Skip to content

Latest commit

 

History

14 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Sonoff BMT01 — Home Assistant Integration

A custom HACS integration that connects to the Sonoff BMT01 4-probe BBQ / meat thermometer over Bluetooth Low Energy and exposes its probe temperatures to Home Assistant.

It works with Home Assistant's built-in Bluetooth stack, including ESPHome Bluetooth Proxies — so the thermometer does not need to be near your Home Assistant host. As reported by the community, with a proxy the device connects on boot (no 7-second button hold needed) and range is excellent.

Local at runtime. All runtime communication happens over local Bluetooth — nothing is sent to any eWeLink or Sonoff server while the integration runs. The only cloud contact is an optional, one-time eWeLink login at setup to fetch your account apikey (Option A); your password is never stored. You can also skip that entirely and enter the apikey manually (Option B). The apikey is only used as a local secret to derive the device's BLE encryption key (see About the apikey).

Status: v1, read-only, reverse-engineered. The BLE protocol was reverse-engineered by the Home Assistant community (thread). There is no official Sonoff documentation. This integration currently exposes 4 probe temperatures and a connection status. Battery, alarms, calibration and temperature-unit control are not implemented yet.

What you get

  • Probe 1–4 temperature sensors (°C; Home Assistant handles unit display).
  • A Battery sensor (diagnostic). Reports unknown until the battery read path is implemented in a future release.
  • Sensors become unavailable when the device disconnects, and recover automatically on reconnect.

Requirements

  • Home Assistant 2024.8 or newer.
  • A Bluetooth adapter on your HA host or at least one ESPHome Bluetooth Proxy in range of the thermometer.
  • Your eWeLink account apikey (see below).

Installation

Option 1 — HACS custom repository

  1. In HACS, open the menu → Custom repositories.
  2. Add the repository URL https://github.com/ScuttleSE/sonoff_grill with category Integration.
  3. Install Sonoff BMT01 BBQ Thermometer.
  4. Restart Home Assistant.
  5. Go to Settings → Devices & Services → Add Integration and search for Sonoff BMT01. If the device is discovered over Bluetooth it may appear automatically.

Option 2 — Manual installation

  1. Copy the custom_components/sonoff_bmt01 folder from this repository into your Home Assistant config/custom_components/ directory.
  2. Restart Home Assistant.
  3. Go to Settings → Devices & Services → Add Integration and search for Sonoff BMT01.

Prerequisite: eWeLink account + pairing (requires the app)

You must use the eWeLink mobile app for a one-time setup. There is no static web "register" page — account creation and the BMT01's initial Bluetooth pairing both happen inside the app:

  1. Install eWeLink: https://ewelink.cc/app/ (iOS / Android).
  2. Create an eWeLink account on first launch.
  3. Pair your BMT01 in the app. Pairing binds the thermometer to your account.

The app is only needed for this one-time account + pairing step. After that, this integration talks to the thermometer entirely over local Bluetooth.

Configuration

Add the integration from Settings → Devices & Services → Add Integration → Sonoff BMT01. You will be offered two ways to configure it:

Option A — Log in to eWeLink (recommended)

Choose Log in to eWeLink and enter your eWeLink email/phone, password, and country code. The integration performs a single cloud login to fetch your account apikey, stores only the apikey, and discards your password. It never contacts the cloud again — all runtime communication is local Bluetooth. After login, enter your BMT01's Bluetooth MAC address to finish.

Option B — Enter the apikey manually

If you prefer not to enter your eWeLink login (or the login path is unavailable), provide the values directly:

Field Description
Bluetooth MAC address The BLE MAC of your BMT01 (e.g. AA:BB:CC:DD:EE:FF).
eWeLink apikey Your eWeLink account apikey (see below).

Either way, the integration validates by performing a real connection and the full authentication handshake before creating the entry.

About the apikey

  • It is an account-level value: one apikey unlocks every BMT01 paired to that eWeLink account.
  • It does not expire — fetch it once and reuse it. (A device paired under a different account requires that account's apikey.)
  • It is never used to talk to the cloud at runtime. The BMT01 refuses to stream data until an AES-128-CBC challenge-response handshake completes, and the encryption key is derived locally as MD5(apikey). Sonoff simply reuses your account apikey as the device's pre-shared BLE secret; the key cannot be sniffed from the air, so it must be retrieved from your account once.
  • Treat it like a password.

Obtaining the apikey manually (for Option B)

If you are using manual entry, retrieve your account apikey with one of:

  • AlexxIT/SonoffLAN — https://github.com/AlexxIT/SonoffLAN. If you already run it, it authenticates to eWeLink and caches your account data (including the apikey) locally.
  • A small login script — POST your credentials to the eWeLink API endpoint POST https://<region>-apia.coolkit.cc/v2/user/login and read data.user.apikey from the response. (Region is one of eu, us, as, cn.)
  • Rooted Android — adb pull /data/data/com.coolkit/databases/ and read the apikey from the catalystLocalStorage table.

The eWeLink OAuth developer demo (https://github.com/nocmt/eWeLinkOAuthLoginDemo) also works but is heavyweight: it requires registering as an eWeLink developer, waiting for approval, and creating an OAuth app. Prefer the options above.

How it works

  1. Home Assistant establishes a BLE connection (directly or via a proxy).
  2. A challenge-response handshake runs: AES-128-CBC with a key of MD5(apikey) and a static zero IV. The app and device exchange encrypted UUIDs and the device grants access.
  3. The integration sends a sync command and the device begins pushing temperature frames, which are decoded (uint16 little-endian °C) and published as sensor states.

Limitations / roadmap

  • Read-only. No battery read, alarms, calibration, or °C/°F control yet — these use a rolling single-use "ticket" byte plus XOR-encrypted control frames and are planned for a later release.
  • Reverse-engineered. Decoding is based on community captures and a decompiled eWeLink bundle. Behaviour may vary across firmware revisions.
  • The Bluetooth auto-discovery name matchers are best-guess; manual entry is the reliable path.

Credits

Protocol reverse-engineering by the Home Assistant community, especially plans-coding and Greywood in the Sonoff BMT01 thread.

License

MIT — see LICENSE.

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages