Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Blog

Using AWS IoT Core as an MQTT Broker for Home Assistant

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Yes—AWS IoT Core can serve as Home Assistant’s cloud MQTT broker. The normal setup does not use Home Assistant’s general AWS integration. Instead, add the built-in MQTT integration and connect it to an account-specific AWS IoT Core endpoint using an X.509 client certificate, private key, and Amazon Root CA certificate.

This is a secure and capable architecture for multi-site systems, AWS-based data processing, and certificate-managed devices. For a single home that only needs local MQTT, however, Home Assistant’s official Mosquitto Broker app is usually simpler, cheaper, and more resilient when the internet is unavailable.

What an AWS IoT environment means for Home Assistant

AWS IoT Core is a managed MQTT broker, not a dedicated native Home Assistant integration. Home Assistant communicates with it through MQTT over TLS, normally on port 8883.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not confuse this with Home Assistant’s separate AWS integration, which is intended for AWS services such as Lambda, SNS, SQS, and EventBridge. It is not the usual way to connect Home Assistant to the AWS IoT Core MQTT broker.

#1 Best Overall
ELEGOO 3PCS ESP-32 Dev Boards, ESP-WROOM-32, USB-C, WiFi Bluetooth 4.2
  • Dual-Core Performance Up to 240 MHz: Run sensor processing, wireless communication, automation logic and connected-device tasks on a 32-bit dual-core ESP32 platform designed for responsive embedded and IoT projects
  • Built-in Wi-Fi and Bluetooth 4.2: Connect to 2.4 GHz Wi-Fi networks or use Bluetooth Classic and BLE for wireless sensors, smart devices, remote controls, home automation and other connected projects
  • Flexible Power-Saving Modes: ESP32 power-management features support dynamic clock scaling and low-power operating modes, helping developers reduce energy use in compatible sensing, monitoring and connected-device applications, suitable for battery-powered Internet of Things (IoT) devices.
  • USB-C Programming with CP2102: Connect through USB-C for power, sketch uploads and serial monitoring, while GPIO, UART, SPI and I2C interfaces support sensors, displays, motor drivers and other modules (USB-C cable not included)
  • Over-the-Air Update Support: Configure OTA functionality through a compatible ESP-32 software framework to update deployed firmware over Wi-Fi without reconnecting the board by USB for every revision

Direct connection

Home Assistant
      │ MQTT over TLS / X.509
      ▼
AWS IoT Core MQTT broker
      ├── other MQTT clients
      ├── Rules Engine
      ├── Device Shadows
      └── Lambda, DynamoDB, S3, SNS, and other services

Other architectures

  • Local broker bridged to AWS: Home Assistant uses Mosquitto locally, while a bridge exports selected topics to AWS IoT Core. This preserves local operation but adds synchronization and another failure point.
  • AWS IoT Greengrass: Home Assistant runs in a more advanced edge architecture alongside AWS-managed components. The AWS Labs Home Assistant Greengrass component documents both direct AWS IoT Core connectivity and Greengrass broker configurations. Greengrass is not required for a direct MQTT connection.

Should you use AWS IoT Core?

Choose AWS IoT Core when… Choose local Mosquitto when…
You need certificate-based identity and a broker reachable across multiple networks. Home Assistant and the devices are primarily in one home.
MQTT data must feed Lambda, S3, DynamoDB, Kinesis, SNS, or other AWS services. You want the simplest setup with minimal administration.
You operate multiple sites or a growing device fleet. Automation must continue independently of an internet connection.
You need AWS policies, monitoring, Rules Engine routing, or lifecycle tooling. You want to avoid cloud-service usage charges.

AWS IoT Core provides managed infrastructure, mutual TLS, fine-grained policies, retained messages, persistent sessions, Last Will and Testament support, and MQTT 3.1.1 and MQTT 5 support. AWS also documents service-specific differences, so MQTT 5 compatibility should not be interpreted as identical behavior for every feature.

For most ordinary homes, the official Mosquitto Broker app remains the practical default. AWS IoT Core becomes compelling when the AWS ecosystem itself is part of the design.

Prerequisites and security decisions

  • An AWS account and a selected AWS Region.
  • Home Assistant with the MQTT integration available.
  • Administrative access to Home Assistant.
  • Permission to create AWS IoT Things, certificates, and policies.
  • A secure method for transferring certificate and private-key files to Home Assistant.
  • A defined MQTT topic hierarchy and discovery strategy.
  • Billing alerts, budgets, or another method of monitoring AWS usage.

