HS200 (US) hardware/firmware not in SUPPORTED.md fails KLAP auth ("Device response did not match our challenge") even after full factory reset with confirmed-correct credentials
Environment
- python-kasa version: 0.10.2 (latest release, confirmed via PyPI — no newer version available)
- Installed via: Home Assistant Core 2026.9.1 (
TP-Link Smart Home integration), also reproduced with the bundled kasa CLI directly inside the HA Core container
- Device: TP-Link Kasa HS200 (US), Hardware Version 5.0, firmware 1.1.2
- This exact firmware is not listed in
SUPPORTED.md — the closest documented HS200 entries for the same Hardware 5.0 (US) are firmware 1.0.11 and 1.0.2
What happened
Two HS200 switches (Hardware 5.0, firmware 1.1.2) both fail local authentication with:
Device response did not match our challenge on ip 10.0.20.51, check that your e-mail and password (both case-sensitive) are correct.
A third HS200 on the same account/network — identical Hardware Version 5.0, firmware 1.0.11 — authenticates and works correctly with the same python-kasa/HA setup. Since the hardware revision is confirmed identical between the working and failing devices, this isolates the regression to firmware 1.1.2 specifically, not the account, network, HA config, or hardware variant.
Troubleshooting already performed (all ruled out)
- Verified TP-Link account email/password are correct and case-sensitive-matched (same credentials work for the 1.0.11 device and the Tapo/Kasa app)
- Confirmed the account is the owner of the device, not a shared/guest account
- Disabled two-factor authentication on the TP-Link account entirely, retried — same failure
- Performed a full factory reset of the device and re-added it fresh in the Tapo app under the same account, then retried HA's Reconfigure/Add-device flow — same failure immediately after fresh pairing
- Reproduced identically via the
kasa CLI directly (bypassing Home Assistant entirely), with --debug, confirming this is a python-kasa issue and not an HA integration bug
Debug output
Ran directly against the container's python-kasa install:
docker exec homeassistant kasa --host 10.0.20.51 --username '<redacted>' --password '<redacted>' --debug
Discovering device 10.0.20.51 for 10 seconds
Raised error: Device response did not match our challenge on ip 10.0.20.51,
check that your e-mail and password (both case-sensitive) are correct.
Traceback (most recent call last):
File "/usr/local/bin/kasa", line 10, in <module>
sys.exit(cli())
~~~^^
File "/usr/local/lib/python3.14/site-packages/kasa/cli/common.py", line 282, in __call__
asyncio.run(self.main(*args, **kwargs))
~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/local/lib/python3.14/asyncio/runners.py", line 205, in run
return runner.run(main)
~~~~~~~~~~^^^^^^
File "/usr/local/lib/python3.14/asyncio/runners.py", line 128, in run
return self._loop.run_until_complete(task)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^
File "/usr/local/lib/python3.14/asyncio/base_events.py", line 719, in run_until_complete
return future.result()
~~~~~~~~~~~~~^^
File "/usr/local/lib/python3.14/site-packages/asyncclick/core.py", line 1549, in main
rv = await self.invoke(ctx)
^^^^^^^^^^^^^^^^^^^^^^
File "/usr/local/lib/python3.14/site-packages/kasa/cli/common.py", line 270, in invoke
_handle_exception(self._debug, exc)
~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^
File "/usr/local/lib/python3.14/site-packages/kasa/cli/common.py", line 268, in invoke
return await super().invoke(ctx)
^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/local/lib/python3.14/site-packages/asyncclick/core.py", line 2072, in invoke
await super().invoke(ctx)
File "/usr/local/lib/python3.14/site-packages/asyncclick/core.py", line 1412, in invoke
return await ctx.invoke(self.callback, **ctx.params)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/local/lib/python3.14/site-packages/asyncclick/core.py", line 965, in invoke
rv = await rv
^^^^^^^^
File "/usr/local/lib/python3.14/site-packages/kasa/cli/main.py", line 370, in cli
await dev.update()
File "/usr/local/lib/python3.14/site-packages/kasa/iot/iotdevice.py", line 315, in update
response = await self.protocol.query(req)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/local/lib/python3.14/site-packages/kasa/protocols/iotprotocol.py", line 83, in query
