fix: add Govee 2FA login support - #652
Conversation
|
this is a really enormous changeset that covers a lot more than 2fa support |
caa2326 to
a26b83f
Compare
|
Thanks, you're right. I rewrote this from current Current scope is one commit, 5 files, all directly tied to 2FA login support:
No MQTT discovery topics, HA MQTT entity schema, availability topics, fork branding, CI, image config, changelog, or unrelated history remain in the PR. Local |
…uirks API resilience - undoc_api: env/CLI-overridable Govee Home app version (--govee-app-version / GOVEE_APP_VERSION) with helpful error when Govee raises the minimum. Recovers without a new release when login returns "app version is too low". Covers issues wez#622, wez#626, wez#627, wez#628, wez#637, wez#647, wez#649. - undoc_api: Govee 2FA login support (status 454/455). Auto-requests an email code on first failure; user supplies it via --govee-2fa-code / GOVEE_2FA_CODE and restarts. Closes wez#656/wez#652. - iot: refresh transaction IDs on every publish (Govee dedupes on transaction; reusing one silently drops the publish). Likely fixes wez#635 Tap-to-Run drops. - hass: client id uses '-' instead of '/' so Mosquitto 7 doesn't reject it as a "dangerous client id". Closes wez#659/wez#661. New entities - fan.rs: HA MQTT Fan entity backed by the existing workMode/percent machinery. Power, speed-percentage (FanSpeed mode), and preset modes all wired up. - sensor.rs: DeviceSettingDiagnostic exposes battery % and Wi-Fi level from the undoc DeviceSettings struct. Wi-Fi has no device_class (Govee reports 0-100% but HA's signal_strength expects dBm). Covers wez#646/wez#668. - sensor.rs: carbonDioxideConcentration, pm25, pm10 mappings with correct units, device classes, state classes, and friendly names. Promoted air- quality measurements to primary entities (not diagnostic). - enumerator.rs: route fan-type devices through Fan entity; auto-add battery and Wi-Fi diagnostics where reported. Effect filtering - light.rs / device_config: per-device `allowed_effects` overrides the global GOVEE_ALLOWED_EFFECTS env var. Useful to keep Google Home SYNC payloads under the size limit without losing scene control inside HA. Closes wez#613. - light.rs: skip empty `supported_color_modes` in MQTT light discovery so brightness-only bulbs (H6093) don't fail HA validation. Closes wez#589. Quirks (device coverage) - AirQualityMonitor device type + helpers; H5140 (CO2 monitor) and H5106 (BLE-only AQM) classified correctly instead of falling to "Other". Closes wez#634, wez#561. - LAN-capable: H616D outdoor strip, H6039 wall sconce, H61E5 strip pro. - Color-temp clamps: H6076 (2700-6500K) and H61E5 (2700-6500K) — API reports 2000-9000K which is wrong. Closes wez#591, partial wez#567. - IoT routing: H6006 bulbs now use IoT instead of rate-limited Platform API (10-15s delays before this). Closes wez#621. - BLE-only classified (controllable when BLE path lands): H6125_321A, H6125_5321, H5129 motion sensor, H5181-H5185/H5198 meat thermometers. Closes wez#569, wez#580, wez#630. Addon - addon/config.yaml + run.sh: surface govee_app_version and govee_2fa_code options; redact 2FA code from env dump. - addon/translations/en.yaml: matching strings.