AWS usage can incur charges even when free usage provisions apply. Message traffic, Rules Engine activity, retained messages, Device Shadow operations, and downstream AWS services should all be considered before publishing continuously. Check the current AWS IoT Core pricing and additional pricing details for your Region.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Treat the private key as a credential. Do not place it in a public repository, a shared folder, or an unencrypted backup. Use a separate certificate and client identity for each independent MQTT client where practical.

Set up AWS IoT Core

1. Select a Region and create a Thing

Open AWS IoT Core in the Region where you want the deployment to live. Create a Thing representing the Home Assistant MQTT client. A Thing is an AWS identity and organizational object; it does not itself create Home Assistant entities.

2. Create and activate an X.509 certificate

Create or register a certificate, activate it, and retain the generated device certificate and matching private key. Also obtain the Amazon Root CA certificate. The AWS Labs example uses AmazonRootCA1.pem; obtain the current CA file through AWS’s official certificate documentation or download flow rather than relying on an old copy.

Attach the certificate to the Thing. An exclusive Thing association can help ensure that a certificate belongs to only one Thing, but AWS also supports non-exclusive associations. See AWS’s documentation on exclusive Thing associations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
OSOYOO ESP8266 NodeMCU IOT Starter kit with ESP-12E Development Board Open Source Serial Module
  • This kit comes with NodeMCU micro controller board which is based on ESP8266, an enconimcal and powerful chip which supports wifi and IDE .
  • This kit is developed specially for those want to learn and play IoT ( Internet of things). In order to connect Things to Internet, for this kit, we uses a very popular and simple IOT protocol - MQTT which has many free open-source coding resources and mobile APP to help beginners to get started in an easy and economical way. Once you master MQTT, you can also buit a smarter home or something else .
  • The kit includes free on-line 17 sample lessons with detailed circuit graph, step-by-step tutorial, fully-tested sample codes and video which can save lots of your time and speed up your learning progress .
  • The kit is nicely packed in plastic box. This IOT programming learning starter kit includes more than 22 kinds of different electronic components items .
  • The kit can not only help students make many fancy projects in science fair, hackathon and homeworks, but also prepare the necessary knowledge base for their future career path in an interesting way.

3. Retrieve the account-specific endpoint

Use the AWS CLI:

aws iot describe-endpoint --endpoint-type iot:Data-ATS

The result resembles:

your-account-specific-prefix-ats.iot.your-region.amazonaws.com

You can also find the endpoint in the AWS IoT Core console’s Settings page. AWS recommends the iot:Data-ATS endpoint rather than the legacy iot:Data endpoint. In Home Assistant, enter only the hostname—do not include mqtt:// or https://.

Create a least-privilege IoT policy

The certificate authenticates the client, but the IoT policy authorizes what that client may do. A direct MQTT client generally needs permission to connect, publish, subscribe, and receive.

Use the following as a template, not as a universal copy-and-paste policy. Replace the Region, account ID, client ID, and topic paths, then narrow the paths to exactly what Home Assistant requires:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "iot:Connect",
      "Resource": "arn:aws:iot:REGION:ACCOUNT_ID:client/HOME_ASSISTANT_CLIENT_ID"
    },
    {
      "Effect": "Allow",
      "Action": ["iot:Publish", "iot:Receive"],
      "Resource": [
        "arn:aws:iot:REGION:ACCOUNT_ID:topic/homeassistant/*",
        "arn:aws:iot:REGION:ACCOUNT_ID:topic/devices/*"
      ]
    },
    {
      "Effect": "Allow",
      "Action": "iot:Subscribe",
      "Resource": [
        "arn:aws:iot:REGION:ACCOUNT_ID:topicfilter/homeassistant/*",
        "arn:aws:iot:REGION:ACCOUNT_ID:topicfilter/devices/*"
      ]
    }
  ]
}

The ARN types matter:

  • client/... restricts the MQTT client allowed to connect.
  • topic/... is used for publish and receive permissions.
  • topicfilter/... is used for subscribe permissions.

Attach the policy to the certificate, then confirm that the certificate is active and associated with the Thing. Avoid an unrestricted Resource: "*" policy. If you use a broad diagnostic policy temporarily, replace it immediately after identifying the problem.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure Home Assistant

Home Assistant labels can change between releases. The following path reflects the current MQTT setup flow documented by Home Assistant; verify the labels on your installed version.

  1. Go to Settings > Devices & services.
  2. Select Add integration.
  3. Choose MQTT.
  4. Enter the AWS iot:Data-ATS hostname as the broker.
  5. Set the port to 8883.
  6. Leave username and password empty for certificate authentication.
  7. Open Advanced options.
  8. Enable the client certificate option.
  9. Upload the AWS device certificate and matching private key.
  10. Configure broker certificate validation and provide the Amazon Root CA when using custom CA validation.
  11. Select TCP transport.
  12. Set a unique client ID, such as the Home Assistant Thing name.
  13. Choose MQTT 3.1.1 or MQTT 5, then submit the integration.

