[{"data":1,"prerenderedAt":1185},["ShallowReactive",2],{"blog-\u002Fblog\u002F2026\u002F05\u002Fopc-ua-security-attack-vectors":3,"featureCatalog":255,"changelog-titles":650,"blog-all-for-related":1184},{"id":4,"title":5,"authors":6,"body":8,"cta":229,"date":233,"description":234,"extension":235,"features":236,"image":237,"lastUpdated":236,"meta":238,"navigation":243,"path":244,"release":236,"seo":245,"sitemap":246,"stem":247,"subtitle":248,"tags":249,"tldr":253,"video":236,"__hash__":254},"blog\u002Fblog\u002F2026\u002F05\u002Fopc-ua-security-attack-vectors.md","OPC UA Security: How Threat Actors Exploit Industrial Protocol Vulnerabilities",[7],"sumit-shinde",{"type":9,"value":10,"toc":216},"minimark",[11,15,18,23,26,29,40,44,53,56,59,65,71,74,77,81,84,96,100,107,115,118,122,131,136,139,160,164,167,180,184,193,202,206,209],[12,13,14],"p",{},"Threat actors don't break OPC UA's cryptography. They walk through the security it left switched off. The attacks that work in the field are disabled trust lists, anonymous logins left on, dead ciphers nobody removed, and servers sitting on the open internet. This post breaks down how attackers actually exploit OPC UA, vector by vector.",[12,16,17],{},"That's the irony. Unlike most industrial protocols, OPC UA ships with real security: authentication, signing, and encryption built into the spec. It's what finally let your Siemens PLC, your Allen-Bradley controller, and your SCADA system speak the same language. But \"built in\" and \"turned on\" are different things, and attackers live in that gap.",[19,20,22],"h2",{"id":21},"why-attackers-target-opc-ua","Why attackers target OPC UA",[12,24,25],{},"The OPC server sits at a dangerous spot in the stack. It talks to PLCs, HMIs, and robotic arms, then exposes everything through one interface. For an attacker, that's the appeal: compromise the server and you don't get one device, you get the read-and-write path to the physical process.",[12,27,28],{},"That changes the attacker's goal. In IT, the aim is usually to take over the machine. In OT, the more alarming prospect is the physical one: because the OPC server issues the commands that run the plant, blinding the operator or freezing the server can create a safety problem, not just a data breach.",[12,30,31,32,39],{},"The scale is real. ",[33,34,38],"a",{"href":35,"rel":36},"https:\u002F\u002Fclaroty.com\u002Fteam82\u002Fresearch\u002Fopc-ua-deep-dive-a-complete-guide-to-the-opc-ua-attack-surface",[37],"nofollow","Claroty's Team82"," has disclosed more than two dozen OPC UA vulnerabilities since 2020, and its exploit framework has helped find close to 50 across clients, servers, and gateways.",[19,41,43],{"id":42},"the-exposure-problem","The exposure problem",[12,45,46,47,52],{},"Before any clever exploit, there's the basic question of who can reach the server. ",[33,48,51],{"href":49,"rel":50},"https:\u002F\u002Fwww.bitsight.com\u002Fblog\u002Fopc-ua-server-internet-device-exposures-in-2025",[37],"Bitsight's TRACE research team",", in a year-long scan through June 2025, found 14,220 internet-exposed OPC UA devices across 99 countries. Over half (51.74%) allowed unauthenticated access. Among the devices that reported their supported security modes, 80.26% supported an unencrypted \"None\" mode that transmits data in plaintext. Most anonymously accessible servers also had auditing disabled, so an attacker connects, reads the plant, and leaves no trail.",[12,54,55],{},"None of this is a flaw in OPC UA itself. The protocol offers strong authentication and encryption; these are deployment and configuration choices made by asset owners.",[12,57,58],{},"Anonymous access, as Bitsight senior security research scientist Vasco Pinto frames it, is what makes the exposure dangerous:",[60,61,62],"blockquote",{},[12,63,64],{},"This configuration represents a significant security risk, as it allows anyone to access server information and potentially read operational data without authentication.",[12,66,67],{},[33,68,70],{"href":49,"rel":69},[37],"Bitsight TRACE",[12,72,73],{},"Major OT vendors, including Siemens, Schneider Electric, and Rockwell Automation, all explicitly advise against putting these servers on the open internet. Thousands remain there anyway.",[12,75,76],{},"The lesson from OT researchers is blunt: attackers often don't need an exploit. Unauthenticated, internet-facing servers are the entry point, and Shodan does the recon for free.",[19,78,80],{"id":79},"anonymous-and-weak-authentication","Anonymous and weak authentication",[12,82,83],{},"If anonymous login is enabled, the server simply doesn't authenticate the user, and combined with internet exposure, there's no attack to speak of. The attacker just connects.",[12,85,86,87,91,92,95],{},"There's a trap here too. OPC UA separates ",[88,89,90],"em",{},"application"," authentication (does the server trust this client's certificate?) from ",[88,93,94],{},"user"," authentication (who is the user?). Anonymous user access is far less risky when application authentication is enforced, but dangerous when it isn't. Many deployments disable the wrong layer and assume they're still covered.",[19,97,99],{"id":98},"broken-certificate-validation","Broken certificate validation",[12,101,102,103,106],{},"This one's the worst, because the servers ",[88,104,105],{},"look"," secure. They advertise certificate-based authentication. They just don't enforce it.",[12,108,109,114],{},[33,110,113],{"href":111,"rel":112},"https:\u002F\u002Farxiv.org\u002Fabs\u002F2104.06051",[37],"CISPA researchers Alessandro Erba, Anne Müller, and Nils Ole Tippenhauer"," systematically tested 48 OPC UA products and libraries. They found 38 of the 48 carried one or more security issues, and 7 didn't support the protocol's security features at all. The failures cluster around certificate and trust list handling: missing trust list support, trust lists disabled by default, and insecure trust list configuration. The researchers were careful to locate the problem in implementations and configuration rather than the protocol's design, though they argued the standard contributes by permitting these insecure options in the first place.",[12,116,117],{},"What does that buy an attacker? A machine-in-the-middle position. A third party inserts itself between two legitimate entities, intercepting and tampering with data while neither side notices, blinding maintenance staff to the real state of the plant. The operator's screen says everything is normal. It isn't. The researchers proved it: their attack framework, which implements Rogue Server, Rogue Client, and Middleperson modes against real implementations, could steal exchanged credentials, eavesdrop on process data, and manipulate the physical process through sensor and actuator values.",[19,119,121],{"id":120},"weak-legacy-crypto-left-switched-on","Weak legacy crypto left switched on",[12,123,124,125,130],{},"OPC UA didn't build on TLS. It implemented its own cryptographic transport layer, which is exactly why Secura's Tom Tervoort, the researcher behind Zerologon, went after it ",[33,126,129],{"href":127,"rel":128},"https:\u002F\u002Fwww.darkreading.com\u002Fvulnerabilities-threats\u002Futilities-factories-encryption-holes-industrial-protocol",[37],"at DEF CON 33 in 2025",":",[60,132,133],{},[12,134,135],{},"That makes it an interesting research target for me, especially because they're not relying on an existing standard protocol like TLS. They implemented their own cryptographic protocol.",[12,137,138],{},"Tom Tervoort, Secura",[12,140,141,142,147,148,153,154,159],{},"His work produced three CVEs, all credited to him in the vendor advisories, and by his own account at the talk the underlying issues affected at least seven products. ",[33,143,146],{"href":144,"rel":145},"https:\u002F\u002Ffiles.opcfoundation.org\u002FSecurityBulletins\u002FOPC%20Foundation%20Security%20Bulletin%20CVE-2024-42513.pdf",[37],"CVE-2024-42513"," lets an unauthorized attacker bypass application authentication in the OPC UA .NET Standard Stack when HTTPS endpoints are enabled with a security policy other than None, which the OPC Foundation classifies as CWE-305 and rates medium severity. ",[33,149,152],{"href":150,"rel":151},"https:\u002F\u002Ffiles.opcfoundation.org\u002FSecurityBulletins\u002FOPC%20Foundation%20Security%20Bulletin%20CVE-2024-42512.pdf",[37],"CVE-2024-42512"," targets the deprecated Basic128Rsa15 policy, which uses RSA with PKCS#1 v1.5 padding. The OPC Foundation classifies it as an observable timing discrepancy (CWE-208) with confidentiality impact and rates it medium severity, noting that Basic128Rsa15 is disabled by default, so most users are unaffected. CODESYS, assessing the same weakness in its own server as ",[33,155,158],{"href":156,"rel":157},"https:\u002F\u002Fcertvde.com\u002Fen\u002Fadvisories\u002FVDE-2025-022\u002F",[37],"CVE-2025-1468",", describes the consequence more bluntly: an unauthenticated attacker exploiting the Bleichenbacher padding oracle (a decades-old attack that recovers RSA-encrypted secrets by watching how a server responds to malformed padding) could compromise the server certificate's private key, then bypass application authentication or decrypt traffic. The common thread is old, known-weak crypto that should have been retired but lingers in non-default configurations.",[19,161,163],{"id":162},"denial-of-service-against-the-process","Denial of service against the process",[12,165,166],{},"Not every attack reads or steals. Some just stop the plant. Flooding or crashing the OPC server kills the SCADA workstation's real-time view and command path.",[12,168,169,170,175,176,179],{},"This is where OPC UA research began. In 2018, ",[33,171,174],{"href":172,"rel":173},"https:\u002F\u002Fics-cert.kaspersky.com\u002Fpublications\u002Freports\u002F2018\u002F05\u002F10\u002Fopc-ua-security-analysis\u002F",[37],"Kaspersky ICS CERT"," reported 17 zero-day vulnerabilities in the OPC Foundation's products, spanning denial of service and remote code execution, plus several flaws in commercial applications built on the stack. All were reported and fixed by the end of March 2018. It's worth noting the OPC Foundation's own response: it reviewed the findings and pointed out that eight of the 17 sat in an ANSI-C ",[88,177,178],{},"sample server application"," shipped as example code on GitHub rather than in the production stack, and that many third-party flaws came from developers misusing the stack's API. The researchers also pinned down the realistic threat model in interviews: exploitation usually needs local network access, and they said they had never seen a configuration allowing direct internet attacks. The broader lesson holds regardless: because a single flaw in a shared OPC UA library or sample can propagate into every product built on it, one bug scales across the supply chain.",[19,181,183],{"id":182},"client-and-gateway-exploitation","Client and gateway exploitation",[12,185,186,187,192],{},"Servers aren't the only target. The client trusts the server, and that trust is exploitable. ",[33,188,191],{"href":189,"rel":190},"https:\u002F\u002Fclaroty.com\u002Fteam82\u002Fresearch\u002Fopc-ua-deep-dive-series-part-8-gaining-client-side-remote-code-execution",[37],"Team82 demonstrated client-side remote code execution"," by exploiting the client's trust in data it receives from the server. Stand up a rogue server and you can reach back into the clients connecting to it.",[12,194,195,196,201],{},"Integration servers, the gateways stitching multiple OPC UA systems together, are richer still, because vulnerabilities chain. ",[33,197,200],{"href":198,"rel":199},"https:\u002F\u002Fclaroty.com\u002Fteam82\u002Fresearch\u002Fopc-ua-deep-dive-series-part-9-chaining-vulnerabilities-to-exploit-softing-opc-ua-integration-server",[37],"In the Softing Secure Integration Server",", researchers chained four new bugs with a fifth to reach full remote code execution. No single flaw was catastrophic; strung together, they owned the box.",[19,203,205],{"id":204},"the-pattern","The pattern",[12,207,208],{},"The vulnerabilities threat actors exploit in OPC UA are rarely clever zero days. They're disabled trust lists, anonymous logins, stale ciphers, exposed servers, and trusted clients fed bad data. The protocol gives you the tools to close every one. The question is whether they're switched on.",[12,210,211,212,215],{},"That's an architecture problem, and it's where we're headed next. In the follow-up, ",[88,213,214],{},"How to Establish a Defensible OPC UA Security Architecture",", we'll turn these attack vectors into a concrete blueprint for building OPC UA deployments that hold up.",{"title":217,"searchDepth":218,"depth":218,"links":219},"",4,[220,222,223,224,225,226,227,228],{"id":21,"depth":221,"text":22},2,{"id":42,"depth":221,"text":43},{"id":79,"depth":221,"text":80},{"id":98,"depth":221,"text":99},{"id":120,"depth":221,"text":121},{"id":162,"depth":221,"text":163},{"id":182,"depth":221,"text":183},{"id":204,"depth":221,"text":205},{"type":230,"title":231,"description":232},"contact","Connect your plant without opening it up","FlowFuse helps you move industrial data off exposed, internet-facing servers and into a managed, secure architecture. Talk to our team about your OT connectivity.","2026-05-29","Most OPC UA breaches don't crack the protocol's encryption. They walk through disabled trust lists, anonymous logins, stale ciphers, and servers left on the open internet. This post breaks down how attackers actually exploit OPC UA, vector by vector, drawing on research from Claroty, Bitsight, CISPA, Secura, and Kaspersky.","md",null,"\u002Fblog\u002F2026\u002F05\u002Fimages\u002Fopcua-security-blog.png",{"excerpt":239},{"type":9,"value":240},[241],[12,242,14],{},true,"\u002Fblog\u002F2026\u002F05\u002Fopc-ua-security-attack-vectors",{"title":5,"description":234},{"loc":244},"blog\u002F2026\u002F05\u002Fopc-ua-security-attack-vectors","The attacks that work in the field aren't broken cryptography, they're security that was never switched on",[250,251,252],"posts","flowfuse","opcua","OPC UA ships with real authentication, signing, and encryption, but attackers rarely touch it. They exploit the