|
Friendly bump — last activity was the rewrite/cleanup on Apr 27. CI is green, branch is mergeable, scope is now contained to the 2FA login path (5 files, single commit). Govee's API change is breaking new installs and any user whose token has expired (see #647, #626, #627, #637, #649). Happy to rebase, split further, or address review feedback whenever you have time. No rush — just flagging that this one has user impact. |
|
I've tested this branch with my home setup and it seems to accomplish everything that is required for 2fa to work. Does anyone know what the next step is to getting this merged up? This is a necessary thing for me as I use a lot of one click actions. |
|
@miller79 if you think this is better than #656 then sure let's go with this one. Just to add a bit more color - I've had govee gear for a while, but never tried connecting it to HomeAssistant until today. I'm not sure if existing users are able to just carry on, but as a new user I'm completely blocked unless I fork, which I might do, but I'd rather just stay on main if this can get merged soon... |
|
@LookingSharp for sure this version is the best version of it. I have forked it myself and have tested it if you want to change repos to mine to test it yourself (https://github.com/miller79/govee2mqtt). I'm also supposing @florianhorner has it working with his version as well but yes it would be must more convenient if it's just merged here. But if we are to pick a PR that fixes the 2FA, this is the one to pick. |
|
Using @miller79 build has worked for me. LGTM and TYSM |
|
Doesn’t fix the issue
…On Sat, Jun 13, 2026 at 5:08 PM Gatorz ***@***.***> wrote:
*Gatorzgaming* left a comment (wez/govee2mqtt#652)
<#652 (comment)>
Using @miller79 <https://github.com/miller79> build has worked for me.
LGTM and TYSM
—
Reply to this email directly, view it on GitHub
<#652?email_source=notifications&email_token=ACSHCOQ5MDIWQTIX7NC5IXL47XGG3A5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTINRZHE4TGNZXGIZKM4TFMFZW63VGNVQW45LBNSSWK5TFNZ2KYZTPN52GK4S7MNWGSY3L#issuecomment-4699937722>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ACSHCOVAV7W2P5HGWY37SQ347XGG3AVCNFSNUABFKJSXA33TNF2G64TZHM3TGOBWGQ4TSMBUHNEXG43VMU5TIMRQHA2TQMBZHE2KC5QC>
.
Triage notifications, keep track of coding agent tasks and review pull
requests on the go with GitHub Mobile for iOS
<https://github.com/notifications/mobile/ios/ACSHCOW3EJTB2YRMSWBDWYD47XGG3A5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTINRZHE4TGNZXGIZKM4TFMFZW63VGNVQW45LBNSSWK5TFNZ2KUZTPN52GK4S7NFXXG>
and Android
<https://github.com/notifications/mobile/android/ACSHCOTXXIVOQOLIQSJSNCT47XGG3A5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTINRZHE4TGNZXGIZKM4TFMFZW63VGNVQW45LBNSSWK5TFNZ2K4ZTPN52GK4S7MFXGI4TPNFSA>.
Download it today!
You are receiving this because you are subscribed to this thread.Message
ID: ***@***.***>
|
|
@ndrwrbgs check your logs |
|
No fix 🦊
…On Sat, Jun 13, 2026 at 8:54 PM Gatorz ***@***.***> wrote:
*Gatorzgaming* left a comment (wez/govee2mqtt#652)
<#652 (comment)>
@ndrwrbgs <https://github.com/ndrwrbgs> check your logs
—
Reply to this email directly, view it on GitHub
<#652?email_source=notifications&email_token=ACSHCOQ7L6NPISRWOP7X5ZT47YAWBA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTINZQGAZTSMBXHA3KM4TFMFZW63VHNVSW45DJN5XKKZLWMVXHJLDGN5XXIZLSL5RWY2LDNM#issuecomment-4700390786>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ACSHCOVAFM6DBZ7MTKWRZAD47YAWBAVCNFSNUABFKJSXA33TNF2G64TZHM3TGOBWGQ4TSMBUHNEXG43VMU5TIMRQHA2TQMBZHE2KC5QC>
.
Triage notifications, keep track of coding agent tasks and review pull
requests on the go with GitHub Mobile for iOS
<https://github.com/notifications/mobile/ios/ACSHCOV4KKKFZYEEI4ZLYOT47YAWBA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTINZQGAZTSMBXHA3KM4TFMFZW63VHNVSW45DJN5XKKZLWMVXHJKTGN5XXIZLSL5UW64Y>
and Android
<https://github.com/notifications/mobile/android/ACSHCOVPAX3FB6XX6BYNL7D47YAWBA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTINZQGAZTSMBXHA3KM4TFMFZW63VHNVSW45DJN5XKKZLWMVXHJLTGN5XXIZLSL5QW4ZDSN5UWI>.
