User interface for configuration and administration of ioBroker.
This adapter uses Sentry libraries to automatically report exceptions and code errors to the developers. For more details and for information on how to disable the error reporting, see Sentry-Plugin Documentation! Sentry reporting is used starting with js-controller 3.0.
The JSON config schema description can be found at JSON config schema.
%ip%- ioBroker ip address (address of the admin)%secure%or%protocol%- read fromnative.securethe value and use http or https%web_protocol%- looking for the first instance of web (e.g.,web.0) and getnative.securefromsystem.adapter.web.0%instance%- instance of the adapter%someField%- get someField fromnativeof this adapter instance%web.0_bind%- getnative.bindfromsystem.adapter.web.0%native_someField%- get someField fromnativeof this adapter instance
Some adapters are not stable, or the connection disappears after one or two days. To fix this, there is a scheduled restart setting. To activate scheduled restart, just define CRON condition when to restart adapter.
It is suggested to restart in the night, when no one uses the adapter, e.g. 0 3 * * * - at 3:00 every day.
To manage and update, let's encrypt certificates you need to use iobroker.acme adapter.
You will have so-called "collections" of certificates. Each collection has its own domains. You can select in the configuration of the admin adapter if and which a collection to use.
The user has the possibility to limit the access to the instance configuration dialog. For that, the option "Allow access only to specific instances" must be activated. It could be found on the "Access to the instances" tab. Additionally, the allowed instances should be selected in the appeared configuration table.
If this option is disabled, the simple configuration page could be accessed under http://IP:8081/configs.html
The admin interface includes an AI assistant (the floating button in the lower-right corner). It can answer
questions about your ioBroker system, recommend adapters for a device or service, and — in "Actions" mode — make
changes after your explicit confirmation. The assistant must first be enabled in the admin instance settings
(native.disableMcp must be off); then pick an AI provider, credential and model in the assistant settings dialog.
If you do not want to configure an AI provider/API key inside ioBroker, you can instead drive the assistant from an external AI client (Claude Desktop, Codex, Gemini CLI, …). The client connects directly to ioBroker through the MCP (Model Context Protocol) server.
Open the assistant and click the "Use without an API key" button (the cable icon in the header). The dialog walks you through three steps:
- Install the MCP server — install the
iobroker.mcpadapter, ideally as a web extension of yourweb(oradmin) instance. It exposes ioBroker's tools to any MCP-compatible AI client. The dialog shows whether the adapter is already installed. - Add the MCP server in your AI client — register a new MCP server in your client using the URL shown in the
dialog, e.g.
http(s)://<host>:<port>/mcp. The dialog lists the actual endpoint(s) of your installation (the embedded admin endpoint and anyweb/mcpinstances) together with a copy button. - System prompt — the same dialog also shows the exact system prompt the built-in assistant uses, with a read-only/actions toggle and a copy button. It is intentionally not reproduced here; copy it from the dialog and paste it as the system/instructions prompt in your AI client to get the same behaviour.
The reverse proxy documentation can be found at Reverse proxy.
This project uses icons from Flaticon.
ioBroker GmbH has a valid license for all used icons. The icons may not be reused in other projects without the proper flaticon license or flaticon subscription.
- (@krobipd) Fixed: with the GUI settings stored on the server, a window of the admin threw away what others had saved in the meantime
- (@GermanBluefox) Fixed: compressed log files (
.gz) are shown unpacked again - (@GermanBluefox) Fixed: the link of a web extension to its own service (e.g.
http://%native_friurl%of frigate) was sent to the web instance
- (@GermanBluefox) Fixed: "Save & Close" of the base settings was active while the settings were still loading
- (@GermanBluefox) Changed: the news in the update dialogs are rendered as Markdown
- (@GermanBluefox) Fixed: links with
localhost,127.0.0.1or0.0.0.0(e.g.http://%native_friurl%) now use the address of the instance's host - (@GermanBluefox) Fixed: the log search and the MCP info dialog require the
executeright - (@GermanBluefox) Fixed: the AI assistant no longer trusts endpoint, permissions and confirmations from the request; tools run with the rights of the user who asked. Reported by two external security researchers
- (@GermanBluefox) Fixed: AI assistant answers and log searches longer than 30 seconds ended in an empty answer or "timeout"; the result is pushed to the browser now
- (@GermanBluefox) Added: "Maximum answer length" in the settings of the AI assistant (Anthropic)
- (@GermanBluefox) Fixed: the news of the notification dialog were always shown in English (#3534)
- (@GermanBluefox) Fixed: the notification dialog showed "undefined" when a translation was missing
- (@GermanBluefox) Fixed: Chrome offered to generate and store a password in the API key fields of the credentials
- (@GermanBluefox) Changed: the info dialog of a host on the quick access page shows what it knows instead of what the host sends. Every line has an icon in front of it - the penguin, the window, the apple or the daemon for the platform, a chip for the CPU, a clock for the time - the names start with a capital letter, and a
trueis now a "Yes". The disk is no longer two lines with two numbers but one bar that fills with the free space,11.8 GB / 26.2 GB, red as soon as less than a tenth is left. The time of the host was a bare timestamp like1790980340380because the entry was looked up underTimewhile the host calls ittime; it is now the wall clock of the host, shifted by the time zone the host reports, so neither UTC nor the time zone of the browser is shown - (@GermanBluefox) Changed: "adapters count" is called "Adapters in repository" now. It counts the adapters that the active repository offers - 812 of them - and was read as the number of the installed ones
- (@GermanBluefox) Fixed: ENTER in the "Write value" dialog reloaded the whole GUI now and then. Its inputs sit in a
<form>whoseonSubmitreturnedfalse- which prevents nothing in react - so the browser submitted the form, and as it has noaction, it requested the current address anew. Chrome submits on ENTER in a one line input and on CTRL+ENTER in a text area, which is exactly when it happened. The same form is used by the value editor of the history table and by the multihost settings - (@GermanBluefox) Added: CTRL+ENTER confirms the dialogs of the object browser, the expert mode included: "Write value" whatever the type of the state is, "Edit object", the role, the alias, the new object, the custom settings ("Save & close"), rename/copy and the import of objects. Only a few text fields reacted to the combination, the JSON editors and all other inputs did not, and nothing told about the shortcut - the confirming button of every one of these dialogs carries the hint as a tooltip now
- (@GermanBluefox) Changed: a global dependency has to be fulfilled on every host of a multihost system, but the update dialog showed a single version and crossed it out -
admin (>=8.0.0): 8.0.14with a red cross in front of it, which reads as if 8.0.14 were older than 8.0.0. The hosts that still run a version that is too old are listed under the line now, each with the version it has, and the tooltip of the adapter row says the same instead of "Invalid version of admin. Required >=8.0.0. Current 8.0.14" (#3666) - (@GermanBluefox) Added: an instance whose adapter is not installed on its host is marked as such. It can never start, and nothing said why - it stayed red among the ones that are merely stopped. A restored backup leaves such instances behind: the objects of the adapter come back with the backup, while the code of an adapter that has left the repository,
flotfor example, cannot be installed any more. The status indicator of the row carries an error sign now, the tile one next to the name, and both say "The adapter is not installed on host ..." on hover. Only the host itself knows what it really has, so every host that runs is asked - without the list of the instances waiting for the answer (#3626) - (@GermanBluefox) Added: the context menu of the object browser has an entry "Edit name" (Alt+9), without the expert mode and next to "Edit function" and "Edit room". Changing the name of an object is an everyday operation, but it was only reachable through "Edit object" - which the expert mode hides. A name that is translated keeps its other languages, only the language of the GUI is written (#3640). Lives in
@iobroker/gui-componentsand needs its next version - (@GermanBluefox) Fixed: the settings page of admin showed the whole "Single sign-on" tab in English, whatever the language: none of its labels and hints had ever reached
admin/i18n, so every one of them fell back to its English key. The five texts of the AI assistant about leaving a tab were missing in nine languages, and the hint about the filtered adapters was left in English in Chinese
- (@GermanBluefox) Fixed: the link of an adapter that runs as a web extension lost everything behind the host.
