If you’ve built even a modest Apple Home setup — a smart lock here, a couple of HomeKit bulbs there, a HomePod mini sitting on the kitchen counter. If you’re still deciding which voice ecosystem makes sense for an Apple-led household, our HomeKit vs Alexa vs Google voice assistant comparison walks through the tradeoffs — you’ve probably also wondered, at least once, whether any of it is actually safe to leave connected to the internet. You’ve heard the headlines about hacked baby monitors and botnets built from home routers. You’ve wondered if you should care.
The honest answer: yes, you should care. But you don’t need to become a network engineer to fix it. Apple built a feature specifically for people like you, called HomeKit Secure Router (now technically called “HomeKit Accessory Security” in the latest iOS, but every router manufacturer still uses the older name). It’s a per-accessory firewall you control from the Apple Home app on your iPhone — no command line, no port forwarding, no subnet math. You tap an accessory, pick one of three privacy levels, and the compatible router does the rest.
It’s not magic, and it’s not for everyone. The feature requires specific hardware, a home hub you might not own yet, and a small amount of setup time. But for the people who can use it, HomeKit Secure Router is one of the most underrated privacy features Apple has shipped. This guide walks through exactly what you need, what’s actually compatible in 2026, how to set it up without losing your mind, and — crucially — when it’s not enough on its own.
What HomeKit Secure Router Actually Does (in Plain English)
Forget the name for a second. “HomeKit Secure Router” sounds like a special kind of hardware. It isn’t. It’s a feature — a set of instructions a compatible router follows when you add it to Apple Home.
Once enabled, the router treats every Wi-Fi and Ethernet accessory in your home as if it were a separate little island. Each one gets a unique WPA2 passkey — Apple calls it a Private PSK — that the router generates automatically and revokes the moment you remove the accessory from your home. According to Apple’s official platform security documentation, this is the design that lets the router “securely identify an accessory even if it changes its MAC address.” That’s important because MAC address spoofing is one of the oldest tricks in the smart-home attack playbook.
More importantly, the router applies firewall rules to each accessory based on a privacy level you pick from the Home app. The default setting is Automatic, which means the accessory can talk to a curated list of internet services and local devices that its manufacturer submitted to Apple. If your smart bulb vendor needs to ping a time server and download firmware, that’s allowed. If someone tries to make your bulb reach out to a server in another country, the router blocks it.
The other two settings are stronger and weaker versions of the same idea. Restrict to Home cuts the accessory off from the internet entirely — it can only talk to your Apple home hub. No Restriction opens everything back up. You pick per accessory, not per router.
What You Need: The Three Things That Must Be in Place First
Before you buy anything, here’s the honest list of prerequisites. Apple’s official support page is unusually specific about this — it’s three things, all required:
- An iPhone, iPad, or Mac running the latest Apple software, signed into the same Apple Account you use for iCloud. This is the device you’ll use to control the firewall settings. iPad-only households work too, but you need at least one device with the Home app.
- A HomeKit home hub running the latest software. The acceptable hubs are Apple TV 4K (any generation), Apple TV HD, HomePod (original), HomePod mini, or HomePod 2nd generation. An old iPad set up as a hub also works, though Apple has been quietly deprecating that path. If you want help picking one that also future-proofs your network for Matter and Thread, our 2026 hub roundup with Thread support is a good starting point.
- A HomeKit-compatible router. Currently, that means select models from eero and Linksys. We cover exactly which models in the next section.
If you’re missing the home hub, no amount of router work will help — the hub is what actually mediates between your accessories and the firewall. If you’re missing the compatible router, the feature simply doesn’t apply to you. You can still use HomeKit normally; you’ll just be relying on whatever security your regular router provides. If you’re also weighing whether to invest in Matter or Thread accessories before any of this, the plain-English Matter and Thread explainer is worth the ten-minute read.
One more thing that trips people up: your home hub and your iPhone both have to be on the same network as the compatible router for setup to work. If you have a weird dual-router setup, an ISP-supplied gateway acting as a router, or your hub is connected via Ethernet to a different subnet, fix that first.
Which Routers Actually Support It in 2026
This is where things get honest and a little disappointing. After years on the market, HomeKit Secure Router is still supported by exactly two vendors: eero and Linksys. And within those two brands, only specific models work.