return await self._query(request, retry_count)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/local/lib/python3.14/site-packages/kasa/protocols/iotprotocol.py", line 99, in _query
raise auex
File "/usr/local/lib/python3.14/site-packages/kasa/protocols/iotprotocol.py", line 88, in _query
return await self._execute_query(request, retry)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/local/lib/python3.14/site-packages/kasa/protocols/iotprotocol.py", line 148, in _execute_query
resp = await self._transport.send(request)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/local/lib/python3.14/site-packages/kasa/transports/klaptransport.py", line 354, in send
await self.perform_handshake()
File "/usr/local/lib/python3.14/site-packages/kasa/transports/klaptransport.py", line 322, in perform_handshake
local_seed, remote_seed, auth_hash = await self.perform_handshake1()
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/local/lib/python3.14/site-packages/kasa/transports/klaptransport.py", line 273, in perform_handshake1
raise AuthenticationError(msg)
kasa.exceptions.AuthenticationError: Device response did not match our challenge on ip 10.0.20.51, check that your e-mail and password (both case-sensitive) are correct.
kasa discover --host 10.0.20.51 (no credentials) reproduces the identical failure/traceback rather than returning unauthenticated discovery metadata.
Notably, the failure path goes through kasa/iot/iotdevice.py → kasa/protocols/iotprotocol.py → kasa/transports/klaptransport.py, i.e. the legacy IOT-family KLAP transport. Other reports of this exact error message on HS200 (e.g. #1155) show the device self-reporting as SMART.KASASWITCH under discovery — it's unclear whether 1.1.2 is being routed through the correct protocol/transport for its actual firmware generation, or whether the KLAP challenge computation itself is incompatible with whatever this firmware revision changed.
Expected behavior
The device should authenticate successfully with correct, verified-owner credentials, consistent with a sibling HS200 (firmware 1.0.11) on the same account/network.
Additional notes
HS200 (US) hardware/firmware not in
SUPPORTED.mdfails KLAP auth ("Device response did not match our challenge") even after full factory reset with confirmed-correct credentialsEnvironment
TP-Link Smart Homeintegration), also reproduced with the bundledkasaCLI directly inside the HA Core containerSUPPORTED.md— the closest documented HS200 entries for the same Hardware 5.0 (US) are firmware 1.0.11 and 1.0.2What happened
Two HS200 switches (Hardware 5.0, firmware 1.1.2) both fail local authentication with:
A third HS200 on the same account/network — identical Hardware Version 5.0, firmware 1.0.11 — authenticates and works correctly with the same python-kasa/HA setup. Since the hardware revision is confirmed identical between the working and failing devices, this isolates the regression to firmware 1.1.2 specifically, not the account, network, HA config, or hardware variant.
Troubleshooting already performed (all ruled out)
kasaCLI directly (bypassing Home Assistant entirely), with--debug, confirming this is a python-kasa issue and not an HA integration bugDebug output
Ran directly against the container's python-kasa install:
kasa discover --host 10.0.20.51(no credentials) reproduces the identical failure/traceback rather than returning unauthenticated discovery metadata.Notably, the failure path goes through
kasa/iot/iotdevice.py→kasa/protocols/iotprotocol.py→kasa/transports/klaptransport.py, i.e. the legacy IOT-family KLAP transport. Other reports of this exact error message on HS200 (e.g. #1155) show the device self-reporting asSMART.KASASWITCHunder discovery — it's unclear whether 1.1.2 is being routed through the correct protocol/transport for its actual firmware generation, or whether the KLAP challenge computation itself is incompatible with whatever this firmware revision changed.Expected behavior
The device should authenticate successfully with correct, verified-owner credentials, consistent with a sibling HS200 (firmware 1.0.11) on the same account/network.
Additional notes
mitmproxy/pcap fixture per the fixture contribution docs if that would help add support for this firmware revision — let me know what's needed.