gap between 'built in' and 'turned on': anonymous access, trust lists that don't enforce certificates, deprecated ciphers nobody removed, and internet-exposed servers Shodan finds for free. The protocol gives you the tools to close every vector. The question is whether they're switched on.","TK6u9Ae-DJtvTZZ5Kk-V1QdWqV_n2T1L6Disud_Y4_M",{"id":256,"extension":257,"meta":258,"sections":259,"stem":648,"__hash__":649},"featureCatalog\u002Ffeature-catalog.yml","yml",{},[260,311,412,474,551,630],{"id":261,"title":262,"features":263},"ai-automation","AI & Automation",[264,274,284,294,300,306],{"id":265,"title":266,"description":267,"docsLink":268,"changelog":269,"tiers":273},"flowfuse-expert-ai","FlowFuse Expert AI","Build industrial apps with agents, and query the state of the factory with an agent. Adapt your current hardware and machines so agentic work can be done against them, without ripping and replacing what's already on the plant floor.","\u002Fdocs\u002Fuser\u002Fexpert\u002F",[270],{"url":271,"release":272},"\u002Fchangelog\u002F2026\u002F02\u002Fff-expert-update-banner\u002F","2.28",{"edge":243,"hub":243,"fleet":243},{"id":275,"title":276,"description":277,"docsLink":278,"changelog":279,"subfeature":243,"showOnPricing":282,"tiers":283},"flowfuse-expert-support-mode","Support Mode","Chat-based assistance for FlowFuse and Node-RED, including Node-RED instance management through natural language.","\u002Fdocs\u002Fuser\u002Fexpert\u002Fchat\u002F#support-mode",[280],{"url":281,"release":272},"\u002Fchangelog\u002F2026\u002F02\u002Fff-expert-debug-log-context\u002F",false,{"edge":243,"hub":243,"fleet":243},{"id":285,"title":286,"description":287,"docsLink":288,"changelog":289,"subfeature":243,"showOnPricing":282,"tiers":293},"flowfuse-expert-application-building","Application Building","Describe what you want to build and FlowFuse Expert assembles it on your workspace, adding tabs, wiring nodes, and configuring properties.","\u002Fdocs\u002Fuser\u002Fexpert\u002Fchat\u002F",[290],{"url":291,"release":292},"\u002Fchangelog\u002F2026\u002F05\u002Fexpert-application-building\u002F","2.30",{"edge":243,"hub":243,"fleet":243},{"id":295,"title":296,"description":297,"docsLink":298,"subfeature":243,"beta":243,"showOnPricing":282,"tiers":299},"flowfuse-expert-insights-mode","Insights Mode","Connects FlowFuse Expert to MCP servers in your Node-RED instances, enabling real-time data queries and actions through a single chat interface.","\u002Fdocs\u002Fuser\u002Fexpert\u002Fchat\u002F#insights-mode",{"edge":243,"hub":243,"fleet":243},{"id":301,"title":302,"description":303,"docsLink":304,"tiers":305},"mcp-servers","Agentic Operations","Expose your Node-RED flows as tools an AI agent can call directly, so agents can query the state of the factory or trigger actions without custom integration work.","\u002Fnode-red\u002Fflowfuse\u002Fmcp\u002F",{"edge":243,"hub":243,"fleet":243},{"id":307,"title":308,"description":309,"tiers":310},"onnx-integration","ONNX Integration","Run trained machine learning models directly in your flows, including on edge hardware, without sending data out to an external inference service.",{"edge":243,"hub":243,"fleet":243},{"id":312,"title":313,"features":314},"build","Build",[315,321,327,337,343,349,353,359,365,373,379,383,387,396,404],{"id":316,"title":317,"description":318,"docsLink":319,"tiers":320},"edge-development","Edge Development","Develop and test Node-RED flows directly on edge devices with a remote editor proxy.","\u002Fdocs\u002Fdevice-agent\u002Fquickstart\u002F",{"edge":243,"hub":282,"fleet":243},{"id":322,"title":323,"description":324,"docsLink":325,"tiers":326},"private-npm-registry","Custom Node-RED Nodes","Create and manage your own private npm registry for Node-RED nodes, so you can share custom nodes across your team and devices without publishing them publicly.","\u002Fdocs\u002Fuser\u002Fcustom-npm-packages\u002F",{"edge":243,"hub":243,"fleet":243},{"id":328,"title":329,"description":330,"docsLink":331,"changelog":332,"tiers":336},"flowfuse-tables","FlowFuse Tables","A managed PostgreSQL database for every application, so you can store and query structured data without standing up and maintaining your own database.","\u002Fdocs\u002Fuser\u002Fff-tables\u002F",[333],{"url":334,"release":335},"\u002Fchangelog\u002F2026\u002F07\u002Fexpert-tables-automation\u002F","2.33",{"edge":243,"hub":243,"fleet":243},{"id":338,"title":339,"description":340,"docsLink":341,"tiers":342},"persistent-files","File Storage","Store and retrieve files from your Node-RED flows, with automatic replication and backup across your devices and hosted instances.","\u002Fdocs\u002Finstall\u002Ffile-storage\u002F",{"edge":243,"hub":243,"fleet":243},{"id":344,"title":345,"description":346,"docsLink":347,"showOnPricing":282,"tiers":348},"persistent-context","Persistent Context","In-memory values defined in a Node-RED flow persist across project restarts and upgrades.","\u002Fdocs\u002Fuser\u002Fpersistent-context\u002F",{"edge":243,"hub":243,"fleet":243},{"id":350,"title":351,"showOnPricing":282,"tiers":352},"static-assets","Static Assets",{"edge":243,"hub":243,"fleet":243},{"id":354,"title":355,"description":356,"docsLink":357,"tiers":358},"team-library","Team Library","Set up standard nodes and flows that can be shared with all team members across your organisation.","\u002Fdocs\u002Fuser\u002Fshared-library\u002F",{"edge":243,"hub":243,"fleet":243},{"id":360,"title":361,"description":362,"docsLink":363,"tiers":364},"personalised-multi-user-dashboards","Personalised Multi-User Dashboards","Build applications that provide unique data to each logged-in user using personalised multi-user dashboards.","https:\u002F\u002Fdashboard.flowfuse.com\u002Fuser\u002Fmulti-tenancy.html",{"edge":243,"hub":243,"fleet":243},{"id":366,"title":367,"description":368,"changelog":369,"subfeature":243,"showOnPricing":282,"tiers":372},"dashboards-view","Dashboards View","Browse and open every dashboard across your team from a dedicated Dashboards view, at both team and application level, without leaving FlowFuse.",[370],{"url":371,"release":335},"\u002Fchangelog\u002F2026\u002F07\u002Fteam-and-application-dashboards\u002F",{"edge":243,"hub":243,"fleet":243},{"id":374,"title":375,"description":376,"docsLink":377,"tiers":378},"blueprints-converge","Blueprints","Ready-made starting points for your apps, from cross-team Converge templates to OT and IT specific blueprints.","\u002Fdocs\u002Fuser\u002Fconcepts\u002F#blueprint",{"edge":243,"hub":243,"fleet":243},{"id":380,"title":381,"subfeature":243,"showOnPricing":282,"tiers":382},"blueprints-ot-apps","Blueprints - OT APPS",{"edge":243,"hub":282,"fleet":243},{"id":384,"title":385,"subfeature":243,"showOnPricing":282,"tiers":386},"blueprints-it-apps","Blueprints - IT APPS",{"edge":282,"hub":243,"fleet":282},{"id":388,"title":389,"description":390,"changelog":391,"showOnPricing":282,"tiers":395},"immersive-editor-snapshots","Snapshot Details in Immersive Editor","View and manage snapshot details directly inside the immersive editor without leaving your editing