Download it today!
You are receiving this because you were mentioned.Message ID:
***@***.***>
|
|
Do you have any more details on what exactly didn't work for you? Without any details of any kind it's impossible to address anything specific. |
|
@ndrwrbgs thanks for testing. A few other setups are confirmed working above, so I'd like to understand your build or environment to rule out the fix missing a case. Can you share:
With that I can tell whether this PR misses a case or it's a separate issue. |
Thanks @miller79 for linking to your fork, made it super easy to test! ❤️ I switched to it also. I uninstalled the official one (temporarily), plugged in miller79's fork repo url, installed the 2026.05.23-62516373 version (because I still had the official repo url in there), started it up and got my 2FA token via email shortly after, plugged it into the new "Govee 2FA Code" field and it started working immediately thanks to the built-in auto-retry. That's another successful test case here! |
|
Worked for me as well, though, restarting it with docker-compose was annoying to figure out the right sequence of commands. |
|
Also worked for me -- thank you! Stumbling block caveat I'll note from my experience: Govee has more than 1 type of logon MFA/2FA.
I made the mistake of manually triggering MFA during login through the browser and attempting to use that code in the MFA field -- too clever for my own good! Correct approach is to have the MFA field be empty, start the add-on, let it attempt to login and fail on the MFA step, which triggers the correct MFA email. === When govee2mqtt starts up, it initiates a brand new authentication session. It says to Govee: "Hey, I want to log in, and here is a code I found." Govee looks at it and says: "Wait, you never asked me for a login code from this session, so this code is invalid here." Because the code wasn't requested by the add-on itself during its own login flow, Govee rejects it instantly. |
|
The fork by @miller79 works for me as well. |
Upstream main has been frozen for months while Govee's 2FA/454 login change (fixed by the cherry-picked PR wez#652) sits unmerged. This repoints the GHCR image references and repository metadata (addon config, addon Dockerfile, CI image env var, docker-compose, root Dockerfile label, repository.yaml) from wez/govee2mqtt to this fork so the add-on actually builds and serves the patched binary instead of upstream's. Bumps the add-on version so Supervisor treats it as a new release. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
To be fair to Wez given all work that went into Govee2MQTT, and to keep this PR here reviewable for him (and mergeable): There is this proposal here as for how to keep this project alive. And I recommend to discuss the question about repo there https://github.com/wez/govee2mqt/issues/700, else these questions remain scattered across dozens of issues, PRs and whatnot. And the suggested fix here gets diluted as well because it is about Govee 2FA login support |
|
Good to hear it's working for you all but yes I wouldn't want to run a fork for sure. The issue I raised #700 hopefully will get some traction on allowing a small group to own it long term that can be governed. I've sent @wez a message on Mastodon so hopefully that may get his attention as I'm sure this is not a high priority for him at the moment. |
|
So I take it Wez hasn't responded to your messages yet? I guess we the community will have to take over maintaining, and we'll need some rules and stuff so it doesn't become slopified or a package bloat supply chain nightmare. I guess this is also opportunity for improving the project and we should probably prioritize the following
|
|
I have reached out to Wes on various channels and have not received any replies so it does seem like this project maybe abandoned. I'm good to fork and rename but I like waiting a full 6 months - year range just in case. It as that time is coming closer, we should discuss what that would look like in a separate issue. |

Summary
Fixes #647 by restoring undocumented Govee login when account 2FA is required.
/v1/loginto/v2/loginGOVEE_2FA_CODE/--govee-2fa-codeand the Home Assistant add-ongovee_2fa_codeoption454when no code is configured, with a 15-minute cache cooldown to avoid repeated email requests during restart loopsThe API behavior is modeled after the confirmed fix in homebridge-govee.
Scope
upstream/mainsrc/undoc_api.rs, add-on config plumbing, add-on translation text, anddocs/CONFIG.mdgovee_2fa_codeTest plan
cargo fmt --all -- --checkcargo test --allpasses (35 tests)cargo clippy --all -- -D warnings