Wake your home network, from anywhere.

A secret crosses the cloud, and the machine at home lights up.

no open ports · no exposed LAN · the server only sees ciphertext

$ docker compose up -d ↓
TLSSSE · dials outUDP · magicbrowserWeb Crypto2 GB VPScaddy · rustagentrsa keypairnas-01

browser

Plaintext MAC never leaves your browser

vps

The server only sees ciphertext

agent

Dials out only — no inbound ports

device

Lights up = woken

§ How it works

One wake, exactly three hops

01 encrypt

Encrypted in your browser

Your browser encrypts the MAC with the agent's public key. From receipt to database, the server only ever sees ciphertext.

RSA-OAEP( 6C:4B:90:…:9E ) → 0x9f3a 7c12 … 44e1 · server sees: ∅

02 relay

The agent dials out, and only out

The agent holds an outbound SSE connection, and commands ride it home. No inbound port points at your house — zero router configuration.

$ wakewake-agent --server https://wakewake.example.com \

--pairing 7F3K-A2BM-9Q4D

✔ paired · rsa-2048 keypair written · dialing out …

03 wake

A magic packet lights it up

The agent decrypts the MAC and broadcasts a magic packet on your LAN. It never scans, forwards, or proxies anything.

FF FF FF FF FF FF · 6C 4B 90 … 9E · ×16 → 192.168.1.255:9

nas-01 online

§ Trust

The hard questions, asked first

What if the whole database is stolen?

Nothing useful. MACs are encrypted in the browser; the database holds only RSA-OAEP ciphertext. The private key lives on the agent's disk — and nowhere else.

Do I need open ports or a public IP at home?

Neither. The agent only dials out, so there is no inbound hole pointing at your home. Your router stays untouched.

If the server is fully compromised, what's the worst case?

At worst, replaying old ciphertexts to boot devices you already registered. It cannot read MACs, cannot forge new devices, and cannot reach into your LAN.

What about the rest of my LAN?

Untouched. The agent sends broadcast magic packets and nothing else — no scanning, no forwarding, no proxying.

§ Deploy

Three commands, on your own VPS

One multi-arch image, fronted by Caddy. Migrations and the bootstrap admin run automatically at startup — there is no migration step to forget.

compose · a 2 GB VPS is enoughsh

$ cp docker/config.example.toml docker/config.toml

$ cp docker/.env.example docker/.env

# 3 secrets → openssl rand -base64 32

$ docker compose -f docker/docker-compose.yml up -d

✔ listening · http://<host>:8443

✔ migrations applied · bootstrap admin ready

one image · amd64 + arm64migrations on startupidempotent bootstrap admin

§ Why WakeWake

No platform lock-in, no hardware upgrade, no open ports

Zero inbound ports

The agent makes only outbound connections — your router needs no port forwarding and your LAN stays invisible.

End-to-end encrypted

MAC addresses are encrypted in your browser with a key generated at home; the server only ever sees ciphertext.

Runs on a tiny server

A 2 GB VPS is enough. One container, no extras.

One image, anywhere

Multi-arch single image — x86 or ARM, wherever you deploy.

Full wake history

Every wake is recorded: who, when, which device.

Groups & notes

Organize devices with groups and notes.

Voice control

Wake devices by voice via the Bemfa integration.

Open source & self-hosted

AGPL-3.0. Your data stays in your hands.

Up and running in three commands.