Back
tapo Library v0.11.1 Adds TPAP Support, Lets Tapo Devices Keep Third-Party Compatibility Off
SiTech AI Team3 min read

tapo Library v0.11.1 Adds TPAP Support, Lets Tapo Devices Keep Third-Party Compatibility Off

The unofficial Rust and Python client for TP-Link Tapo devices now speaks the TPAP protocol, so plugs, lights and cameras can be controlled locally without enabling the app's Third-Party Compatibility switch.

The unofficial tapo library for TP-Link Tapo devices has added support for the TPAP protocol in version 0.11.1. The change means scripts and home automation setups can control plugs, lights, power strips, hubs and some cameras with the Tapo app's "Third-Party Compatibility" switch left off, which is the default since firmware 1.4.0 arrived in October 2025.

TPAP support

Since firmware 1.4.0, plugs only speak the older KLAP protocol while the Third-Party Compatibility switch, found under Me > Third-Party Services in the Tapo app, is turned on. Lights followed in the first half of 2026 with firmware 1.4.1 to 1.4.3. The library previously could not speak TPAP, so it could only reach devices with the switch on, a situation that has tripped up users repeatedly. Version 0.11.1 changes that: the client detects which protocol a device speaks and logs in over it automatically, both when connecting by IP address and through discover_devices.

Three caveats apply. A wrong password can lock a TPAP device for a while, reported as TPAP_CREDENTIALS and TPAP_AUTH_ATTEMPTS_LIMIT, and neither should be retried in a loop. Camera hubs do not speak TPAP yet: an H200 on firmware 1.7.5 announces AES SSL regardless of the switch. Some cameras also lack TPAP support depending on model and firmware; a C210 on firmware 1.5.2, for example, only works with the switch on. Version 0.11.0 also removed the legacy AES protocol, which no recent firmware uses, while keeping AES SSL for cameras and hubs.

Why TPAP is the safer protocol

TPAP logs in with SPAKE2+, a password-authenticated key exchange described in RFC 9383. Unlike KLAP, which exchanges hashes built from the credentials and two random values sent in the clear, a recorded TPAP login cannot be checked against candidate passwords offline. Each session's keys depend on secrets generated for that login, so captured traffic stays private even if the password is learned later. TP-Link's FAQ says the compatibility switch "is disabled by default to ensure security" and that enabling it "may reduce the security of your devices".

Camera hubs, schedules and timers

The release series, v0.10.0 on 28 September, v0.11.0 on 2 October and v0.11.1 on 4 October, also adds support for the H200 and H500 camera hubs. Beyond pairing sensors and switches like the H100, these hubs store camera recordings, and the library can now list paired cameras, find days with recordings, list recordings in a time range and download them as playable MPEG-TS clips. Version 0.10 additionally brings plug schedules and timers to PlugHandler and PlugEnergyMonitoringHandler, contributed by a community member. Schedule rules can fire at a time of day, at an offset from sunrise or sunset, once or on selected weekdays, and they run on the plug's own clock, so they keep working when the controlling script or internet connection is down. The companion MCP server, as of v0.5.3, lists H200 and H500 hubs and works with devices that have Third-Party Compatibility switched off.

What's next

Upcoming work includes more MCP server features such as energy usage and caching of discovery results, an H110 hub handler with infrared remote control support, a handler for fixed cameras starting with the C120, a device simulator for testing without real hardware, and possibly a Node.js wrapper. Users upgrading from v0.9 should expect breaking changes, including the removal of the legacy AES protocol and new field names for trigger logs and temperature records.

Sources: mihai.dinculescu.dev

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.