According to eero’s official support page, the supported models are:
- eero (Gen 1)
- eero Pro
- eero (the second generation, sometimes labeled “eero 2019”)
- eero 6
- eero Pro 6
The notable exclusions matter. The eero Pro 6E, eero 7, and any newer 2024-2025 flagship eero models do not support HomeKit Secure Router. Multiple users have confirmed this on the MacRumors forum and the official eero community. If you’re buying fresh, double-check the model number before you order.
For Linksys, the supported Velop models are the AC2200, AC4400, and the WiFi 6 AX4200. If you already own a Velop mesh system, you almost certainly have one of these. If you’re buying new, the iMore roundup of best HomeKit routers in 2026 is a good starting point, though the underlying list hasn’t changed much in three years.
Other vendors — Asus, Netgear, TP-Link, Synology, Ubiquiti — have not implemented the feature. Netgear in particular offers its own network-security subscription called NETGEAR Armor (powered by Bitdefender), which is a different and parallel approach to the same problem. If you already own a non-supported router, NETGEAR Armor is worth a look, though it requires a subscription and works at the network level rather than the per-accessory level.
The good news: the feature is free once you have the hardware. No subscription, no per-device fee, no Apple ID upgrade.
How to Set It Up Without Losing Your Mind
The setup is two apps, in order. Apple has documented this well in their “Use routers secured with HomeKit” guide, and the actual flow takes about ten minutes if nothing goes wrong.
Step 1 — Set up the router first in the vendor app. If you have an eero, open the eero app and finish the normal Wi-Fi setup. If you have a Linksys Velop, use the Linksys app. The router needs to be functioning as a normal router before Apple Home can talk to it.
Step 2 — Look for the prompt. Both the eero and Linksys apps will eventually offer to add the router to your Apple Home. Tap Accept. If the prompt never appears, your router firmware might be out of date — update it through the vendor app and try again.
Step 3 — Finish in the Apple Home app. Once the router is added, the Home app will show it under Home Settings → Wi-Fi Network & Routers. You’ll see a master toggle for Accessory Security, plus a list of every Wi-Fi and Ethernet accessory in your home. Every accessory defaults to Automatic.
There’s one optional step Apple recommends if you have accessories that were already on the network before you set this up: remove each Wi-Fi accessory from the Home app and re-add it. That triggers HomeKit to generate a unique PPSK passkey for it. If you skip this, older accessories continue to work using their original Wi-Fi credentials — they still get the firewall rules, but they don’t get the per-device passkey. LinkDhome’s technical writeup goes deep on this part if you want the details.
One eero-specific gotcha: the network has to be in Automatic DHCP mode, not Bridge mode. eero’s official documentation flags this. If you’ve put your eero into bridge mode to use a separate firewall, the HomeKit features won’t work.
The Three Privacy Levels: When to Use Each One
This is the part that actually matters day-to-day. Every Wi-Fi or Ethernet accessory in your home gets one of three privacy levels, and you pick per device. Here’s how to think about them:
Automatic (the right default for most people)
This is where every accessory lands out of the box, and where I’d leave 90% of them. The accessory can talk to HomeKit normally, and it can also talk to a curated list of internet services and local devices that its manufacturer submitted to Apple. Your Hue Bridge can sync its time server. Your Ecobee thermostat can download firmware. Your Aqara hub can phone home for sensor updates.
What Automatic doesn’t do is let the accessory talk to anything else. So if a security researcher publishes a CVE in your smart bulb’s firmware and a botnet tries to recruit it, the bulb can’t phone the botnet’s command server — that server isn’t on the approved list. Trusted Reviews calls this “the right level for most people,” and I agree. You get meaningful protection without breaking normal functionality.
Restrict to Home (lock it down hard)
This setting tells the router: cut this accessory off from the internet entirely. It can still talk to your home hub, which means HomeKit automations still work, you can still turn the light on from your iPhone on cellular, and Siri still finds it. But it cannot reach any cloud service, ever.
The tradeoff: firmware updates won’t install automatically. If you have an indoor security camera you want to keep entirely local — no cloud storage, no remote viewing outside the home — Restrict to Home is the right setting. For most other accessories, it’ll cause more headaches than it solves.
No Restriction (almost never the right choice)
This setting explicitly bypasses the HomeKit firewall. The accessory gets the same network access it had before you set this up — full internet, full local network, no curated allowlist. Apple documents this as “least secure.”
