Passwords, Tokens, the Mobile App, and a Lost Phone

Passwords, Tokens, the Mobile App, and a Lost Phone

Module 8 · Lesson 3

With accounts properly separated, this lesson covers the credentials themselves: strong passwords, password managers, long-lived tokens, the mobile app's own sessions, and exactly what to do the moment a phone goes missing.

A strong password

A strong password for Home Assistant means long, unique, and never reused anywhere else, a random string of at least sixteen characters, or a memorable passphrase of four or five unrelated words, both work well and both resist the credential-stuffing attacks Lesson 1 described. Length matters more than complexity for resisting brute-force guessing, and uniqueness matters more than either for resisting the leaked-password databases attackers actually use in practice, since a password that's never appeared anywhere else simply can't show up in one of those databases to begin with.

A password manager

A password manager, whether a standalone app or one built into your browser or phone's operating system, generates and remembers a genuinely unique password for every account you have, Home Assistant included, so you never have to actually memorize or reuse one. This is the single most practical tool for following the previous section's advice consistently, without a password manager, most people quietly drift back toward reused or simplified passwords within a few months simply because remembering a dozen truly random strings by hand isn't realistic for anyone. If you don't already use one, setting one up is worth doing before moving further into this lesson.

Sessions and logged-in devices

Every device you've logged into, your phone, a tablet, a laptop browser, shows up as an active session under your user profile, along with roughly when and where it last connected. Reviewing this list occasionally, alongside the login history Lesson 2 mentioned, is worth doing the same way you'd occasionally glance at a bank statement, not out of anxiety, but as basic account hygiene. Revoke any session you don't immediately recognize right away, and revoke sessions for devices you no longer actually own or use, an old phone traded in years ago has no real business still holding an active session to your smart home.

Long-lived access tokens

Beyond your regular login, Home Assistant lets you generate long-lived access tokens, special credentials used by scripts, third-party integrations, or automations outside Home Assistant itself that need programmatic access without a human typing a password each time. Treat every token exactly like a password, give each one a clear, specific name describing what uses it, and revoke any token the moment whatever used it is no longer in service. An old, forgotten token still technically works forever unless revoked, quietly outliving the project it was created for and sitting there as an unnecessary, unmonitored point of access.

The Home Assistant mobile app

Once logged into the mobile app, it stays signed in indefinitely by default, exactly like most apps you use daily, meaning your phone's own lock screen becomes the practical barrier standing between anyone who picks it up and your Home Assistant dashboard. This makes a strong phone lock screen, a PIN, pattern, or biometric unlock, a genuinely essential part of your overall Home Assistant security, not a separate, unrelated concern. If your phone doesn't currently have one enabled, this is genuinely worth fixing before anything else covered in this lesson.

Common phone and password mistakes

A few mistakes show up repeatedly: saving the Home Assistant password as an unencrypted note in a phone's default notes app, texting it to a family member instead of setting up their own account the way Lesson 2 described, disabling the phone's lock screen "just for convenience," and leaving the mobile app permanently logged in on a device that then gets sold, traded in, or handed down without first logging out and revoking its session. Each of these individually feels minor, together they meaningfully undercut everything else this module builds.

A lost phone

If your phone is lost or stolen, act in this order: use your phone's own remote-lock or remote-wipe feature first, most phones support this natively and it's the fastest way to deny physical access. Then, from another device, log into Home Assistant and revoke that phone's session from your user profile, immediately cutting off its access even if the remote lock somehow fails or the thief gets past it. Finally, change your Home Assistant password as a precaution if the phone didn't have a lock screen at all, since anyone who picked it up may have had a brief window of unlocked access to the app before you acted.

Getting a new phone

When upgrading to a new phone normally, log into the Home Assistant app on the new device, confirm it works exactly as expected, and then explicitly log out of and revoke the old device's session rather than simply leaving it dormant. If the old phone is being sold or traded in, do this before handing it over, not after, and if you use two-factor authentication with an app tied to that specific phone, transfer or re-register it to the new device as part of the same changeover, rather than discovering it's broken the next time you try to log in somewhere new.

VPN profiles from Module 7

If you chose WireGuard or Tailscale in Module 7, each device's VPN profile is itself a credential worth treating with the same care as a password, a lost phone with an active WireGuard configuration or Tailscale login has a path into your entire home network, not just your Home Assistant dashboard specifically. Revoking a lost device's VPN access, from your router's WireGuard peer list or Tailscale's own admin console, belongs on the exact same lost-phone checklist as revoking its Home Assistant session, treat both as one combined step rather than two separate afterthoughts.

Local access versus remote access on your phone

Recall from Module 7 that Nabu Casa's Remote UI switches automatically between local and remote connections depending on which WiFi network your phone is on, while WireGuard and Tailscale generally need their own toggle active, and Cloudflare Tunnel simply works the same way from anywhere. Whichever method you chose, the credentials this lesson covers, password, two-factor authentication, VPN profile, apply identically regardless of whether you happen to be connecting locally or remotely at any given moment.

