Wake your home network, from anywhere.
A secret crosses the cloud, and the machine at home lights up.
no open ports · no exposed LAN · the server only sees ciphertext
$ docker compose up -d ↓browser
Plaintext MAC never leaves your browser
vps
The server only sees ciphertext
agent
Dials out only — no inbound ports
device
Lights up = woken
§ How it works
One wake, exactly three hops
01 encrypt
Encrypted in your browser
Your browser encrypts the MAC with the agent's public key. From receipt to database, the server only ever sees ciphertext.
RSA-OAEP( 6C:4B:90:…:9E ) → 0x9f3a 7c12 … 44e1 · server sees: ∅
02 relay
The agent dials out, and only out
The agent holds an outbound SSE connection, and commands ride it home. No inbound port points at your house — zero router configuration.
$ wakewake-agent --server https://wakewake.example.com \
--pairing 7F3K-A2BM-9Q4D
✔ paired · rsa-2048 keypair written · dialing out …
03 wake
A magic packet lights it up
The agent decrypts the MAC and broadcasts a magic packet on your LAN. It never scans, forwards, or proxies anything.
FF FF FF FF FF FF · 6C 4B 90 … 9E · ×16 → 192.168.1.255:9
nas-01 online
§ Trust
The hard questions, asked first
What if the whole database is stolen?
Nothing useful. MACs are encrypted in the browser; the database holds only RSA-OAEP ciphertext. The private key lives on the agent's disk — and nowhere else.
Do I need open ports or a public IP at home?
Neither. The agent only dials out, so there is no inbound hole pointing at your home. Your router stays untouched.
If the server is fully compromised, what's the worst case?
At worst, replaying old ciphertexts to boot devices you already registered. It cannot read MACs, cannot forge new devices, and cannot reach into your LAN.
What about the rest of my LAN?
Untouched. The agent sends broadcast magic packets and nothing else — no scanning, no forwarding, no proxying.
§ Deploy
Three commands, on your own VPS
One multi-arch image, fronted by Caddy. Migrations and the bootstrap admin run automatically at startup — there is no migration step to forget.
$ cp docker/config.example.toml docker/config.toml
$ cp docker/.env.example docker/.env
# 3 secrets → openssl rand -base64 32
$ docker compose -f docker/docker-compose.yml up -d
✔ listening · http://<host>:8443
✔ migrations applied · bootstrap admin ready
§ Why WakeWake
No platform lock-in, no hardware upgrade, no open ports
Zero inbound ports
The agent makes only outbound connections — your router needs no port forwarding and your LAN stays invisible.
End-to-end encrypted
MAC addresses are encrypted in your browser with a key generated at home; the server only ever sees ciphertext.
Runs on a tiny server
A 2 GB VPS is enough. One container, no extras.
One image, anywhere
Multi-arch single image — x86 or ARM, wherever you deploy.
Full wake history
Every wake is recorded: who, when, which device.
Groups & notes
Organize devices with groups and notes.
Voice control
Wake devices by voice via the Bemfa integration.
Open source & self-hosted
AGPL-3.0. Your data stays in your hands.