session.",[392],{"url":393,"release":394},"\u002Fchangelog\u002F2026\u002F03\u002Fsnapshot-detail-modal-immersive-editor\u002F","2.29",{"edge":243,"hub":243,"fleet":243},{"id":397,"title":398,"description":399,"changelog":400,"showOnPricing":282,"tiers":403},"immersive-editor-drawer","Customisable Immersive Editor Drawer","Pin, move, resize, or full-screen the immersive editor drawer. Your preferences are remembered between sessions.",[401],{"url":402,"release":292},"\u002Fchangelog\u002F2026\u002F04\u002Fimmersive-editor-drawer\u002F",{"edge":243,"hub":243,"fleet":243},{"id":405,"title":406,"description":407,"changelog":408,"showOnPricing":282,"tiers":411},"embedded-editor-tab-title","Embedded Editor Browser Tab Title","The browser tab title updates to reflect the active Node-RED canvas tab when working in the embedded editor.",[409],{"url":410,"release":394},"\u002Fchangelog\u002F2026\u002F03\u002Fembedded-editor-tab-title\u002F",{"edge":243,"hub":243,"fleet":243},{"id":413,"title":414,"features":415},"deploy","Deploy",[416,422,431,437,443,449,455,461,466],{"id":417,"title":418,"description":419,"docsLink":420,"tiers":421},"hosted-instances","Cloud Instances","Run Node-RED instances managed and hosted by FlowFuse.","\u002Fdocs\u002Fuser\u002Fintroduction\u002F#creating-a-node-red-instance",{"edge":243,"hub":243,"fleet":243},{"id":423,"title":424,"description":425,"docsLink":426,"changelog":427,"tiers":430},"edge-devices","Edge Instances","Deploy and mange your Node-RED instances on edge PLCs and gateways, with full visibility and control from the cloud.","\u002Fdocs\u002Fdevice-agent\u002Fintroduction\u002F",[428],{"url":429,"release":272},"\u002Fchangelog\u002F2026\u002F02\u002Fdevice-agent-nodejs-options\u002F",{"edge":243,"hub":282,"fleet":243},{"id":432,"title":433,"description":434,"docsLink":435,"tiers":436},"custom-hostnames","Custom Hostnames","Access your Node-RED application via your own domain name.","\u002Fdocs\u002Fuser\u002Fcustom-hostnames\u002F",{"edge":282,"hub":243,"fleet":282},{"id":438,"title":439,"description":440,"docsLink":441,"tiers":442},"mqtt-broker","MQTT Broker","Manage and create MQTT clients to transport data for efficient messaging and communication within your applications.","\u002Fdocs\u002Fuser\u002Fteambroker\u002F",{"edge":243,"hub":282,"fleet":243},{"id":444,"title":445,"description":446,"docsLink":447,"showOnPricing":282,"tiers":448},"project-nodes","Project Nodes aka seamless project comms","FlowFuse Project Nodes enable the passing of data and messages between your Node-RED projects.","\u002Fdocs\u002Fuser\u002Fprojectnodes\u002F",{"edge":243,"hub":243,"fleet":243},{"id":450,"title":451,"description":452,"docsLink":453,"tiers":454},"devops-pipelines","DevOps Pipelines","Set up different environments for development, testing, and production Node-RED instances to support a full software delivery lifecycle.","\u002Fdocs\u002Fuser\u002Fdevops-pipelines\u002F",{"edge":243,"hub":243,"fleet":243},{"id":456,"title":457,"description":458,"docsLink":459,"tiers":460},"git-integration","Git Integration","Back up your flows to a remote Git repository through a DevOps Pipeline. Supports GitHub and Azure DevOps repositories.","\u002Fdocs\u002Fuser\u002Fdevops-pipelines\u002F#git-repository-stage",{"edge":282,"hub":243,"fleet":282},{"id":462,"title":463,"description":464,"docsLink":459,"subfeature":243,"showOnPricing":282,"tiers":465},"git-integration-github","GitHub","Push and pull snapshots to GitHub repositories through DevOps Pipeline Git Stages.",{"edge":282,"hub":243,"fleet":282},{"id":467,"title":468,"description":469,"docsLink":459,"changelog":470,"subfeature":243,"showOnPricing":282,"tiers":473},"git-integration-azure","Azure DevOps","Push and pull snapshots to Azure DevOps repositories through DevOps Pipeline Git Stages.",[471],{"url":472,"release":394},"\u002Fchangelog\u002F2026\u002F03\u002Fazure-dev-ops-gitops\u002F",{"edge":282,"hub":243,"fleet":282},{"id":475,"title":476,"features":477},"operate-maintain","Operate & Maintain",[478,484,490,495,503,507,511,516,522,528,533,539,543,547],{"id":479,"title":480,"description":481,"docsLink":482,"tiers":483},"snapshots","Snapshots & Version History","Automatic snapshots on remote devices and hosted instances, plus a full version history timeline so you can roll back to any prior state.","\u002Fdocs\u002Fuser\u002Fsnapshots\u002F",{"edge":243,"hub":243,"fleet":243},{"id":485,"title":486,"description":487,"docsLink":488,"subfeature":243,"showOnPricing":282,"tiers":489},"auto-snapshot-remote","Auto Snapshot (Remote)","Automatically capture a snapshot every time a remote instance is deployed, so you always have a recoverable history of what was running on each device.","\u002Fdocs\u002Fuser\u002Fsnapshots\u002F#auto-snapshots",{"edge":243,"hub":243,"fleet":243},{"id":491,"title":492,"description":493,"docsLink":488,"subfeature":243,"showOnPricing":282,"tiers":494},"auto-snapshot-hosted","Auto Snapshot (Hosted)","Automatically capture a snapshot every time a hosted instance is deployed, so you always have a recoverable history of what was running.",{"edge":243,"hub":243,"fleet":243},{"id":496,"title":497,"description":498,"changelog":499,"subfeature":243,"showOnPricing":282,"tiers":502},"snapshot-comparison","Snapshot Comparison","Compare two snapshots side-by-side with a navigable diff view. Step through every changed, added, or deleted node and see property and code diffs.",[500],{"url":501,"release":394},"\u002Fchangelog\u002F2026\u002F04\u002Fsnapshot-diff-viewer\u002F",{"edge":243,"hub":243,"fleet":243},{"id":504,"title":505,"subfeature":243,"showOnPricing":282,"tiers":506},"version-history-timeline","Version History Timeline",{"edge":243,"hub":243,"fleet":243},{"id":508,"title":509,"tiers":510},"unlimited-workflow-executions","Unlimited Workflow Executions",{"edge":243,"hub":243,"fleet":243},{"id":512,"title":513,"description":514,"tiers":515},"device-fleet-updates","Device Fleet Updates","Connect to edge devices to quickly assess and update logic. Debug one device and roll out improvements to your fleet in minutes, securely without requiring full device access for your whole organisation.",{"edge":243,"hub":282,"fleet":243},{"id":517,"title":518,"description":519,"docsLink":520,"tiers":521},"device-group-management","Device Group Management","Logically group devices assigned to an application and integrate device groups into your DevOps Pipeline for coordinated fleet updates.","\u002Fdocs\u002Fuser\u002Fdevice-groups\u002F",{"edge":243,"hub":282,"fleet":243},{"id":523,"title":524,"description":525,"docsLink":526,"tiers":527},"high-availability","High Availability","Leverage horizontal scaling for reliable and scalable processing of your data through Node-RED.","\u002Fdocs\u002Fuser\u002Fhigh-availability\u002F",{"edge":282,"hub":243,"fleet":282},{"id":529,"title":530,"description":531,"tiers":532},"performance-monitoring","Performance Monitoring & Alerts","Track CPU, memory, and event loop performance across your instances and devices, with email alerts when something needs your