskier example is “leave home,” if that routine also opens a garage door, changes alarm modes, adjusts heat and sends a notification to other people. Keep consequential actions separate so the assistant has fewer opportunities to combine them accidentally.

 ## The second check: decide whether an administrator is necessary

 Home Assistant 2026.10 keeps administrator-only access enabled by default for new MCP setups. That is safer than treating a general household account as sufficient for every API. It is also a signal that the connection deserves the same care as any other privileged integration.

 The official user documentation distinguishes administrator accounts from ordinary users. Administrators can configure integrations, devices and system settings, while non-administrator accounts have restricted access to configuration and system areas. The MCP documentation says the base endpoint can be configured to require an administrator, and that APIs other than the built-in Assist API require an authenticated administrator account.

 Do not make a household member’s everyday account an administrator just because an AI client asks for one. If the client genuinely needs a privileged API, create a separate account for that purpose, use a strong unique password, and keep the account’s role and exposure list under review. A service account without a person attached can be useful for integrations, but it should not become an untracked permanent superuser.

 Home Assistant’s security guidance recommends strong unique passwords, multi-factor authentication and limiting administrator access to accounts that need it. Those recommendations become more important when a client can use a token or an authenticated remote connection. Treat access tokens as credentials. Do not paste them into public issue trackers, screenshots, chat rooms or shared notes.

 If your household does not need external AI control, there is no reason to enable MCP. Installing Home Assistant 2026.10 and using its ordinary dashboards, automations, Assist features or device integrations does not require connecting an external MCP client. The safest permission is the one you do not need to grant.

 ## The third check: confirm how the connection reaches your home

 The MCP server is exposed at an endpoint such as `/api/mcp`, and the client must authenticate. A local client on the same network has a different risk profile from a hosted service that connects to your Home Assistant over the internet. Understand which one you are setting up before you approve it.

 Home Assistant’s security documentation advises using a secure method for remote access rather than exposing the installation directly to the internet. It lists Home Assistant Cloud, TLS with a certificate, a VPN and an SSH tunnel as possible approaches, with different levels of setup and maintenance. Port-forwarding a Home Assistant instance directly to the public internet is not a sensible shortcut for an AI experiment.

 If you use a reverse proxy, tunnel or hosted MCP client, check the hostname and authentication flow carefully. The MCP documentation notes that remote clients may need the hostname to match the internal or external URL configured in Home Assistant. A connection that fails because of a URL mismatch is inconvenient. A connection that works through an unintended public route is a security problem.

 OAuth support does not remove the need to understand the permission being granted. It can make authentication easier, but the client still receives whatever the selected API and exposed entities permit. When an application offers several connection methods, choose the one that gives you the clearest account, token and revocation controls.

 After setup, test from the client’s tool list or connection screen. Confirm that it can see only the entities you intended to expose. Then revoke or remove the connection and verify that access stops. A permission system is easier to trust when you have tested both the allow path and the removal path.

 ## A safer rollout for a real household

 A practical rollout can be completed in stages. First, update Home Assistant and let it restart normally. Check that important automations, dashboards and device integrations still work. The release notes include backward-incompatible changes, including normalized usernames: usernames are now handled in lowercase, with leading and trailing spaces removed. If Home Assistant shows a repair or account warning, resolve that before adding a new AI connection.

 Next, make a short list of tasks you actually want an AI client to perform. “Tell me whether the garage door is open” is more specific than “manage my house.” “Turn on the kitchen lights” is a better first control test than “run the away routine.” If you cannot describe the desired action in one sentence, it is probably too broad for the first setup.

 Expose only the sensors and devices required for those tasks. Use read-only checks first. Ask for the current state of a temperature sensor, a light or a door contact. Watch whether the answer identifies the correct area and device. If it does not, fix names and exposure before allowing control.

 Add one low-risk control next. Turn on a lamp or start a fan, then verify that the action reached the intended entity. Do not test with a lock, garage door, heater, oven, water valve or alarm. The first successful command proves only that the connection works; it does not prove that the client will always interpret a natural-language request correctly.

