ha-login-approval
ghcr.io/nebur692/ha-login-approval:latest
bridge
sh
false
https://forums.unraid.net/topic/200264-support-ha-login-approval-nebur692/
https://github.com/Nebur692/ha-login-approval
Approve or reject sign-ins from a Home Assistant push notification. Truly PASSWORDLESS login, acting as a generic OIDC identity provider compatible with ZITADEL, Keycloak, Authentik, or any standard OIDC-capable relying party. Includes one-time recovery codes, IP blocking after 3 failed attempts, optional GeoIP enrichment, and a full admin panel.
Full step-by-step guide (registering the IDP in ZITADEL/Keycloak/Authentik, the admin panel, every variable): https://github.com/Nebur692/ha-login-approval
Admin panel: http://IP:8000/admin
IMPORTANT if you run this behind a reverse proxy (Nginx Proxy Manager, Traefik, Caddy...): set "Trusted proxies" below to your proxy's address. Until you do, this service uses the address it is connected from, so every notification and audit entry will show the proxy instead of the visitor, and location lookups will be meaningless. Sign-in itself keeps working either way.
Security:
http://[IP]:[PORT:8000]/admin
https://raw.githubusercontent.com/Nebur692/ha-login-approval/main/ha-login-approval.xml
https://raw.githubusercontent.com/Nebur692/ha-login-approval/main/.github/images/ha-login-approval_logo.png
--restart unless-stopped
Support this project
https://ko-fi.com/nebur69265723
Home Assistant (with the Companion App installed on at least one device) and an OIDC-capable identity provider (ZITADEL, Keycloak, Authentik...) where you'll register this service as a generic external identity provider.
admin
8000
/mnt/user/appdata/ha-login-approval
120
60
3
10
3