attention.",{"edge":243,"hub":243,"fleet":243},{"id":534,"title":535,"description":536,"docsLink":537,"subfeature":243,"showOnPricing":282,"tiers":538},"instance-monitoring","Instance Monitoring","Enable alerts to be sent via email when your Node-RED instances encounter issues.","\u002Fdocs\u002Fuser\u002Finstance-settings\u002F#alerts",{"edge":243,"hub":243,"fleet":243},{"id":540,"title":541,"subfeature":243,"showOnPricing":282,"tiers":542},"email-alerts","Email Alerts",{"edge":243,"hub":243,"fleet":243},{"id":544,"title":545,"showOnPricing":282,"tiers":546},"api-debug-length-limit","API\u002FDebug Length Limit",{"edge":243,"hub":243,"fleet":243},{"id":548,"title":549,"tiers":550},"protected-instances","Protected Instances",{"edge":282,"hub":243,"fleet":282},{"id":552,"title":553,"features":554},"govern-secure","Govern and Secure",[555,564,570,576,581,587,593,599,607,613,619,625],{"id":556,"title":557,"description":558,"docsLink":559,"changelog":560,"tiers":563},"single-sign-on","Single Sign-On (SSO)","Configure FlowFuse to work with your own SSO provider, allowing users to access FlowFuse with a single set of login credentials.","\u002Fdocs\u002Fadmin\u002Fsso\u002F",[561],{"url":562,"release":335},"\u002Fchangelog\u002F2026\u002F07\u002Fapplication-sso-groups\u002F",{"edge":243,"hub":243,"fleet":243},{"id":565,"title":566,"description":567,"docsLink":568,"tiers":569},"two-factor-authentication","Two-Factor Authentication","Two-factor authentication adds an extra layer of security to your FlowFuse account.","\u002Fdocs\u002Fuser\u002Fuser-settings\u002F#two-factor-authentication",{"edge":243,"hub":243,"fleet":243},{"id":571,"title":572,"description":573,"docsLink":574,"tiers":575},"certified-nodes-it","Certified Nodes - IT","IT certified node bundle includes: Redis, MQTT, HTTP Request, AI nodes (Gemini, Claude, ChatGPT, Ollama), MCP Server","\u002Fblog\u002F2025\u002F07\u002Fcertified-nodes-v2\u002F",{"edge":282,"hub":243,"fleet":243},{"id":577,"title":578,"description":579,"tiers":580},"certified-nodes-ot","Certified OT Connections - OPC-UA, Modbus, etc.","OT certified node bundle includes: OPC-UA, Modbus TCP & RTU, RTSP, EtherNet\u002FIP, AI nodes (Gemini, Claude, ChatGPT, Ollama), MCP Server",{"edge":243,"hub":282,"fleet":282},{"id":582,"title":583,"description":584,"docsLink":585,"tiers":586},"audit-log","Audit Log","Keep track of everything going on in your Node-RED instances and FlowFuse. Audit Logs provide details on what actions have taken place, when they happened, and who did them.","\u002Fdocs\u002Fuser\u002Flogs\u002F#audit-log",{"edge":243,"hub":243,"fleet":243},{"id":588,"title":589,"description":590,"docsLink":591,"tiers":592},"role-based-access-control","Role-Based Access Control","Control who can do what at both the team and application level, from viewers to admins.","\u002Fdocs\u002Fuser\u002Frole-based-access-control\u002F",{"edge":243,"hub":243,"fleet":243},{"id":594,"title":595,"description":596,"docsLink":597,"subfeature":243,"showOnPricing":282,"tiers":598},"application-level-rbac","Application-Level RBAC","Fine-grained access control per application, allowing team members to have different permission levels across different applications without requiring separate teams.","\u002Fdocs\u002Fuser\u002Frole-based-access-control\u002F#application-level-rbac",{"edge":243,"hub":243,"fleet":243},{"id":600,"title":601,"description":602,"changelog":603,"subfeature":243,"showOnPricing":282,"tiers":606},"scoped-personal-access-tokens","Scoped Personal Access Tokens","Restrict a Personal Access Token to specific teams, limit it to read-only operations, or control whether it carries admin privileges.",[604],{"url":605,"release":335},"\u002Fchangelog\u002F2026\u002F07\u002Fscoped-pats\u002F",{"edge":243,"hub":243,"fleet":243},{"id":608,"title":609,"description":610,"docsLink":611,"showOnPricing":282,"tiers":612},"team-members","Team Members","Invite multiple team members to collaborate on the same Node-RED flows.","\u002Fdocs\u002Fuser\u002Fteam\u002F#teams",{"edge":243,"hub":243,"fleet":243},{"id":614,"title":615,"description":616,"docsLink":617,"showOnPricing":282,"tiers":618},"endpoint-security","Endpoint Security","Secure HTTP endpoints for hosted Node-RED instances using FlowFuse credentials.","\u002Fdocs\u002Fuser\u002Finstance-settings\u002F#security",{"edge":243,"hub":243,"fleet":243},{"id":620,"title":621,"description":622,"docsLink":623,"tiers":624},"baa-for-hipaa","BAA for HIPAA","FlowFuse can sign a Business Associate Agreement to ensure proper safeguarding of protected health information handled on your behalf.","\u002Fhandbook\u002Fsales\u002Fsubscription-agreement-1.5\u002F",{"edge":282,"hub":243,"fleet":282},{"id":626,"title":627,"description":628,"tiers":629},"sbom","Software Bill of Materials","A complete list of all software components used in your Node-RED instances and hosted applications, including version numbers and license information.",{"edge":282,"hub":243,"fleet":282},{"id":631,"title":632,"features":633},"support","Support",[634,639,643],{"id":635,"title":636,"docsLink":637,"tiers":638},"installation-support","Installation Support","\u002Fdocs\u002Finstall\u002Fintroduction\u002F#do-you-need-help-installation-service",{"edge":243,"hub":243,"fleet":243},{"id":640,"title":641,"showOnPricing":282,"tiers":642},"live-chat-support","Live Chat Support",{"edge":243,"hub":243,"fleet":243},{"id":644,"title":645,"docsLink":646,"tiers":647},"enterprise-support","Enterprise Support","\u002Fdocs\u002Fpremium-support\u002F",{"edge":243,"hub":243,"fleet":243},"feature-catalog","0AnkhTIPCECCwP9NmbTWP5HvRYx4FTSao4lG93-HaWM",[651,654,657,660,663,666,668,671,674,677,680,682,685,688,691,694,697,700,703,706,709,712,715,718,721,724,727,730,733,736,739,742,745,748,751,754,757,760,763,766,769,772,775,778,781,784,787,790,793,795,798,801,804,807,810,813,816,818,821,824,827,830,833,835,838,841,844,847,850,853,856,859,862,865,867,870,873,876,879,882,885,888,891,894,897,900,903,906,909,911,914,917,920,923,926,929,932,935,938,941,944,947,950,953,956,959,962,965,967,970,973,976,979,982,985,988,990,993,996,999,1002,1005,1008,1011,1014,1017,1020,1023,1026,1029,1032,1035,1038,1041,1044,1047,1050,1053,1056,1059,1062,1065,1068,1071,1074,1077,1080,1083,1086,1089,1092,1095,1098,1101,1104,1107,1110,1113,1116,1119,1122,1125,1128,1131,1134,1137,1140,1142,1145,1148,1151,1154,1157,1160,1163,1166,1169,1172,1175,1178,1181],{"path":652,"title":653},"\u002Fchangelog\u002F2023\u002F09\u002Fcustom-node-support","Custom Node Support",{"path":655,"title":656},"\u002Fchangelog\u002F2023\u002F09\u002Fdevops-actions","DevOps Pipeline with action selection",{"path":658,"title":659},"\u002Fchangelog\u002F2023\u002F09\u002Fintroduction-enterprise-tier","Introducing the Enterprise Tier",{"path":661,"title":662},"\u002Fchangelog\u002F2023\u002F09\u002Fpipeline-api","API Endpoint for DevOps Pipeline",{"path":664,"title":665},"\u002Fchangelog\u002F2023\u002F09\u002Fsnapshots-devices","Usability improvements to Device Management",{"path":667,"title":375},"\u002Fchangelog\u002F2023\u002F10\u002Fblueprints",{"path":669,"title":670},"\u002Fchangelog\u002F2023\u002F10\u002Fcertified-nodes","Certified