Skip to content

Add getting the API key from the device, with a press on its button - #1199

Merged
frenck merged 1 commit into
mainfrom
frenck/local-api-key
Oct 3, 2026
Merged

frenck merged 1 commit into
mainfrom
frenck/local-api-key

Conversation

@frenck

@frenck frenck commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Proposed Changes

(Describe the changes and rationale behind them)

Devices from 2022 onward can hand out their API key locally, after someone presses the button on top of the device. No LaMetric account or cloud involved. This adds LaMetricLocalAuth for that:

  1. request_challenge() makes the device show CLICK ME, and returns an AuthChallenge.
  2. challenge(challenge_id=...) polls it. resolved turns true once the button is pressed; the state goes to expired when the time runs out.
  3. api_key(challenge_id=...) exchanges the resolved challenge for a web admin key, and uses that to read the API key from the users of the device. A key generated in the LaMetric app is preferred over the one of the LaMetric account.

This matters for Home Assistant: according to the LaMetric docs, a key generated in the app stays on the device and is not synced to the cloud, so the cloud based config flow cannot see it.

This uses the web interface of the device (port 443), which LaMetric does not document. The flow was described in #915; I tested it end to end on a real sa8 TIME on firmware 3.2.6, with a press on the button, and the key it returned is the one the device API accepts. An LM 37X8 TIME on firmware 2.3.9 has no web interface and answers with a 401; request_challenge() turns that into a clear "does not support" error rather than an authentication error.

Two differences from what #915 describes, seen on the real device:

  • Without a key generated in the app, there is no local integration key, only the account one. api_key() falls back to that one.
  • The web interface answers errors as {"error": {"message": ...}} instead of {"errors": [...]}. error_message() now understands both, so the reason of the device is passed on, for example "Invalid challenge status in-progress".

Nothing is retried: requesting a challenge twice would show it twice on the device. The test fixtures are the answers of the real sa8, with keys and IDs replaced.

Related Issues

(Github link to related issues or pull requests)

Closes #915

Devices from 2022 onward can hand out their API key locally: request a
challenge, have someone press the button on top of the device while it
shows it, and exchange the resolved challenge for the key. No LaMetric
account or cloud involved.

This uses the web interface of the device, which LaMetric does not
document. Tested end to end on an sa8 TIME on firmware 3.2.6. An LM 37X8
TIME does not have it, and now says so.

The error helper also understands the error shape of that web interface,
so the reason of the device is passed on.
@frenck frenck added the new-feature New features or options. label Oct 3, 2026
@frenck
frenck merged commit 99534cc into main Oct 3, 2026
32 checks passed
@frenck
frenck deleted the frenck/local-api-key branch October 3, 2026 12:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new-feature New features or options.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support for non cloud based API key retrieval, directly from LaMetric Time device

1 participant