Horizon

Reach Home Assistant from outside your network

Reach Home Assistant from outside your network with a Horizon tunnel, with WebSocket passthrough, reverse proxy settings and the external URL.

Open your Home Assistant at https://my-app.hrzn.run from any network, without router changes.

Before you begin

  • Node.js 18 or later
  • A Horizon account and the CLI (see Getting started)
  • A reserved subdomain for -s. Reserve one on the Subdomains page.
  • Home Assistant running, with an owner account

Start a tunnel

Home Assistant Container listens on port 8123. Home Assistant Operating System listens on port 80 from release 2026.8. Use the port your install uses. Use -s with a subdomain you reserved. Without it, the subdomain is random and changes every run. Reserved subdomains are a paid feature, see Pricing.

hrzn tunnel http://localhost:8123 -s my-app
Output
HORIZON: Tunnel connected
  URL          https://my-app.hrzn.run (reserved)
  Forwarding   http://localhost:8123
  Request log  https://hrzn.run/dashboard/tunnels/my-app

If Home Assistant runs on another machine, point the tunnel at that machine's address, for example http://192.168.1.50:8123. Keep this terminal open.

Horizon passes WebSockets through. The Home Assistant frontend needs a WebSocket connection, and it works without extra settings on the Horizon side.

Trust the proxy

Horizon sends X-Forwarded-For with the visitor's IP address and X-Forwarded-Host with the public host. Home Assistant blocks requests that carry these headers until you trust the proxy. The Horizon CLI connects to Home Assistant from the same machine, so Home Assistant sees the proxy at 127.0.0.1 or ::1.

Open Settings, System, Network. Turn on Trust X-Forwarded-For. Under Trusted proxies, add 127.0.0.1 and ::1. If the CLI runs on a different machine than Home Assistant, add that machine's address instead. Use a network address for a range, such as 192.168.1.0/24, not a host address.

Home Assistant releases before this setting moved to the UI use configuration.yaml:

configuration.yaml
http:
  use_x_forwarded_for: true
  trusted_proxies:
    - 127.0.0.1
    - ::1

Restart Home Assistant after you change it.

Set the external URL

Home Assistant uses the external URL for links it builds for use from the internet. Open Settings, System, Network and set the external URL to https://my-app.hrzn.run. It takes a protocol, a host and a port, no path. In configuration.yaml it looks like this:

configuration.yaml
homeassistant:
  external_url: https://my-app.hrzn.run

Check it works

Open https://my-app.hrzn.run in a browser outside your network. The first visit shows Before you continue. Select Continue to site, then sign in. The dashboard loads and its cards update live.

Your Horizon terminal prints a line per request:

Output
  GET     200  /

Troubleshooting

Home Assistant blocks requests from the tunnel

Home Assistant's docs say requests from reverse proxies are blocked when the proxy options aren't set. Turn on Trust X-Forwarded-For and add 127.0.0.1 and ::1 to Trusted proxies, then restart. If the CLI runs on another machine, add that machine's address. Check the Home Assistant log for the address it reports.

The page loads but the dashboard never updates

The frontend runs over a WebSocket. Check that the Request log page shows the request to the WebSocket path. If it doesn't, check that the tunnel points at the right port.

The URL changed after a restart

You started the tunnel without -s, so Horizon gave you a new random subdomain. Restart with -s my-app and the URL stays the same. -s needs a subdomain you reserved, see Pricing.

Next steps

On this page