Why Home Assistant needs this
When a request travels through a reverse proxy, the proxy tells Home Assistant who the original visitor was in the X-Forwarded-For header. Anyone can write that header, so Home Assistant only accepts it from addresses you have explicitly listed as trusted proxies. A request that carries the header from anywhere else is rejected with 400: Bad Request, and Home Assistant writes one of these lines to its log:
A request from a reverse proxy was received from 172.30.32.1, but your HTTP integration is not set-up for reverse proxies
Received X-Forwarded-For header from an untrusted proxy 172.30.32.1
The Pluggie app forwards every request with the visitor's address in that header, so Home Assistant has to trust it once. The address shown in the log line is the one Home Assistant sees for Pluggie — useful if you are not sure what to enter below.
Which address to trust
| Your setup | Trusted proxy to add |
|---|---|
| Home Assistant OS or Supervised, with the Pluggie app | 172.30.32.0/23 |
| Home Assistant Container or Core, with the Pluggie Docker container | The address of the Pluggie container as Home Assistant sees it — the IP from the log line above |
172.30.32.0/23 is the internal network Home Assistant uses for all apps. It also covers other apps that act as a proxy, such as NGINX Proxy Manager or Cloudflared, so you can use the same entry for all of them.
Until the setting is saved, Home Assistant keeps rejecting requests that arrive through Pluggie. Open Home Assistant locally — for example http://homeassistant.local:8123 or http://<IP address of your Home Assistant>:8123 (new Home Assistant OS installations since 2026.8 listen on port 80, so use http://homeassistant.local without a port) — and sign in as an administrator.
Home Assistant 2026.8 or newer
Since 2026.8, the HTTP settings are in the user interface instead of configuration.yaml.
Go to Settings → System → Network and find the HTTP server section. If you do not see it right after an update, reload the page.
Without it, Home Assistant ignores the trusted proxies list and keeps blocking proxied requests.
Enter 172.30.32.0/23, or the address of your Pluggie Docker container. If the list already contains entries, keep them and add the new one.
Home Assistant restarts. Afterwards it asks you to confirm the new settings. If you do not confirm within 5 minutes, it returns to the previous settings — a safety net in case a change makes Home Assistant unreachable.
Open your Pluggie address, for example https://yourname.pluggie.net. The Home Assistant login page should appear.
Home Assistant older than 2026.8
Add this to configuration.yaml and restart Home Assistant. If you already have an http: section, add the two keys to it instead of creating a second one.
http:
use_x_forwarded_for: true
trusted_proxies:
- 172.30.32.0/23 # Pluggie app
When you upgrade to 2026.8 or newer, Home Assistant imports the http: section into the new HTTP server settings on the first start and shows a repair asking you to remove it from configuration.yaml. Remove it and restart — the YAML configuration stops working in Home Assistant 2027.2.0.
Pluggie Docker container with Home Assistant Container
The steps are the same. Only the address is different: instead of 172.30.32.0/23, trust the address that Home Assistant sees for the Pluggie container. The easiest way to find it is the log line from the beginning of this guide — open your Pluggie address once, then look for "untrusted proxy" or "not set-up for reverse proxies" in the Home Assistant log. If both containers run on the same machine, it is usually a Docker network address such as 172.17.0.5. If Pluggie runs on a different machine, it is that machine's LAN address.
A single address can be entered as it is, or as 172.17.0.5/32.
Common mistakes
- A host address with a network mask.
172.30.32.1/23is not a valid network. Use the network address172.30.32.0/23, or a single address without a mask. - Replacing existing entries. If another proxy is already listed, removing it breaks that proxy. Add Pluggie next to it.
- Trusting everything. Entering
0.0.0.0/0or your whole home network makes the error go away, but then any device on that network can claim to be any IP address — and IP banning can be bypassed. Trust only the address Pluggie actually uses. - Not confirming after the restart. Home Assistant silently reverts unconfirmed settings after 5 minutes, and the 400 error comes back.
Locked out?
If Home Assistant becomes unreachable after a change, do not confirm it — the previous settings return after 5 minutes. You can always reach Home Assistant from your home network on its local address, because the trusted proxy setting only affects requests that come through a proxy. As a last resort, the HTTP server settings are stored in .storage/http in your configuration folder; edit that file only while Home Assistant is stopped.
What you get afterwards
With the trusted proxy in place and Pluggie 0.7.0 or newer, Home Assistant sees the real IP address of every visitor. Failed login notifications show who actually tried, and you can safely turn on IP banning in the same HTTP server settings. Read more in Home Assistant Now Sees the Real IP Address of Every Visitor.
Send the "untrusted proxy" line from your Home Assistant log to support@pluggie.net and we will tell you exactly what to enter.