I own a couple of Tata Power EZ Home Wifi MOSFET Smart Switch 16A 1 Channel units, mostly wired up to control water pumps at home. They do exactly what the box says: a phone app, scheduling, on/off from anywhere. What they don’t offer is any way to use them without that app. No Home Assistant integration, no HomeKit support, not even a documented “local mode” for people who just want to control a device they already own without a permanent dependency on Tata Power’s servers.
That’s the part that bothered me. I run a homelab and use Home Assistant and HomeKit for everything else in the house, so having two switches that only work through one company’s app and one company’s cloud felt backwards for hardware I’d already paid for. I emailed and called Tata Power support more than once to ask if a local API or any kind of offline control existed. I never got a reply. So I decided to find out myself.
Why “just use the app” wasn’t good enough
To be clear, the app itself works fine. The actual problem is architectural: every single command, even turning on a switch sitting three metres from your phone, goes out to Tata Power’s cloud and back before anything happens. No internet, no control. And there’s no way to plug these switches into a home automation setup like Home Assistant or Apple Home, which is the whole reason I run a homelab in the first place. For hardware I own outright, that felt like an artificial limitation, not a technical one, so I went looking for whatever was actually running on the device itself.
First attempt: a port scan that told me nothing
The obvious first move was to point a port scanner at the switch’s IP address and see what was listening. Nothing useful came back, and that led me to wrongly conclude, at first, that there was no local control surface at all. That conclusion turned out to be wrong, and the reason why was interesting on its own: the switch runs on a tiny ESP8266 chip with a very small network stack, and firing hundreds of scanning threads at it in parallel was enough to exhaust its connection handling and make it drop or reset connections it would normally accept. A slower, single-threaded scan, checking a wider range of ports, found a TCP port the first scan had completely missed.
Second attempt: watching the app talk to the switch
Rather than keep guessing at ports, I captured traffic on my own access point while using the Tata Power app normally, watching exactly what the phone sent to the switch and what it sent to the cloud. That was far more productive than scanning. It showed the switch broadcasting a small discovery beacon on the local network every second or so, and listening for commands on the TCP port the second scan had found, using a custom binary protocol with its own framing and checksum.
It also revealed that these aren’t bespoke Tata Power devices. The hardware and firmware are made by a company called Ogemray, and Tata Power just rebadges it under the EZ Home name. That’s common in this part of the smart-plug market: a lot of switches sold under different brand names in India and elsewhere are the same Ogemray hardware, so anything built from this would likely work well beyond my own two switches.
Third attempt: assuming the hard part was encryption
With the protocol framing worked out, I assumed the next problem would be authentication. Surely you need some kind of paired key or login before a random device on the network can flip someone’s relay. So I went down that road properly. I pulled apart the Android app itself to look at how it builds and signs commands, and found a native library with real symbols for packet assembly, AES encryption, and a checksum routine. There was a static factory key baked into the app, and a second, per-account key that the app appeared to fetch after logging into the Tata Power cloud, used to derive some kind of session key for live commands.
At that point it looked like proper local control, without ever touching Tata Power’s servers, wasn’t going to be possible. If the switch was validating an account-derived key on every command, the realistic plan was “log into the cloud once to fetch the key, then control locally,” which still isn’t the same as a genuinely offline device.
The anticlimax: none of it was actually being checked
Before committing to that plan, I ran a few direct tests against a live switch, and they upended everything I had just spent time reverse-engineering. I took a known-good “turn on” command, corrupted the trailing checksum bytes that were supposed to require the account key, and sent it. The relay switched on anyway. I then built a command from scratch and sent it over a brand-new connection, skipping the multi-step handshake the app always performs first. It worked too, on the first try.
So I went further and tried to actually break it. I sent a valid command with the wrong password. It worked. I sent one with a completely wrong account ID. It also worked. I even sent a command addressed with a fabricated, nonexistent device ID as a control test. That worked as well. The switch was accepting anything shaped like a valid command, regardless of what was actually inside it.
To make sure this wasn’t a quirk of the one switch I had been capturing traffic from, I tested it against my second switch, one I had never packet-captured, never logged into, and had no stored credentials for. I read its device ID straight off its own discovery beacon and sent it a command with made-up credentials. It turned on and off exactly like the first one.
The Tata Power EZ Home smart switch does not authenticate commands at all. Any device on the same local network can control it by IP address alone.
All the encryption and account-key machinery in the app is real, but the switch itself never verifies any of it. Everything I had assumed would be the hard part of this project simply wasn’t there.
What that means if you own one
For anyone else with a Tata Power EZ Home Wifi Smart Switch, this cuts both ways. On one hand, it makes genuinely zero-config local control possible: no login, no pairing, no cloud account, just discover the switch on the network and talk to it directly. That’s exactly what makes a clean Home Assistant or HomeKit integration possible without ever touching Tata Power’s servers again.
On the other hand, it means anyone who gets onto your Wi-Fi, a guest, a compromised device, or someone who breaks into your router, can control these switches with zero credentials. In my case that’s a water pump, so the worst case is mildly annoying rather than dangerous, but it’s a real gap and worth knowing about if you’re using this switch, or any other Ogemray-based device sold under a different brand, for something with higher stakes. Putting IoT devices like this on their own isolated network segment, separate from your phones and laptops, is the sensible mitigation until that changes.
Local Home Assistant and HomeKit support, finally
The result is homebridge-ogemray, a Homebridge plugin that gives the Tata Power EZ Home switch, and other Ogemray-based switches, proper local HomeKit support: true local control, zero cloud, zero login. A matching Home Assistant integration is next, using the same zero-config discovery.
If you bought a Tata Power EZ Home smart switch hoping for Home Assistant or HomeKit support, contacted Tata Power about it, and got the same silence I did, hopefully this saves you the reverse-engineering step and gets your switch talking to your own home automation setup instead of only theirs.