energiefluss-erweitertpoints at.../energiefluss-erweitert/?instance=%instance%, and the quick access offered.../energiefluss-erweitert/- without the page and without the instance. Such an adapter has no own port, so the origin of its link has to come from the web instance that serves it, but the whole address was built anew instead of only its origin being exchanged. The same happened tohabpanel, whoseindex.htmldisappeared, and to a second link of an adapter that pointed at its documentation on a foreign host: it ended up on the own web server (#3661) - (@GermanBluefox) Fixed: a card of the quick access belonged to whichever adapter was processed first. Every vis-2 widget adapter registers a link to the vis-2 runtime, and because the instance IDs decide the order,
vis-2itself lost its own card to one of them, together with its name, its icon and its color. The card now belongs to the adapter that serves the page - (@GermanBluefox) Added: the admin recognizes that it was opened through the remote access of ioBroker Cloud/Pro and moves the links onto the service. The quick access, the instance list and the tabs of the left menu pointed into the local network, which is of no use to somebody who is not in it. Which instances the service publishes is read from the configuration of the
cloudoriotadapter, so nothing is guessed: the web instance is reachable at/, the admin at/admin/and lovelace at/lovelace/. A page the service does not publish - Node-RED or a second admin, for example - is no longer offered as a dead link but shown dimmed with a note that it only works in the local network - (@GermanBluefox) Added: the identity provider for the single sign-on can be configured. The issuer, the client ID, an optional client secret and the scopes are set in the new "Single sign-on" tab of the admin settings, and the endpoints are read from the discovery document of the issuer, so every provider that follows the standard works. Without a complete configuration the SSO stays off and the login page does not offer it (needs
@iobroker/webserver3.3.0) - (@GermanBluefox) Fixed: with authentication enabled, the GUI took seconds to come up and sometimes did not come up at all. If the access token had expired while the tab was closed, the websocket was opened with it, the server asked for a new one and then stopped listening on that connection: the token the browser fetched within milliseconds could not be announced, the browser waited for an answer that could not come until its own three second timeout, and the single-use refresh token was burnt for nothing before the whole start began again (needs
@iobroker/socket-classes2.6.2) - (@GermanBluefox) Changed:
mimewas replaced bymime-types.mime4 is ESM only, and version 3 is no longer maintained;mime-typesuses the same database, is already part of the dependency tree through express, and three duplicated copies of it disappear from the lockfile. A JavaScript file is now served astext/javascriptinstead of the deprecatedapplication/javascript
- (@GermanBluefox) Fixed: on a grown installation, the start of the GUI ran into "Detected slow connection!" and the dialog offering a longer read timeout, on a fast local network as well. The start page read the whole object database only to count the objects and the states for its tile - 32 MB on a system with 10,000 objects - which blocked the admin process for seconds, so every other request of the start waited for it and ran into its own timeout. The counting is now done by the server, which answers with two numbers instead (needs
@iobroker/socket-classes2.6.0 and@iobroker/socket-client5.4.0; an older backend still reads all objects, but delayed until the start is through). The whole start now transfers 2.4 MB, and the object database is no longer part of it (#3656) - (@GermanBluefox) Fixed: the news check read all objects a second time, right after the start page had read them
- (@GermanBluefox) Fixed: the admin stayed on its logo and only came up after the page was reloaded. The start reads its own settings, the easy mode and the GUI settings one after the other, and each of them with a timeout of five seconds - which is less than a busy host needs for the first requests. Those reads no longer end the start, and whatever else goes wrong, the app is shown instead of the loader: the menu, the error message and the reconnect are more use than a logo that never goes away (#3641)
- (@GermanBluefox) Changed: the read timeout starts at 30 seconds instead of 15 (60 instead of 40 in the cloud), and it now applies to every request of the start instead of only to the repository and the installed versions
- (@GermanBluefox) Changed: the dialog about a slow connection only appears for a read the user asked for - switching the host or retrying from the dialog itself. Nothing waits for the read of the start any more, so a dialog there interrupted a start that was going perfectly well otherwise
- (@GermanBluefox) Added: the "Resource usage" card has a button that first stops the recording of CPU and RAM by the history instance, then collapses the card, which gives the system log room for 16 lines instead of 6. A collapsed card reads nothing at all until it is opened again, and it stays collapsed after a reload (needs
@iobroker/gui-components10.3.7) - (@GermanBluefox) Fixed: a timeout while reading
guiSettingsat the start overwrote the stored GUI settings of the user with the defaults - (@GermanBluefox) Fixed: the system log of the start page was left empty by "Cannot get logs: TypeError: e.pop is not a function" when the host answered with anything but its log lines
The MIT License (MIT)
Copyright (c) 2014-2026 bluefox dogafox@gmail.com