There are a small number of legitimate reasons to use this. If an accessory manufacturer never submitted an internet-service list to Apple, Automatic behaves like No Restriction until that list exists. If you have a legacy accessory that genuinely needs wide-open access to function, you can put it here. But for the average homeowner, this is the setting you never touch.
Why This Actually Matters: What Smart-Home Attacks Look Like in 2026
If you’ve read this far and you’re still thinking “this is overkill for my three smart bulbs,” I’d push back gently. The threat landscape in 2026 isn’t theoretical anymore — it’s measurable, and it’s accelerating.
The most cited dataset right now is the Bitdefender/NETGEAR 2025 IoT Security Landscape Report, based on telemetry from 6.1 million homes, 58 million devices, and 13.6 billion intercepted attacks between January and October 2025. The headline finding: the average household now faces 29 IoT attack attempts every single day, almost triple the 10-per-day rate from 2024. The average home now has 22 connected devices, and over half of all smart-home vulnerabilities come from just three device categories — streaming devices, smart TVs, and routers.
These aren’t exotic nation-state attacks. The vast majority are automated scans looking for devices with default passwords, outdated firmware, or open telnet ports. Stingrai’s IoT attack statistics roundup cites SonicWall’s 2025 Cyber Threat Report showing a 124% year-over-year jump in IoT attacks during 2024, with over 17 million attacks targeting IoT cameras alone. Cloudflare mitigated a 5.6 Tbps Mirai-variant DDoS in October 2024 sourced from 13,000 compromised devices, and a 29.7 Tbps attack from the Aisuru botnet in Q3 2025 that conscripted somewhere between 300,000 and 700,000 routers, DVRs, and IP cameras.
What does this have to do with your smart bulbs? The botnets are built from devices like yours. Mirai in 2016 was famously built from cameras and DVRs running factory-default credentials. Aisuru in 2025 was built from routers — the kind of routers sitting in millions of living rooms right now. A firewall that prevents your smart bulb from talking to a server it has no business talking to is exactly the kind of small protection. For a deeper look at what your existing accessories already share by default, the smart-home privacy guide covers what to audit first that, multiplied across millions of homes, makes the botnet operator’s job materially harder.
HomeKit Secure Router won’t stop the attacks from coming. It will stop your devices from being conscripted into them.
Honest Limitations: When HomeKit Secure Router Is Not Enough
I’d be doing you a disservice if I didn’t flag what this feature doesn’t do.
It only covers Wi-Fi and Ethernet accessories. Thread and Bluetooth accessories in Apple Home don’t show up in the firewall list — they communicate with your home hub directly using those protocols. So if you’ve gone all-in on Thread-based sensors, HomeKit Secure Router is mostly protecting your older Wi-Fi gear. Matter-over-Wi-Fi accessories are firewalled; Matter-over-Thread accessories follow the Thread model and generally can’t be firewalled individually.
Restrict to Home can break firmware updates. If you lock an accessory out of the internet, it cannot download firmware updates. You’ll need to flip it to Automatic temporarily, run the update, then flip it back. This is a real but manageable annoyance — just set a phone reminder to check for firmware every few months.
The router list is shrinking. Eero hasn’t added HomeKit support to any new flagship since the eero Pro 6. Linksys Velop support has expanded via firmware updates, but it’s unclear whether the next Velop generation will include the feature. The lack of new vendors signing on means the future of HomeKit Secure Router is genuinely uncertain. If you’re buying fresh today, the supported-routers list might look very different in two years.
You still need router-level security. HomeKit Secure Router firewalls your accessories. It does not protect your laptops, phones, or tablets from phishing, malicious downloads, or compromised websites. For those, you still want a modern router with automatic firmware updates, WPA3 encryption, and ideally a vendor security subscription like NETGEAR Armor or eero Plus.
It requires trusting Apple with your topology. Adding a router to Apple Home means Apple now knows how many smart-home devices you own, where they are, and how they’re configured. That’s not necessarily a deal-breaker, but it’s a real consideration if you’ve structured your whole privacy approach around minimizing what Apple sees.
FAQ: Quick Answers to the Questions Smart-Home Owners Actually Ask
Do I have to pay for HomeKit Secure Router?
No. The HomeKit Secure Router feature itself is free — there is no Apple subscription, no eero subscription, and no Linksys subscription required to use it. You do need to own a compatible router and a HomeKit home hub, both of which are one-time hardware purchases. Some router vendors offer optional paid security subscriptions (for example NETGEAR Armor, or eero Plus), but those are separate add-ons for vendor-level threat detection and are not required for the HomeKit firewall to work.