Nodes",{"path":672,"title":673},"\u002Fchangelog\u002F2023\u002F10\u002Fdevice-snapshot-selection","Enhanced Snapshot Selection",{"path":675,"title":676},"\u002Fchangelog\u002F2023\u002F10\u002Fpath-bug-fix","Device Agent path bug fix",{"path":678,"title":679},"\u002Fchangelog\u002F2023\u002F10\u002Fresource-alerts","Resource Monitoring in Audit Log",{"path":681,"title":566},"\u002Fchangelog\u002F2023\u002F11\u002F2fa",{"path":683,"title":684},"\u002Fchangelog\u002F2023\u002F11\u002Fdefault-editor","Device Editor enabled by default",{"path":686,"title":687},"\u002Fchangelog\u002F2023\u002F11\u002Fdevices-in-pipelines","Devices in DevOps Pipelines",{"path":689,"title":690},"\u002Fchangelog\u002F2023\u002F11\u002Fproject-nodes-devices","Project Nodes for Devices",{"path":692,"title":693},"\u002Fchangelog\u002F2023\u002F12\u002Fbilling","No Credit Card required for billing",{"path":695,"title":696},"\u002Fchangelog\u002F2023\u002F12\u002Fblueprint-selection","Blueprint Selection Update",{"path":698,"title":699},"\u002Fchangelog\u002F2023\u002F12\u002Fdevice-groups","Device Groups",{"path":701,"title":702},"\u002Fchangelog\u002F2023\u002F12\u002Femail-alerting-node-red-crash","Email Alerts for Audit Log Events",{"path":704,"title":705},"\u002Fchangelog\u002F2023\u002F12\u002Fnode-red-updated","Node-RED 3.1.3 now available",{"path":707,"title":708},"\u002Fchangelog\u002F2024\u002F01\u002Fdevice-audit-log","Introducing the Device Auditlog Feature",{"path":710,"title":711},"\u002Fchangelog\u002F2024\u002F01\u002Fdevice-groups-snapshot","Device Groups - Automatic snapshot assignment",{"path":713,"title":714},"\u002Fchangelog\u002F2024\u002F01\u002Ffleet-mode","Renaming \"Default Device Mode\" to \"Fleet Mode\"",{"path":716,"title":717},"\u002Fchangelog\u002F2024\u002F01\u002Fhelm-v2","Helm Chart v2.0",{"path":719,"title":720},"\u002Fchangelog\u002F2024\u002F01\u002Fnew-blueprints","New Blueprints added",{"path":722,"title":723},"\u002Fchangelog\u002F2024\u002F01\u002Fsecurity-updates","Security Updates",{"path":725,"title":726},"\u002Fchangelog\u002F2024\u002F01\u002Fsso-team-membership","Managing Team Membership via SSO",{"path":728,"title":729},"\u002Fchangelog\u002F2024\u002F01\u002Fstreamlined-device-assignment","Streamlined Device assignment",{"path":731,"title":732},"\u002Fchangelog\u002F2024\u002F02\u002Fdevice-auto-snapshot","Device Auto Snapshots",{"path":734,"title":735},"\u002Fchangelog\u002F2024\u002F02\u002Fdevice-instance-audit-logs","Device Instance Audit Logging",{"path":737,"title":738},"\u002Fchangelog\u002F2024\u002F02\u002Fdevice-onboarding-improvements","Device Onboarding Improvements",{"path":740,"title":741},"\u002Fchangelog\u002F2024\u002F02\u002Fdevice-pricing-change","Pricing change for Devices",{"path":743,"title":744},"\u002Fchangelog\u002F2024\u002F02\u002Finstance-auto-snapshots","Instance Auto Snapshots",{"path":746,"title":747},"\u002Fchangelog\u002F2024\u002F02\u002Fpostgresql-upgrade","PostgreSQL Version update",{"path":749,"title":750},"\u002Fchangelog\u002F2024\u002F03\u002Fbearer-token-authentication","Bearer Token Authentication for Node-RED Instances",{"path":752,"title":753},"\u002Fchangelog\u002F2024\u002F03\u002Finstance-protection-mode","Instance Protection Mode",{"path":755,"title":756},"\u002Fchangelog\u002F2024\u002F03\u002Flimits-debug-payload","Configure HTTP Payload and Debug Message size",{"path":758,"title":759},"\u002Fchangelog\u002F2024\u002F03\u002Frestart-devices-remotly","Remote Device Restart",{"path":761,"title":762},"\u002Fchangelog\u002F2024\u002F04\u002Fcustom-nodes-on-devices","Custom Nodes Support on Devices",{"path":764,"title":765},"\u002Fchangelog\u002F2024\u002F04\u002Fdevice-auto-snapshot","Direct Dashboard Access",{"path":767,"title":768},"\u002Fchangelog\u002F2024\u002F04\u002Fimproving-device-groups","Improving Device Groups",{"path":770,"title":771},"\u002Fchangelog\u002F2024\u002F04\u002Fpricing-change","Pricing change Enterprise & Teams Tier",{"path":773,"title":774},"\u002Fchangelog\u002F2024\u002F04\u002Ftougher-rate-limiting","Tougher Rate Limiting on Public Routes",{"path":776,"title":777},"\u002Fchangelog\u002F2024\u002F05\u002Finstance-healthcheck","Customizing instance health-check settings",{"path":779,"title":780},"\u002Fchangelog\u002F2024\u002F05\u002Flibrary-blueprints","Blueprints added to Library",{"path":782,"title":783},"\u002Fchangelog\u002F2024\u002F05\u002Flibrary-flowviewer","Team Library - Flow Viewer",{"path":785,"title":786},"\u002Fchangelog\u002F2024\u002F05\u002Fmanaging-node-red-version-on-devices","Managing Node-RED versions on Devices",{"path":788,"title":789},"\u002Fchangelog\u002F2024\u002F05\u002Fsnapshot-improvements","Snapshot Improvements",{"path":791,"title":792},"\u002Fchangelog\u002F2024\u002F05\u002Fsnapshot-improvements-pt3","Snapshot Upload",{"path":794,"title":792},"\u002Fchangelog\u002F2024\u002F05\u002Fsnapshot-upload",{"path":796,"title":797},"\u002Fchangelog\u002F2024\u002F06\u002Fdevice-agent-proxy-support","Running the Device Agent behind an HTTP proxy",{"path":799,"title":800},"\u002Fchangelog\u002F2024\u002F06\u002Flibrary-blueprints","Custom hostnames for your instances",{"path":802,"title":803},"\u002Fchangelog\u002F2024\u002F06\u002Fmultiline-env-vars","Multi-line Environment Variables",{"path":805,"title":806},"\u002Fchangelog\u002F2024\u002F06\u002Fsnapshot-flow-compare","Compare Snapshots flows",{"path":808,"title":809},"\u002Fchangelog\u002F2024\u002F07\u002Fapplications-search","Applications Search",{"path":811,"title":812},"\u002Fchangelog\u002F2024\u002F07\u002Fdevice-group-clear-snapshot","Device Groups Snapshots",{"path":814,"title":815},"\u002Fchangelog\u002F2024\u002F07\u002Fdevice-management-bulk-delete","Managing devices",{"path":817,"title":815},"\u002Fchangelog\u002F2024\u002F07\u002Fdevice-management-bulk-move",{"path":819,"title":820},"\u002Fchangelog\u002F2024\u002F07\u002Fedit-snapshots","Edit Snapshots",{"path":822,"title":823},"\u002Fchangelog\u002F2024\u002F07\u002Fflowfuse-assistant","The FlowFuse Expert",{"path":825,"title":826},"\u002Fchangelog\u002F2024\u002F07\u002Fflowfuse-assistant-json","FlowFuse Expert Writes JSON",{"path":828,"title":829},"\u002Fchangelog\u002F2024\u002F07\u002Fimmersive-editor","Immersive Editor Experience",{"path":831,"title":832},"\u002Fchangelog\u002F2024\u002F07\u002Fnotifications-inbox","Notifications Inbox",{"path":834,"title":832},"\u002Fchangelog\u002F2024\u002F07\u002Fnotifications-update",{"path":836,"title":837},"\u002Fchangelog\u002F2024\u002F07\u002Fpersistent-storage","Persistent Storage on FlowFuse Cloud",{"path":839,"title":840},"\u002Fchangelog\u002F2024\u002F07\u002Fsso","Single Sign On Updates",{"path":842,"title":843},"\u002Fchangelog\u002F2024\u002F08\u002Fbill-of-materials","Bill of Materials",{"path":845,"title":846},"\u002Fchangelog\u002F2024\u002F08\u002Fenterprise-license-update","Enforcing Enterprise Restrictions",{"path":848,"title":849},"\u002Fchangelog\u002F2024\u002F08\u002Fldap-sso-groups","LDAP Single Sign On