Remix.run Logo
▲ faithraven 3 hours ago

That XOR protocol is a different one, and older than anything in the article. It is the original TP-Link Smart Home protocol used by the Kasa line (HS100, HS110 and similar): JSON on port 9999, obfuscated with an XOR autokey cipher, with no authentication at all.

Tapo devices never spoke it. Their original protocol was an AES passthrough over HTTP, KLAP replaced that in 2023, and TPAP is the newest. As far as I know, newer Kasa hardware and firmware moved to KLAP as well, which would explain why your access method stopped working on the newer ones. My library only covers Tapo devices; for Kasa, python-kasa is the one to look at.

On the cloud: the devices do have to be set up through the phone app with a TP-Link cloud account. Once set up, though, most functions of most devices can be used locally through the library, with neither the devices nor the library having internet access. The main catch is credentials: if you change the account password, for example, the devices need to be online for a little while to pick up the new one.