 If you later expose a consequential device, require an explicit confirmation in the surrounding process. For example, use a script that asks for a clear confirmation before changing an alarm state, or keep the final action manual. Do not rely on a vague instruction such as “make the house secure” when the result depends on the AI deciding which doors, windows, cameras and alarms count as secure.

 Document the connection in a household note: which client is connected, which account it uses, which entities are exposed, and how to revoke access. This is particularly useful when a family member sets up the connection and someone else is responsible for maintaining the smart home. An undocumented integration tends to survive long after everyone has forgotten why it exists.

 ## What is worth testing after the update

 The new AI page is the obvious place to look, but the release has several non-AI changes worth checking. The new Modbus panel under Settings > Connectivity lists serial and network connections, the devices on them and the integrations using them. That is useful for homes with inverters, energy meters, heating equipment or other Modbus hardware, especially when several integrations share one connection.

 Home Assistant also improves dashboard visibility conditions. The Visibility tab now shows whether a card is currently visible and whether each condition passes. This can help diagnose a dashboard that appears to be missing a control, without immediately rewriting the card or automation.

 The release improves media search behavior as well. Home Assistant says that an AI asking to play music can receive a list of results and select a better match, while search inside artists, albums and playlists has been improved for supported media systems. That is convenient, but it remains a low-risk place to evaluate the AI connection. Playing the wrong song is an annoyance; changing a lock state is a security incident.

 Some homes will also encounter integration-specific changes. The release notes mention changed behavior for Teslemetry vehicles, a UniFi Network reconfiguration path that was removed, and username normalization. Custom integrations can have their own compatibility requirements. If the installation depends on HACS components or unusual vendor integrations, review the release notes and repairs before assuming that every device is unaffected.

 ## Backups matter more when permissions change

 Make a fresh backup before changing authentication, adding a new integration or exposing a large set of devices. A backup will not prevent an AI from making a wrong decision, but it gives you a recovery point if a configuration change breaks the installation. Keep at least one copy somewhere other than the Home Assistant host; a backup stored only on a failed device is not a complete recovery plan.

 Be precise about what a backup can and cannot do. Home Assistant’s restore documentation warns that restoring a full backup replaces the current Home Assistant setup, applications and their data with the contents of the backup. Changes made after that backup are lost. Restoration is therefore a recovery operation, not an undo button for one mistaken voice command.

 For an AI permission change, record the original exposure list or take screenshots of the relevant settings. If the new setup becomes confusing, you may need to restore the permission configuration manually rather than restore the entire home. A simple written inventory is often more useful than a large backup when the problem is “which entity did I expose?”

 ## Should you enable MCP now?

 Enable it now if you have a specific local or remote AI workflow, understand the account and network path, and are willing to maintain a small exposure list. The 2026.10 interface should make that setup easier, and the Assist API provides a narrower boundary than general administrator access. Start with read-only sensors and low-consequence devices.

 Wait if the appeal is only that the feature is new, if you cannot identify which client will connect, or if you do not yet have a reliable way to revoke access. You lose little by postponing the connection. Home Assistant will still control the home through its ordinary app, dashboards, automations and compatible voice paths.

 Do not enable it as a replacement for a backup, a security system or a carefully designed automation. An AI can interpret a request, but it does not know your household’s safety rules unless you define them and keep the tool boundary narrow. It can also misunderstand an ambiguous request while sounding confident.

 The useful lesson from Home Assistant 2026.10 is therefore less about AI enthusiasm than about permission design. A shorter setup flow is good product work. It should reduce friction around a decision you have already made, not make the decision for you. Let the client see only what it needs, give it the least powerful account that works, keep remote access deliberate, test revocation, and leave consequential actions behind a manual confirmation when the cost of a mistake is high.

 That approach makes the new feature practical without turning the smart home into an unexamined extension of every AI application on the network.