Cloudflare Access: just a preview

If you set up Cloudflare Tunnel in Module 7, Lesson 6 of this module covers Cloudflare Access, an optional additional login layer sitting in front of your tunnel, requiring authentication through Cloudflare itself before your Home Assistant login page even loads. It's not required, and this lesson doesn't assume you have it, but it's worth knowing it exists as you think through this lesson's password and token practices, since Access adds a second, independent credential to the same lost-phone and account-hygiene checklist this lesson has been building.

What to record in your notebook

Add a Credentials section to your notebook noting which password manager you use, without the master password itself, how many active long-lived tokens exist and what each one is for, and a short written version of this lesson's lost-phone checklist so you're not searching for it under stress the one time you actually need it. A calm, already-written checklist is worth far more to you in the moment than trying to recall these exact steps entirely from memory during a real, actual emergency.

Exercise

Check your Home Assistant password against your password manager, is it genuinely unique and long enough, review your active sessions and long-lived tokens carefully and revoke anything you don't immediately recognize or no longer actually need, and confirm your phone actually has a working lock screen enabled right now. Then write your lost-phone checklist into your notebook in full, using this lesson's order as a starting template you can refine over time.

Browser-saved passwords on shared computers

If you ever log into Home Assistant from a shared or public computer, a library terminal, a hotel business center, a friend's laptop, decline the browser's offer to save your password on that device, and log out explicitly when you're done rather than simply closing the tab. A saved password on a computer you don't control is functionally the same risk as writing it on a sticky note left behind on someone else's desk, convenient in the moment, but a small, lingering exposure that quietly outlives the actual reason you happened to be there in the first place. Your own personal devices, protected by the lock screen this lesson already covered, are a genuinely different and much safer story.

A real story: the trade-in that almost went wrong

A reader in this course's community traded in an old phone at a retail store, only to realize on the drive home that the Home Assistant app, along with a WireGuard profile from Module 7, was still active and logged in on it, having forgotten this lesson's changeover checklist in the excitement of getting a new device. A quick call to the store confirmed the trade-in devices hadn't yet been processed, giving them a narrow window to remotely revoke both the Home Assistant session and the WireGuard peer before the old phone left their control for good. It worked out, but only through luck and a fast phone call, exactly why this lesson frames the changeover checklist as something to run through before handing a device over, not something to remember afterward under pressure.

Two-factor authentication apps and switching phones

Most authenticator apps support either a built-in cloud backup or a manual export and import process specifically for moving to a new phone, worth doing deliberately as part of any phone changeover rather than discovering, mid-login on the new device, that your two-factor codes no longer generate correctly. If you ever do get locked out this way, the recovery codes from Lesson 2 are exactly the fallback meant for this situation, one more reason they're worth storing somewhere secure and genuinely accessible rather than buried and forgotten.

Biometric unlock and its limits

Fingerprint and face unlock are genuinely convenient and, for the everyday threat model this lesson focuses on, a reasonable lock screen choice, meaningfully better than no lock screen at all. It's worth knowing their limits too: biometric unlock can sometimes be legally compelled in ways a memorized PIN cannot in certain jurisdictions, and it can occasionally be bypassed by a sufficiently determined and well-resourced attacker in ways a long, random PIN generally resists better. For the overwhelming majority of readers, this distinction is far more theoretical than practical, and any lock screen at all is dramatically better than the alternative of having none, but it's still worth knowing this particular tradeoff exists in case your own personal threat model genuinely calls for something more cautious than the default choice.

Auto-fill and credential syncing across devices

Most password managers sync automatically across every device tied to your account, meaning updating your Home Assistant password on your laptop makes it immediately available on your phone too, without needing to manually re-type or re-save it anywhere. This is genuinely convenient, but it also means your password manager's own master password and its own two-factor authentication deserve just as much care as anything covered so far in this lesson, since it now effectively guards every single other credential behind it, Home Assistant fully included, in one single, unified place.

Putting it all together before moving on

Between Lesson 2's account separation and this lesson's password, token, and phone hygiene, you now have a genuinely solid identity and access layer protecting your Home Assistant server, arguably the single most impactful pair of lessons in this entire module for the actual, everyday risk most households face. Nothing here required buying anything at all or touching a single line of YAML, only a handful of deliberate, repeatable habits, which is precisely why it's worth getting right now, while your system is still small and manageable enough that fixing an oversight takes only minutes rather than the many hours it might eventually take once dozens of devices and automations all depend on the same underlying accounts.

Key takeaways

Use a password manager, a unique password beats a memorable but reused one every time.

Your phone's lock screen is the practical barrier once the Home Assistant app is logged in.

A lost phone: remote-lock it, revoke its session, revoke its VPN access, in that order.

Name and periodically review every long-lived token, revoke ones no longer in use.

Lesson 4 covers the single most important safety net in this entire module, backups, since a good, properly tested backup undoes nearly any other mistake this lesson or the ones before it might somehow fail to catch in time before it becomes a real problem.

Finished this lesson?