Can I use HomeKit accessories without a HomeKit Secure Router?
Yes. HomeKit Secure Router is an optional security layer — Apple Home works on any Wi-Fi network. Apple Home and HomeKit accessories can still be added to the Home app, controlled from your iPhone, and automated through a home hub (Apple TV, HomePod, or HomePod mini) even if your router has zero HomeKit integration. The feature simply gives you the option to firewall individual accessories, and skipping it leaves them on whatever security your regular router provides.
What’s the difference between HomeKit and HomeKit Secure Router?
HomeKit is Apple’s smart-home ecosystem — the protocol and Apple Home app that let you control compatible accessories from your iPhone, iPad, Mac, Apple Watch, HomePod, and Apple TV. HomeKit Secure Router is a specific security feature built on top of that ecosystem that requires a compatible router. When you add a supported router to Apple Home, it unlocks per-accessory firewall controls. You can use HomeKit without the Secure Router feature, but you cannot use HomeKit Secure Router without first owning HomeKit-compatible hardware and having a HomeKit home hub on the network.
Will my Thread or Matter devices be protected by HomeKit Secure Router?
Thread and Bluetooth accessories in Apple Home do not appear in the Wi-Fi Network & Routers panel and are not affected by the per-accessory firewall rules. They communicate with your home hub directly using those protocols, and your home hub handles their network access. The restriction lists only cover accessories connected via Wi-Fi or Ethernet. Matter-over-Wi-Fi devices are treated like any other Wi-Fi accessory and can be firewalled; Matter-over-Thread devices follow the Thread model and generally cannot be firewalled individually.
What happens if I turn HomeKit Secure Router off later?
Disabling the feature removes the firewall rules and the unique PPSK passkeys that HomeKit generated for each accessory. Your accessories continue to work using whatever credentials your router assigns them — usually the main Wi-Fi password. They lose the per-accessory network isolation and the curated manufacturer-approved service lists, so any compromised accessory once again has free access to talk to anything on your home network and the open internet. You can re-enable the feature at any time, but you’ll be prompted to remove and re-add Wi-Fi accessories to regenerate the unique passkeys.
Your 5-Step Checklist to Decide Whether to Enable It Today
If you’ve read this far and you want to take action, here’s a five-minute decision framework. If you’re still in the “build a smart home from scratch” stage rather than the “lock down an existing one” stage, the first-week setup timeline is the natural companion piece Do these in order:
- Check your router model. Look at the bottom of your router for the model number, then compare it against the supported eero and Linksys Velop lists in the section above. If you have an unsupported router — including newer eero 7 or Pro 6E — HomeKit Secure Router isn’t an option for you, and the rest of the checklist doesn’t apply. Consider whether the threat landscape is reason enough to swap routers.
- Confirm you have a home hub running the latest software. Apple TV, HomePod, HomePod mini — whatever you have, update it. If you don’t have one, the feature won’t work, and that’s the prerequisite to fix first.
- Update the router firmware. Open the eero app or Linksys app, find the firmware update section, install any pending updates. The setup prompt to add the router to Apple Home sometimes doesn’t appear on older firmware versions.
- Add the router to Apple Home. Open the vendor app, accept the prompt, finish in the Home app. Verify the router appears under Home Settings → Wi-Fi Network & Routers. The master Accessory Security toggle should be on.
- Leave every accessory on Automatic. Don’t go accessory-by-accessory locking things down — Automatic is the right setting for nearly everything. The single exception: if you have an indoor security camera you genuinely want to keep local, set that one to Restrict to Home.
That’s it. Five minutes, and your smart home has a real per-accessory firewall that didn’t exist five years ago. For a room-by-room walk-through of the rest of the smart-home security stack, the renter-friendly smart-home security checklist pairs well with this guide. The threat landscape isn’t getting calmer, but this is one of those rare features that gives you meaningful protection without making you learn what a subnet is.
If you want to keep going after this, the next practical step is doing a quick firmware audit on every accessory that ended up on Restrict to Home. Set a calendar reminder to check for updates quarterly, flip the affected devices to Automatic just long enough to update, and then lock them back down. That’s the only ongoing maintenance, and it’s roughly five minutes every three months.



