The mikrotik platform offers presence detection by looking at connected devices to a MikroTik RouterOS based router.

Configuring mikrotik device tracker

You have to enable accessing the RouterOS API on your router to use this platform.


/ip service
set api disabled=no port=8728

Web Frontend:

Go to IP -> Services -> api and enable it.

Make sure that port 8728 or the port you choose is accessible from your network.

To use a MikroTik router in your installation, add the following to your configuration.yaml file:

# Example configuration.yaml entry
  - platform: mikrotik
    host: IP_ADDRESS

Configuration Variables


(string)(Required)The IP address of your MikroTik device.


(string)(Required)The username of a user on the MikroTik device.


(string)(Required)The password of the given user account on the MikroTik device.


(integer)(Optional)RouterOS API port.

Default value: 8728 (or 8729 if SSL is enabled)


(boolean)(Optional)Use SSL to connect to the API.

Default value: false


(string)(Optional)Override autodetection of device scanning method. Can be wireless to use local wireless registration, capsman for capsman wireless registration, or ip for DHCP leases.

Use a certificate

To use SSL to connect to the API (via api-ssl instead of api service) further configuration is required at RouterOS side. You have to upload or generate a certificate and configure api-ssl service to use it. Here is an example of a self-signed certificate:

/certificate add common-name="Self signed demo certificate for API" days-valid=3650 name="Self signed demo certificate for API" key-usage=digital-signature,key-encipherment,tls-server,key-cert-sign,crl-sign
/certificate sign "Self signed demo certificate for API"
/ip service set api-ssl certificate="Self signed demo certificate for API"
/ip service enable api-ssl

Then add ssl: true to mikrotik device tracker entry in your configuration.yaml file.

If everything is working fine you can disable the pure api service in RouterOS:

/ip service disable api

The user privileges in RouterOS

To use this device tracker you need restricted privileges only. To enhance the security of your MikroTik device create a “read only” user who is able to connect to API only:

/user group add name=homeassistant policy=read,api,!local,!telnet,!ssh,!ftp,!reboot,!write,!policy,!test,!winbox,!password,!web,!sniff,!sensitive,!romon,!dude,!tikapp
/user add group=homeassistant name=homeassistant
/user set password="YOUR_PASSWORD" homeassistant

Using the additional configuration to the mikrotik device tracker entry in your configuration.yaml file:

  - platform: mikrotik
    username: homeassistant
    password: YOUR_PASSWORD
    ssl: true
    port: 8729
    method: capsman

See the device tracker component page for instructions on how to configure the people to be tracked.