Why Home Assistant needs this

When a request travels through a reverse proxy, the proxy tells Home Assistant who the original visitor was in the X-Forwarded-For header. Anyone can write that header, so Home Assistant only accepts it from addresses you have explicitly listed as trusted proxies. A request that carries the header from anywhere else is rejected with 400: Bad Request, and Home Assistant writes one of these lines to its log:

A request from a reverse proxy was received from 172.30.32.1, but your HTTP integration is not set-up for reverse proxies
Received X-Forwarded-For header from an untrusted proxy 172.30.32.1

The Pluggie app forwards every request with the visitor's address in that header, so Home Assistant has to trust it once. The address shown in the log line is the one Home Assistant sees for Pluggie — useful if you are not sure what to enter below.

Which address to trust

Your setup Trusted proxy to add
Home Assistant OS or Supervised, with the Pluggie app 172.30.32.0/23
Home Assistant Container or Core, with the Pluggie Docker container The address of the Pluggie container as Home Assistant sees it — the IP from the log line above

172.30.32.0/23 is the internal network Home Assistant uses for all apps. It also covers other apps that act as a proxy, such as NGINX Proxy Manager or Cloudflared, so you can use the same entry for all of them.

Do this from your home network

Until the setting is saved, Home Assistant keeps rejecting requests that arrive through Pluggie. Open Home Assistant locally — for example http://homeassistant.local:8123 or http://<IP address of your Home Assistant>:8123 (new Home Assistant OS installations since 2026.8 listen on port 80, so use http://homeassistant.local without a port) — and sign in as an administrator.

Home Assistant 2026.8 or newer

Since 2026.8, the HTTP settings are in the user interface instead of configuration.yaml.

1
Open the HTTP server settings

Go to Settings → System → Network and find the HTTP server section. If you do not see it right after an update, reload the page.

2
Turn on "Trust X-Forwarded-For"

Without it, Home Assistant ignores the trusted proxies list and keeps blocking proxied requests.

3
Add the address to "Trusted proxies"

Enter 172.30.32.0/23, or the address of your Pluggie Docker container. If the list already contains entries, keep them and add the new one.

4
Save and confirm

Home Assistant restarts. Afterwards it asks you to confirm the new settings. If you do not confirm within 5 minutes, it returns to the previous settings — a safety net in case a change makes Home Assistant unreachable.

5
Test

Open your Pluggie address, for example https://yourname.pluggie.net. The Home Assistant login page should appear.

Home Assistant older than 2026.8

Add this to configuration.yaml and restart Home Assistant. If you already have an http: section, add the two keys to it instead of creating a second one.

http:
  use_x_forwarded_for: true
  trusted_proxies:
    - 172.30.32.0/23  # Pluggie app
Upgrading later?

When you upgrade to 2026.8 or newer, Home Assistant imports the http: section into the new HTTP server settings on the first start and shows a repair asking you to remove it from configuration.yaml. Remove it and restart — the YAML configuration stops working in Home Assistant 2027.2.0.

Pluggie Docker container with Home Assistant Container

The steps are the same. Only the address is different: instead of 172.30.32.0/23, trust the address that Home Assistant sees for the Pluggie container. The easiest way to find it is the log line from the beginning of this guide — open your Pluggie address once, then look for "untrusted proxy" or "not set-up for reverse proxies" in the Home Assistant log. If both containers run on the same machine, it is usually a Docker network address such as 172.17.0.5. If Pluggie runs on a different machine, it is that machine's LAN address.

A single address can be entered as it is, or as 172.17.0.5/32.

Common mistakes

Locked out?

If Home Assistant becomes unreachable after a change, do not confirm it — the previous settings return after 5 minutes. You can always reach Home Assistant from your home network on its local address, because the trusted proxy setting only affects requests that come through a proxy. As a last resort, the HTTP server settings are stored in .storage/http in your configuration folder; edit that file only while Home Assistant is stopped.

What you get afterwards

With the trusted proxy in place and Pluggie 0.7.0 or newer, Home Assistant sees the real IP address of every visitor. Failed login notifications show who actually tried, and you can safely turn on IP banning in the same HTTP server settings. Read more in Home Assistant Now Sees the Real IP Address of Every Visitor.

📬 Still seeing 400?

Send the "untrusted proxy" line from your Home Assistant log to support@pluggie.net and we will tell you exactly what to enter.