Reach Home Assistant from outside your network
Reach Home Assistant from outside your network with a Horizon tunnel, with WebSocket passthrough, reverse proxy settings and the external URL.
Open your Home Assistant at https://my-app.hrzn.run from any network, without router changes.
Anyone who has the URL can reach your Home Assistant sign-in page. Horizon has no password protection or IP allowlist. Home Assistant's security guide says to use a strong, unique password for every account and to turn on multi-factor authentication. It also recommends Home Assistant Cloud, a VPN or an SSH tunnel over exposing the instance directly. Stop the tunnel when you don't need it.
Before you begin
- Node.js 18 or later
- A Horizon account and the CLI (see Getting started)
- A reserved subdomain for
-s. Reserve one on the Subdomains page. - Home Assistant running, with an owner account
Start a tunnel
Home Assistant Container listens on port 8123. Home Assistant Operating System listens on port 80 from release 2026.8. Use the port your install uses. Use -s with a subdomain you reserved. Without it, the subdomain is random and changes every run. Reserved subdomains are a paid feature, see Pricing.
hrzn tunnel http://localhost:8123 -s my-appHORIZON: Tunnel connected
URL https://my-app.hrzn.run (reserved)
Forwarding http://localhost:8123
Request log https://hrzn.run/dashboard/tunnels/my-appIf Home Assistant runs on another machine, point the tunnel at that machine's address, for example http://192.168.1.50:8123. Keep this terminal open.
Horizon passes WebSockets through. The Home Assistant frontend needs a WebSocket connection, and it works without extra settings on the Horizon side.
Trust the proxy
Horizon sends X-Forwarded-For with the visitor's IP address and X-Forwarded-Host with the public host. Home Assistant blocks requests that carry these headers until you trust the proxy. The Horizon CLI connects to Home Assistant from the same machine, so Home Assistant sees the proxy at 127.0.0.1 or ::1.
Open Settings, System, Network. Turn on Trust X-Forwarded-For. Under Trusted proxies, add 127.0.0.1 and ::1. If the CLI runs on a different machine than Home Assistant, add that machine's address instead. Use a network address for a range, such as 192.168.1.0/24, not a host address.
Home Assistant releases before this setting moved to the UI use configuration.yaml:
http:
use_x_forwarded_for: true
trusted_proxies:
- 127.0.0.1
- ::1Restart Home Assistant after you change it.
Set the external URL
Home Assistant uses the external URL for links it builds for use from the internet. Open Settings, System, Network and set the external URL to https://my-app.hrzn.run. It takes a protocol, a host and a port, no path. In configuration.yaml it looks like this:
homeassistant:
external_url: https://my-app.hrzn.runCheck it works
Open https://my-app.hrzn.run in a browser outside your network. The first visit shows Before you continue. Select Continue to site, then sign in. The dashboard loads and its cards update live.
Your Horizon terminal prints a line per request:
GET 200 /Troubleshooting
Home Assistant blocks requests from the tunnel
Home Assistant's docs say requests from reverse proxies are blocked when the proxy options aren't set. Turn on Trust X-Forwarded-For and add 127.0.0.1 and ::1 to Trusted proxies, then restart. If the CLI runs on another machine, add that machine's address. Check the Home Assistant log for the address it reports.
The page loads but the dashboard never updates
The frontend runs over a WebSocket. Check that the Request log page shows the request to the WebSocket path. If it doesn't, check that the tunnel points at the right port.
The URL changed after a restart
You started the tunnel without -s, so Horizon gave you a new random subdomain. Restart with -s my-app and the URL stays the same. -s needs a subdomain you reserved, see Pricing.
Next steps
- Read Home Assistant's security recommendations.
- Read the HTTP integration reference.
Receive webhooks in self-hosted n8n
Receive webhooks in self-hosted n8n on localhost with a Horizon tunnel, and set WEBHOOK_URL so n8n shows the public URL.
Share a local WordPress site
Share a local WordPress site through a Horizon tunnel, and stop it redirecting to localhost by setting WP_HOME and WP_SITEURL.