Talk to Home Assistant from scripts: long-lived tokens, REST and WebSocket API, and !secretcode · unverified · Create a long-lived access token in your user profile, send it as 'Authorization: Bearer', and use /api/states and /api/services, or the WebSocket API for live events. Keep passwords in secrets.yaml, but know that secrets used in automations are visible to admins.