Updates",{"path":851,"title":852},"\u002Fchangelog\u002F2024\u002F08\u002Fstatic-file-service-navigation-visibility","Static File Service Navigation and Visibility",{"path":854,"title":855},"\u002Fchangelog\u002F2024\u002F10\u002Fdevice-group-env-vars","Environment Variables for your Device Groups",{"path":857,"title":858},"\u002Fchangelog\u002F2024\u002F10\u002Fmqtt-service","MQTT Broker Service",{"path":860,"title":861},"\u002Fchangelog\u002F2024\u002F10\u002Fnotifications-bulk-actions","Managing Notifications",{"path":863,"title":864},"\u002Fchangelog\u002F2024\u002F10\u002Fsnapshot-download-upload-options","Snapshot Upload and Download Improvements",{"path":866,"title":505},"\u002Fchangelog\u002F2024\u002F10\u002Fversion-history-timeline",{"path":868,"title":869},"\u002Fchangelog\u002F2024\u002F11\u002Faudit-log-hierarchy","Audit logs show hierarchical events",{"path":871,"title":872},"\u002Fchangelog\u002F2024\u002F11\u002Fdevice-agent-release","Device Agent 3.0 released",{"path":874,"title":875},"\u002Fchangelog\u002F2024\u002F11\u002Fmqtt-topic-hierarchy","MQTT Topic Hierarchy view",{"path":877,"title":878},"\u002Fchangelog\u002F2024\u002F11\u002Fteam-search","Team-wide search",{"path":880,"title":881},"\u002Fchangelog\u002F2024\u002F12\u002Fdashboad-iframe","Allow Dashboards to be embedded in iFrames",{"path":883,"title":884},"\u002Fchangelog\u002F2024\u002F12\u002Fdevice-editor-cache","Device Editor Access Speed Up",{"path":886,"title":887},"\u002Fchangelog\u002F2024\u002F12\u002Fteam-bom-timeline","Team BOM and Pipeline Views",{"path":889,"title":890},"\u002Fchangelog\u002F2025\u002F01\u002Ffree-tier-onboarding","New Onboarding Tour for Free Tier Users",{"path":892,"title":893},"\u002Fchangelog\u002F2025\u002F01\u002Fhidden-env-vars","Hidden Environment Variables",{"path":895,"title":896},"\u002Fchangelog\u002F2025\u002F01\u002Fimproved-diagnostics","Improved Diagnostics",{"path":898,"title":899},"\u002Fchangelog\u002F2025\u002F01\u002Fteam-level-groups","Team level view of Groups",{"path":901,"title":902},"\u002Fchangelog\u002F2025\u002F02\u002Fadditional-device-version-history-events","New Remote Instances Version History Events",{"path":904,"title":905},"\u002Fchangelog\u002F2025\u002F02\u002Fbroker-error-feedback","Improved Broker Connection Feedback",{"path":907,"title":908},"\u002Fchangelog\u002F2025\u002F02\u002Fdevice-agent-updates","FlowFuse User Authentication on Remote Instances",{"path":910,"title":505},"\u002Fchangelog\u002F2025\u002F02\u002Fdevice-version-history-timeline",{"path":912,"title":913},"\u002Fchangelog\u002F2025\u002F02\u002Fexternal-brokers","External MQTT Brokers",{"path":915,"title":916},"\u002Fchangelog\u002F2025\u002F02\u002Fmqtt-schema-suggestions","MQTT Smart Schema Suggestions",{"path":918,"title":919},"\u002Fchangelog\u002F2025\u002F02\u002Fresend-and-extend-team-invitation-expiration","Re-send Team Invitations",{"path":921,"title":922},"\u002Fchangelog\u002F2025\u002F02\u002Fschema-docs","Personalized Schema Documentation",{"path":924,"title":925},"\u002Fchangelog\u002F2025\u002F02\u002Ftopic-hierarchy-search","Search & Filter for Topic Hierarchy List",{"path":927,"title":928},"\u002Fchangelog\u002F2025\u002F03\u002Fcontainer-tags","Changes to tags for flowfuse\u002Fnode-red",{"path":930,"title":931},"\u002Fchangelog\u002F2025\u002F03\u002Fdevice-groups","Multiple Device Groups in a pipeline",{"path":933,"title":934},"\u002Fchangelog\u002F2025\u002F03\u002Fdevice-local-login","Local Login for Remote Instances",{"path":936,"title":937},"\u002Fchangelog\u002F2025\u002F03\u002Ffree-tier","Free Tier now more accessible to all",{"path":939,"title":940},"\u002Fchangelog\u002F2025\u002F03\u002Fresource-notifications","Resource Alerts",{"path":942,"title":943},"\u002Fchangelog\u002F2025\u002F03\u002Fsnapshot-filter","Filtering Snapshots",{"path":945,"title":946},"\u002Fchangelog\u002F2025\u002F03\u002Fteam-npm-registry","NPM Package Hosting",{"path":948,"title":949},"\u002Fchangelog\u002F2025\u002F03\u002Ftopic-deletion","MQTT Topic Management",{"path":951,"title":952},"\u002Fchangelog\u002F2025\u002F04\u002Fdevice-provisioning","Remote Instance Provisioning",{"path":954,"title":955},"\u002Fchangelog\u002F2025\u002F04\u002Fgit-integration","Git Integration with Pipelines",{"path":957,"title":958},"\u002Fchangelog\u002F2025\u002F04\u002Finstance-log-browsing","Better Node-RED log handling",{"path":960,"title":961},"\u002Fchangelog\u002F2025\u002F05\u002Fimport-node-red-flows","Import Node-RED Flows During Remote Instance Setup",{"path":963,"title":964},"\u002Fchangelog\u002F2025\u002F06\u002Fflowfuse-assistant","FlowFuse Expert just got smarter",{"path":966,"title":964},"\u002Fchangelog\u002F2025\u002F06\u002Fflowfuse-assistant-2",{"path":968,"title":969},"\u002Fchangelog\u002F2025\u002F06\u002Fgit-integration","Pulling snapshots from Git with Pipelines",{"path":971,"title":972},"\u002Fchangelog\u002F2025\u002F06\u002Finstance-performance-memory","Memory Metrics in Instance Performance View",{"path":974,"title":975},"\u002Fchangelog\u002F2025\u002F06\u002Fnew-home-page","Introducing the New Home Page Experience",{"path":977,"title":978},"\u002Fchangelog\u002F2025\u002F06\u002Fteam-performance","Team Performance Feature",{"path":980,"title":981},"\u002Fchangelog\u002F2025\u002F06\u002Fteam-performance-view","Instance Performance View",{"path":983,"title":984},"\u002Fchangelog\u002F2025\u002F06\u002Fui-refresh","Navigation UI Refresh",{"path":986,"title":987},"\u002Fchangelog\u002F2025\u002F07\u002Fbrowse-node-red-flows","Browse for Node-RED Flows During Remote Instance Setup",{"path":989,"title":329},"\u002Fchangelog\u002F2025\u002F07\u002Fflowfuse-tables",{"path":991,"title":992},"\u002Fchangelog\u002F2025\u002F07\u002Fimport-blueprints","Import blueprints directly into your existing instances",{"path":994,"title":995},"\u002Fchangelog\u002F2025\u002F07\u002Fsimplified-applications-overview","Simplified Applications Page with Summary Tiles",{"path":997,"title":998},"\u002Fchangelog\u002F2025\u002F07\u002Fsmart-suggestions","Smart Suggestions",{"path":1000,"title":1001},"\u002Fchangelog\u002F2025\u002F07\u002Fteam-to-pro-plan-rename","Team Plan Renamed to Pro Plan",{"path":1003,"title":1004},"\u002Fchangelog\u002F2025\u002F08\u002Fai-generated-snapshot-descriptions-hosted","Generate snapshot descriptions with AI",{"path":1006,"title":1007},"\u002Fchangelog\u002F2025\u002F08\u002Fai-generated-snapshot-descriptions-remote","AI Snapshot Descriptions Now Work with Remote Instances",{"path":1009,"title":1010},"\u002Fchangelog\u002F2025\u002F08\u002Fdevice-performance","FlowFuse Remote Instance Performance Data",{"path":1012,"title":1013},"\u002Fchangelog\u002F2025\u002F08\u002Fdirect-sso","Direct SSO Login",{"path":1015,"title":1016},"\u002Fchangelog\u002F2025\u002F08\u002Fflowfuse-assistant","FlowFuse Expert documents your flows",{"path":1018,"title":1019},"\u002Fchangelog\u002F2025\u002F08\u002Fflowfuse-mqtt","FlowFuse MQTT",{"path":1021,"title":1022},"\u002Fchangelog\u002F2025\u002F08\u002Fhttp-cors","Configure HTTP CORS",{"path":1024,"title":1025},"\u002Fchangelog\u002F2025\u002F08\u002Fsubflow-export","Export