For the first connection, use the straightforward combination of TCP, port 8883, certificate authentication, and normal hostname validation. Home Assistant supports automatic validation when the broker certificate chains to a trusted bundled CA and custom validation when you supply a CA certificate. Keep hostname verification enabled.

Do not treat “ignore broker certificate validation” as a fix. It only hides certificate, hostname, or endpoint errors while weakening TLS security.

Rank #3
ESP32 IoT Development Board RS485/Ethernet/Wi-Fi MQTT Protocol High Precision ADC/DAC for Industrial Automation & Smart Home (with Shell)
  • Working voltage: Wide voltage DC 12-28V
  • Working Current : Standby current 15MA, 1 relay open 50MA, 2 relays open 85MA, 3 relays open 120MA, 4 relays open 155MA

Design MQTT topics and discovery

AWS IoT topics are application-defined. AWS does not automatically turn arbitrary MQTT messages into Home Assistant entities. Devices must publish valid Home Assistant MQTT discovery payloads, or entities must be configured manually.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A workable topic hierarchy is:

homeassistant/status
homeassistant/<domain>/<device>/config
homeassistant/<domain>/<device>/state
homeassistant/<domain>/<device>/command
devices/<device_id>/telemetry
devices/<device_id>/availability

Home Assistant’s default discovery prefix is homeassistant. It also publishes a birth/status message at homeassistant/status, normally using online and offline payloads.

A minimal discovery message for a sensor might be published to:

homeassistant/sensor/garage_temperature/config

with a payload shaped like:

{
  "name": "Garage temperature",
  "unique_id": "garage_temperature",
  "state_topic": "devices/garage/telemetry",
  "value_template": "{{ value_json.temperature }}",
  "unit_of_measurement": "°C",
  "device_class": "temperature",
  "availability_topic": "devices/garage/availability"
}

The payload must match the Home Assistant release and entity type you are using. The important design requirements are a stable unique ID, correct state and command topics, and a predictable availability topic.

Retained discovery versus birth-triggered discovery

Discovery configuration must still be available after Home Assistant restarts. Retaining configuration messages is convenient, but stale retained messages can create ghost entities when devices are renamed or removed. Large collections of retained messages can also increase broker activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An alternative is to have devices or an automation listen for homeassistant/status and republish discovery configuration when Home Assistant announces that it is online. This birth-triggered approach is often cleaner for dynamic systems, provided the publisher is reliable. Scope subscriptions to the discovery prefix and required topics rather than subscribing Home Assistant to # without a clear reason.

Test the connection before adding devices

Test from Home Assistant

Use the MQTT publish and listen controls exposed by the configured integration, where available.

Rank #4
ESP32 IoT Development Board RS485/Ethernet/Wi-Fi MQTT Protocol High Precision ADC/DAC for Industrial Automation & Smart Home (Only Board)
  • Working voltage: Wide voltage DC 12-28V
  • Working Current : Standby current 15MA, 1 relay open 50MA, 2 relays open 85MA, 3 relays open 120MA, 4 relays open 155MA
Topic: homeassistant/test
Payload: hello

Subscribe to the same topic and confirm that the message is delivered. This separates basic broker connectivity from later discovery or entity configuration problems.

Test from an MQTT command-line client

The Mosquitto tools can test AWS IoT Core, but the command must include the AWS endpoint, certificate, private key, and CA file. Syntax varies by installed Mosquitto version and operating system, so inspect the local tool’s help output before using a command in production. The conceptual form is:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
mosquitto_sub 
  -h YOUR_IOT_DATA_ATS_ENDPOINT 
  -p 8883 
  --cafile AmazonRootCA1.pem 
  --cert device-certificate.pem.crt 
  --key private.pem.key 
  -t 'homeassistant/#' -v

In a second terminal, publish a test message using the same TLS options:

mosquitto_pub 
  -h YOUR_IOT_DATA_ATS_ENDPOINT 
  -p 8883 
  --cafile AmazonRootCA1.pem 
  --cert device-certificate.pem.crt 
  --key private.pem.key 
  -t 'homeassistant/test' 
  -m 'hello'

Use the AWS IoT MQTT test client to subscribe and publish as well. Confirm that the client appears connected and that messages travel in both directions. AWS IoT Core can then forward matching messages to the Rules Engine for downstream processing.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting by symptom

CERTIFICATE_VERIFY_FAILED

  1. Confirm that the broker is the exact iot:Data-ATS hostname.
  2. Re-copy or re-download the Amazon Root CA file.
  3. Check that the certificate and private key are a matching pair.
  4. Keep hostname validation enabled and inspect Home Assistant logs for the underlying TLS error.

