Skip to content

HS200 (US) HW 5.0 firmware 1.1.2 fails KLAP auth ("Device response did not match our challenge") even after factory reset with confirmed-correct credentials #1754

Description

@adam8833

HS200 (US) hardware/firmware not in SUPPORTED.md fails KLAP auth ("Device response did not match our challenge") even after full factory reset with confirmed-correct credentials

Environment

  • python-kasa version: 0.10.2 (latest release, confirmed via PyPI — no newer version available)
  • Installed via: Home Assistant Core 2026.9.1 (TP-Link Smart Home integration), also reproduced with the bundled kasa CLI directly inside the HA Core container
  • Device: TP-Link Kasa HS200 (US), Hardware Version 5.0, firmware 1.1.2
  • This exact firmware is not listed in SUPPORTED.md — the closest documented HS200 entries for the same Hardware 5.0 (US) are firmware 1.0.11 and 1.0.2

What happened

Two HS200 switches (Hardware 5.0, firmware 1.1.2) both fail local authentication with:

Device response did not match our challenge on ip 10.0.20.51, check that your e-mail and password (both case-sensitive) are correct.

A third HS200 on the same account/network — identical Hardware Version 5.0, firmware 1.0.11 — authenticates and works correctly with the same python-kasa/HA setup. Since the hardware revision is confirmed identical between the working and failing devices, this isolates the regression to firmware 1.1.2 specifically, not the account, network, HA config, or hardware variant.

Troubleshooting already performed (all ruled out)

  • Verified TP-Link account email/password are correct and case-sensitive-matched (same credentials work for the 1.0.11 device and the Tapo/Kasa app)
  • Confirmed the account is the owner of the device, not a shared/guest account
  • Disabled two-factor authentication on the TP-Link account entirely, retried — same failure
  • Performed a full factory reset of the device and re-added it fresh in the Tapo app under the same account, then retried HA's Reconfigure/Add-device flow — same failure immediately after fresh pairing
  • Reproduced identically via the kasa CLI directly (bypassing Home Assistant entirely), with --debug, confirming this is a python-kasa issue and not an HA integration bug

Debug output

Ran directly against the container's python-kasa install:

docker exec homeassistant kasa --host 10.0.20.51 --username '<redacted>' --password '<redacted>' --debug
Discovering device 10.0.20.51 for 10 seconds
Raised error: Device response did not match our challenge on ip 10.0.20.51,
check that your e-mail and password (both case-sensitive) are correct.
Traceback (most recent call last):
  File "/usr/local/bin/kasa", line 10, in <module>
    sys.exit(cli())
             ~~~^^
  File "/usr/local/lib/python3.14/site-packages/kasa/cli/common.py", line 282, in __call__
    asyncio.run(self.main(*args, **kwargs))
    ~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.14/asyncio/runners.py", line 205, in run
    return runner.run(main)
           ~~~~~~~~~~^^^^^^
  File "/usr/local/lib/python3.14/asyncio/runners.py", line 128, in run
    return self._loop.run_until_complete(task)
           ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^
  File "/usr/local/lib/python3.14/asyncio/base_events.py", line 719, in run_until_complete
    return future.result()
           ~~~~~~~~~~~~~^^
  File "/usr/local/lib/python3.14/site-packages/asyncclick/core.py", line 1549, in main
    rv = await self.invoke(ctx)
         ^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.14/site-packages/kasa/cli/common.py", line 270, in invoke
    _handle_exception(self._debug, exc)
    ~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.14/site-packages/kasa/cli/common.py", line 268, in invoke
    return await super().invoke(ctx)
           ^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.14/site-packages/asyncclick/core.py", line 2072, in invoke
    await super().invoke(ctx)
  File "/usr/local/lib/python3.14/site-packages/asyncclick/core.py", line 1412, in invoke
    return await ctx.invoke(self.callback, **ctx.params)
           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.14/site-packages/asyncclick/core.py", line 965, in invoke
    rv = await rv
         ^^^^^^^^
  File "/usr/local/lib/python3.14/site-packages/kasa/cli/main.py", line 370, in cli
    await dev.update()
  File "/usr/local/lib/python3.14/site-packages/kasa/iot/iotdevice.py", line 315, in update
    response = await self.protocol.query(req)
               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.14/site-packages/kasa/protocols/iotprotocol.py", line 83, in query
    return await self._query(request, retry_count)
           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.14/site-packages/kasa/protocols/iotprotocol.py", line 99, in _query
    raise auex
  File "/usr/local/lib/python3.14/site-packages/kasa/protocols/iotprotocol.py", line 88, in _query
    return await self._execute_query(request, retry)
           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.14/site-packages/kasa/protocols/iotprotocol.py", line 148, in _execute_query
    resp = await self._transport.send(request)
           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.14/site-packages/kasa/transports/klaptransport.py", line 354, in send
    await self.perform_handshake()
  File "/usr/local/lib/python3.14/site-packages/kasa/transports/klaptransport.py", line 322, in perform_handshake
    local_seed, remote_seed, auth_hash = await self.perform_handshake1()
                                         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.14/site-packages/kasa/transports/klaptransport.py", line 273, in perform_handshake1
    raise AuthenticationError(msg)
kasa.exceptions.AuthenticationError: Device response did not match our challenge on ip 10.0.20.51, check that your e-mail and password (both case-sensitive) are correct.

kasa discover --host 10.0.20.51 (no credentials) reproduces the identical failure/traceback rather than returning unauthenticated discovery metadata.

Notably, the failure path goes through kasa/iot/iotdevice.py → kasa/protocols/iotprotocol.py → kasa/transports/klaptransport.py, i.e. the legacy IOT-family KLAP transport. Other reports of this exact error message on HS200 (e.g. #1155) show the device self-reporting as SMART.KASASWITCH under discovery — it's unclear whether 1.1.2 is being routed through the correct protocol/transport for its actual firmware generation, or whether the KLAP challenge computation itself is incompatible with whatever this firmware revision changed.

Expected behavior

The device should authenticate successfully with correct, verified-owner credentials, consistent with a sibling HS200 (firmware 1.0.11) on the same account/network.

Additional notes

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions