AUTHENTICATION
Device authentication
Credentials identify one purpose and never expand ownership.
REST and WebSocket
REST ingestion sends X-Device-Secret. Realtime connects to wss://api.homeautopro.in/ws/device/<DEVICE_CODE> and immediately sends:
{"type":"auth","device_secret":"YOUR_DEVICE_SECRET"}The Device ID is safe identity metadata. The Device Secret remains local and is never inserted by documentation or Assistant.