SubFlow as Node-RED module",{"path":1027,"title":1028},"\u002Fchangelog\u002F2025\u002F08\u002Ftables-assistant","FlowFuse Tables with a little help from the Assistant",{"path":1030,"title":1031},"\u002Fchangelog\u002F2025\u002F09\u002Fexpose-saml-groups-to-dashboard","Allow SSO groups to be shared with the Node-RED Dashboard",{"path":1033,"title":1034},"\u002Fchangelog\u002F2025\u002F09\u002Finline-assist","FlowFuse Expert can help you write code",{"path":1036,"title":1037},"\u002Fchangelog\u002F2025\u002F09\u002Fretiring-flowforge-device-agent","No more @flowforge\u002Fflowforge-device-agent releases",{"path":1039,"title":1040},"\u002Fchangelog\u002F2025\u002F09\u002Frevised-instance-snapshot-ui","Streamlined Snapshot Management",{"path":1042,"title":1043},"\u002Fchangelog\u002F2025\u002F09\u002Fteam-broker-async-api","Capture Async API data from FlowFuse Team Broker",{"path":1045,"title":1046},"\u002Fchangelog\u002F2025\u002F10\u002Fapplication-level-rbac","Application-level access control for Enterprise teams",{"path":1048,"title":1049},"\u002Fchangelog\u002F2025\u002F10\u002Fbulk-device-group-assignment","Easier Access to Bulk Device Group Management",{"path":1051,"title":1052},"\u002Fchangelog\u002F2025\u002F10\u002Fduplicate-instances-across-applications","Duplicate Instances Across Different Applications",{"path":1054,"title":1055},"\u002Fchangelog\u002F2025\u002F10\u002Fimport-flows-on-instance-creation","Import flows during instance creation",{"path":1057,"title":1058},"\u002Fchangelog\u002F2025\u002F10\u002Fmcp-nodes","FlowFuse MCP Server Nodes",{"path":1060,"title":1061},"\u002Fchangelog\u002F2025\u002F10\u002Fonnx-nodes","FlowFuse AI Nodes",{"path":1063,"title":1064},"\u002Fchangelog\u002F2025\u002F10\u002Fsettings-page-device-group-management","Device Group Management from Settings Page",{"path":1066,"title":1067},"\u002Fchangelog\u002F2025\u002F11\u002Fff-expert-update","FlowFuse Expert Update",{"path":1069,"title":1070},"\u002Fchangelog\u002F2025\u002F11\u002Fminimum-nodejs-version","Node.js v20 Minimum Version Requirement",{"path":1072,"title":1073},"\u002Fchangelog\u002F2025\u002F11\u002Fsso-session","SSO control over Session life",{"path":1075,"title":1076},"\u002Fchangelog\u002F2025\u002F12\u002Fff-expert-mcp-insights","FlowFuse Expert: Now with MCP-Powered Insights",{"path":1078,"title":1079},"\u002Fchangelog\u002F2025\u002F12\u002Fscheduled-maintenance","Scheduled Maintenance Mode",{"path":1081,"title":1082},"\u002Fchangelog\u002F2026\u002F01\u002Fdevice-agent-containers","Device Agent Docker Containers updated",{"path":1084,"title":1085},"\u002Fchangelog\u002F2026\u002F01\u002Fff-expert-manage-palette","FlowFuse Expert: Enhanced Palette Integration",{"path":1087,"title":1088},"\u002Fchangelog\u002F2026\u002F01\u002Fff-expert-nr-actions","FlowFuse Expert: Integration with Node-RED",{"path":1090,"title":1091},"\u002Fchangelog\u002F2026\u002F01\u002Fff-expert-palette-queries","FlowFuse Expert: Palette Queries",{"path":1093,"title":1094},"\u002Fchangelog\u002F2026\u002F01\u002Fff-expert-select-flows","FlowFuse Expert: Ask about your flows",{"path":1096,"title":1097},"\u002Fchangelog\u002F2026\u002F01\u002Fmcp-rbacs","FlowFuse Expert: MCP-Powered Insights with RBACs",{"path":1099,"title":1100},"\u002Fchangelog\u002F2026\u002F01\u002Fmcp-security","FlowFuse Expert: MCP-Powered Insights",{"path":1102,"title":1103},"\u002Fchangelog\u002F2026\u002F02\u002Fdevice-agent-nodejs-options","Set Node.js Options for Remote Instances",{"path":1105,"title":1106},"\u002Fchangelog\u002F2026\u002F02\u002Fff-expert-debug-log-context","FlowFuse Expert: Helping you make sense of your debug log",{"path":1108,"title":1109},"\u002Fchangelog\u002F2026\u002F02\u002Fff-expert-update-banner","FlowFuse Expert: Never Miss an Update",{"path":1111,"title":1112},"\u002Fchangelog\u002F2026\u002F02\u002Fha-instance-rolling-restart","HA Hosted Instance Rolling Restart",{"path":1114,"title":1115},"\u002Fchangelog\u002F2026\u002F02\u002Fremote-instances-immersive-editor","Immersive Mode for Remote Instances",{"path":1117,"title":1118},"\u002Fchangelog\u002F2026\u002F02\u002Frestoring-snapshots-to-remote-instances","Restoring snapshots to developer-mode Remote Instances",{"path":1120,"title":1121},"\u002Fchangelog\u002F2026\u002F03\u002Fazure-dev-ops-gitops","Azure DevOps Pipeline support",{"path":1123,"title":1124},"\u002Fchangelog\u002F2026\u002F03\u002Fdeveloper-mode-in-immersive-editor","Developer Mode Now Accessible from the Immersive Editor",{"path":1126,"title":1127},"\u002Fchangelog\u002F2026\u002F03\u002Fembedded-editor-tab-title","Embedded Editor Now Shows Active Tab",{"path":1129,"title":1130},"\u002Fchangelog\u002F2026\u002F03\u002Fmarch-scheduled-maintenance","Updated: Upcoming Scheduled Server Maintenance on March 28th, 2026",{"path":1132,"title":1133},"\u002Fchangelog\u002F2026\u002F03\u002Fsnapshot-detail-modal-immersive-editor","View Snapshot Details in the Immersive Editor",{"path":1135,"title":1136},"\u002Fchangelog\u002F2026\u002F04\u002Fexpert-action-links","FlowFuse expert action links",{"path":1138,"title":1139},"\u002Fchangelog\u002F2026\u002F04\u002Fhosted-instance-url-env-var","Hosted Instances know their own URL",{"path":1141,"title":398},"\u002Fchangelog\u002F2026\u002F04\u002Fimmersive-editor-drawer",{"path":1143,"title":1144},"\u002Fchangelog\u002F2026\u002F04\u002Fsnapshot-diff-viewer","Richer snapshot comparison view",{"path":1146,"title":1147},"\u002Fchangelog\u002F2026\u002F05\u002Fai-opt-out","AI Feature Opt-Out for Teams",{"path":1149,"title":1150},"\u002Fchangelog\u002F2026\u002F05\u002Fexpert-application-building","FlowFuse Expert Builds Your Application",{"path":1152,"title":1153},"\u002Fchangelog\u002F2026\u002F05\u002Fsingle-sso-provider","Single SSO provider for all users",{"path":1155,"title":1156},"\u002Fchangelog\u002F2026\u002F06\u002Fdark-mode","Dark Mode",{"path":1158,"title":1159},"\u002Fchangelog\u002F2026\u002F06\u002Fdevice-agent-v4-released","Device Agent v4 released",{"path":1161,"title":1162},"\u002Fchangelog\u002F2026\u002F06\u002Fgeneric-git-server-support","Connect Pipelines to Any Git Server",{"path":1164,"title":1165},"\u002Fchangelog\u002F2026\u002F06\u002Fjuly-scheduled-maintenance","Updated: Upcoming Scheduled Server Maintenance on July 11th, 2026",{"path":1167,"title":1168},"\u002Fchangelog\u002F2026\u002F07\u002Fapplication-sso-groups","Application Roles from SSO Groups",{"path":1170,"title":1171},"\u002Fchangelog\u002F2026\u002F07\u002Fdevice-agent-onboarding","Getting started with FlowFuse straight from the terminal",{"path":1173,"title":1174},"\u002Fchangelog\u002F2026\u002F07\u002Fexpert-enhancements","FlowFuse Expert Enhancements",{"path":1176,"title":1177},"\u002Fchangelog\u002F2026\u002F07\u002Fexpert-tables-automation","FlowFuse Expert Can Now Work With Your Tables",{"path":1179,"title":1180},"\u002Fchangelog\u002F2026\u002F07\u002Fscoped-pats","Team Scoped Personal Access Tokens",{"path":1182,"title":1183},"\u002Fchangelog\u002F2026\u002F07\u002Fteam-and-application-dashboards","A Dedicated Home for Your Dashboards",[],1786105901938]