Common causes include a missing CA, incorrect CA selection, a mistyped endpoint, invalid file formatting, or a hostname mismatch.

Not authorized

  • Check that the certificate is active.
  • Confirm that the policy is attached to the certificate.
  • Confirm the certificate-to-Thing association.
  • Compare the exact client ID with the iot:Connect client ARN.
  • Check that publish and receive use topic/ resources and subscribe uses topicfilter/ resources.
  • Compare every topic path with the policy wildcards.

The connection works but no entities appear

Broker connectivity does not create entities. Check that discovery is enabled, the discovery prefix is correct, and a valid .../config message is being published. Confirm that Home Assistant can subscribe to the discovery topic and that the payload contains a stable unique ID. If configuration is not retained, use the homeassistant/status birth message to trigger rediscovery.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Repeated reconnects or duplicate clients

Two clients using the same client ID can interfere with each other. Give every MQTT client a unique ID, avoid reusing a private key among unrelated clients, and review persistent-session behavior. Exclusive Thing associations can help enforce a one-certificate-to-one-Thing design where appropriate.

Best Value
STEM V4B IoT Development Board Compatible with Arduino Uno R4 WiFi, RA4M1 32 Bit ARM Cortex M4 with ESP32-S3 WiFi Bluetooth, USB-C, for Learning Prototyping Education
  • COMPATIBLE WITH ARDUINO UNO R4 WIFI: Works seamlessly with Arduino IDE for coding uploading and debugging as a drop in alternative for Uno R4 WiFi projects
  • 32 BIT RA4M1 WITH ESP32 S3: Combines RA4M1 ARM Cortex M4 processor with ESP32-S3 coprocessor for powerful performance and built in WiFi and Bluetooth connectivity
  • DESIGNED FOR STEM AND IOT PROJECTS: Ideal for students makers engineers and educators to learn electronics embedded systems wireless communication and IoT development
  • EASY CONNECTION WITH 3 PIN HEADERS: All GPIOs arranged in 2.54mm VCC GND Signal groups for quick and reliable connection to sensors modules and devices
  • READY TO USE WITH USB C: Includes USB Type C connection for stable power and programming with tutorials available for fast learning and project setup

Port 443 does not work

Changing the port from 8883 to 443 is not a universal workaround. Certificate-authenticated MQTT on port 443 can require ALPN, including x-amzn-mqtt-ca, depending on the configuration. MQTT over WebSocket Secure uses a different authentication path and commonly involves SigV4. Start with port 8883; use port 443 only when you understand the required AWS protocol configuration.

The AWS bill is higher than expected

Review publishing frequency and the use of retained messages, persistent sessions, Will messages, Device Shadows, Rules Engine evaluations, and downstream services such as Lambda or storage. Publish on meaningful changes where possible, avoid retaining high-frequency telemetry unnecessarily, route only required topics through rules, and configure AWS budgets or billing alerts.

Cost and operational trade-offs

AWS IoT Core is usage-based. The relevant cost is not limited to the number of Home Assistant connections. Message transport, retained messages, Rules Engine operations, Device Shadow activity, data transfer, and downstream AWS services can all affect the bill. Because rates and free-usage terms vary by Region, account, and service dimension, do not rely on a single household cost estimate without modeling your message volume.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Operationally, AWS IoT Core replaces local broker administration with cloud identity and policy administration. You avoid exposing a local broker through port forwarding, but you depend on internet access and must protect, rotate, and eventually revoke certificates and private keys.

Alternatives

Home Assistant Mosquitto Broker

Best for most single-home installations. It is local, low-latency, simple to operate, and avoids AWS IoT usage charges. Its trade-off is that AWS cloud routing, managed certificate identity, and multi-site capabilities must be built separately.

EMQX

EMQX is a broader MQTT broker and managed-cloud platform suited to users who need more broker features, clustering, or fleet-oriented capabilities than a basic Mosquitto installation. It is typically more operationally complex than Mosquitto.

HiveMQ

HiveMQ is oriented toward enterprise MQTT deployments and managed broker infrastructure. It is usually disproportionate for a normal household installation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AWS IoT Greengrass

AWS IoT Greengrass is appropriate when Home Assistant must coexist with AWS-managed edge components. It adds an edge-runtime architecture and should not be introduced merely to obtain a direct AWS IoT Core MQTT connection.

Local broker bridged to AWS IoT Core

This is the compromise for installations that require local resilience but also need selected telemetry in AWS. Home Assistant continues using a local broker, while a carefully scoped bridge exports chosen topics. The design is more complex than either a purely local broker or a direct AWS connection, but it avoids making every local automation dependent on the cloud.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.