← 返回
开发者工具 Key 中文

Starling Home Hub (Nest/Google Home)

Controls Nest and Google Home smart home devices via the Starling Home Hub's local REST API. Supports thermostats, cameras, Nest Protects, Nest × Yale locks, temperature sensors, home/away control, and Nest weather service. Use this skill when managing Nest/Google Home devices through Starling Home Hub — reading device status, setting temperatures, getting camera snapshots, locking/unlocking doors, checking smoke/CO alerts, and toggling home/away mode.
通过 Starling Home Hub 的本地 REST API 控制 Nest 和 Google Home 智能家居设备。支持恒温器、摄像头、Nest Protect、Nest × Yale 门锁、温度传感器、在家/外出控制及天气服务。用于管理设备状态、设置温度、获取摄像头快照、开关门锁、检查烟雾/一氧化碳警报及切换在家/外出模式。
michaeljmoody
开发者工具 clawhub v1.0.2 1 版本 100000 Key: 需要
★ 2
Stars
📥 1,362
下载
💾 9
安装
1
版本
#camera#google-home#home-automation#iot#latest#lock#nest#smart-home#thermostat

概述

Starling Home Hub (Nest/Google Home)

> Community skill — not affiliated with or endorsed by Starling LLC, Google, Nest, or Apple. Nest is a trademark of Google LLC. Starling Home Hub is a product of Starling LLC. This skill requires a Starling Home Hub with firmware 8.0+ and the Developer Connect API enabled.

Overview

Control Nest smart home devices through the Starling Home Hub Developer Connect (SDC) local REST API using the starling.sh script.

Required Environment Variables

VariableRequiredSecretDescription
-----------------------------------------
STARLING_HUB_IPYesNoLocal IP address of your Starling Home Hub (e.g. 192.168.1.151)
STARLING_API_KEYYesYesAPI key created in the Starling Home Hub app (Developer Connect section)

Setup

Set these environment variables (never hardcode keys in scripts):

export STARLING_HUB_IP="192.168.1.xxx"
export STARLING_API_KEY="your-api-key"     # From Starling Home Hub app

The script is at: scripts/starling.sh

Options: --http (downgrade to HTTP — not recommended), --raw (skip jq formatting)

HTTPS is the default. The script uses port 3443 unless --http is specified.

Security

API Key Management

  • Always use the STARLING_API_KEY env var — never pass keys via --key (visible in ps output)
  • Never store keys in scripts, SKILL.md, or version-controlled files
  • Use a .env file with restricted permissions: chmod 600 .env
  • Consider a secrets manager for production/automated setups

Least Privilege

  • Create API keys with minimum required permissions in the Starling Home Hub app
  • Use read-only keys unless you need to set properties or access camera streams
  • Create separate keys for different automation tasks if possible

TLS Certificate Verification

  • HTTPS is the default, but the script uses curl -k (skip cert verification) because Starling Home Hub uses a self-signed certificate
  • This is acceptable on a trusted local network but increases MITM risk on untrusted networks
  • To pin the hub's certificate instead: starling.sh --cacert /path/to/hub-cert.pem status
  • When --cacert is provided, -k is not used and full certificate verification applies

API Key in URL

  • The Starling Developer Connect API requires the key as a URL query parameter (?key=...) — this is the API's design, not a skill choice
  • URL query parameters can appear in access logs and browser history — this is mitigated by the API being local-only (no intermediary proxies/CDNs)
  • Always use HTTPS to encrypt the key in transit on your local network

Network Security

  • The Starling API is local network only by design — no cloud exposure
  • Never port-forward 3080 or 3443 to the internet
  • Always use HTTPS (default) to prevent local network sniffing of API keys and device data

Snapshot Handling

  • Camera snapshots contain sensitive imagery — don't store in world-readable locations
  • The script sets snapshot files to chmod 600 (owner-only) automatically
  • Clean up temporary snapshot files when no longer needed

Best Practices

Always Check Status First

Before making device calls, verify the hub is ready:

scripts/starling.sh status

Confirm apiReady: true and connectedToNest: true before proceeding.

Respect Rate Limits

These limits are enforced by the Nest cloud:

  • POST (set properties): max once per second per device
  • Snapshot: max once per 10 seconds per camera
  • GET (read properties/device list): no cloud rate limit (local cache)

Idempotent Operations

Safe to retry without side effects:

  • All GET operations (status, devices, device, get, snapshot)
  • SET operations with the same values (setting temp to 22 when already 22)
  • stream-extend (just resets the keepalive timer)

Not idempotent: stream-start (creates a new stream each time)

Error Handling

The script provides actionable error messages:

  • 401: Check API key and permissions — key is never exposed in error output
  • 404: Verify device ID and property name
  • 400: Check parameter values and types

Common Workflows

List All Devices

scripts/starling.sh devices

Read Device Properties

scripts/starling.sh device <id>          # All properties
scripts/starling.sh get <id> <property>  # Single property

Set Device Properties

scripts/starling.sh set <id> key=value [key=value...]

Camera Snapshots

scripts/starling.sh snapshot <id> --output photo.jpg --width 1280

Camera Streaming (WebRTC)

scripts/starling.sh stream-start <id> <base64-sdp-offer>
scripts/starling.sh stream-extend <id> <stream-id>   # Every 60s
scripts/starling.sh stream-stop <id> <stream-id>

Common Tasks

Set thermostat to 22°C:

scripts/starling.sh set <thermostat-id> targetTemperature=22

Set HVAC mode:

scripts/starling.sh set <thermostat-id> hvacMode=heat

Check for motion on camera:

scripts/starling.sh get <camera-id> motionDetected

Lock/unlock a door:

scripts/starling.sh set <lock-id> targetState=locked

Get camera snapshot:

scripts/starling.sh snapshot <camera-id> --output front-door.jpg

Check smoke/CO status:

scripts/starling.sh get <protect-id> smokeDetected
scripts/starling.sh get <protect-id> coDetected

Set home/away:

scripts/starling.sh set <home-away-id> homeState=away

API Reference

See references/api-reference.md for full device property details, writable properties, error codes, and endpoint documentation.

版本历史

共 1 个版本

  • v1.0.2 当前
    2026-03-29 03:25 安全 安全

安全检测

腾讯云安全 (Keen)

安全,无风险
查看报告

腾讯云安全 (Sanbu)

安全,无风险
查看报告

🔗 相关推荐

developer-tools

Github

steipete
使用 `gh` CLI 与 GitHub 交互,通过 `gh issue`、`gh pr`、`gh run` 和 `gh api` 管理议题、PR、CI 运行及高级查询。
★ 672 📥 324,513
developer-tools

CodeConductor.ai

larsonreever
AI驱动平台,提供快速全栈开发、智能体、工作流自动化及低代码AI集成的可扩展产品创建。
★ 68 📥 180,461
developer-tools

Gog

steipete
Google Workspace 命令行工具,支持 Gmail、日历、云端硬盘、通讯录、表格和文档。
★ 921 📥 185,924