[{"data":1,"prerenderedAt":1594},["ShallowReactive",2],{"blog-\u002Fblog\u002F2026\u002F06\u002Fopc-ua-security-best-practices":3,"featureCatalog":664,"changelog-titles":1059,"blog-all-for-related":1593},{"id":4,"title":5,"authors":6,"body":8,"cta":641,"date":645,"description":646,"extension":647,"features":648,"image":649,"lastUpdated":648,"meta":650,"navigation":652,"path":653,"release":648,"seo":654,"sitemap":655,"stem":656,"subtitle":657,"tags":658,"tldr":662,"video":648,"__hash__":663},"blog\u002Fblog\u002F2026\u002F06\u002Fopc-ua-security-best-practices.md","OPC UA Security: How to Establish a Defensible OPC UA Security Architecture",[7],"sumit-shinde",{"type":9,"value":10,"toc":626},"minimark",[11,21,24,29,41,49,52,76,79,89,93,96,112,121,128,131,159,162,171,175,182,185,209,216,225,244,262,269,273,276,290,313,334,352,356,373,376,399,406,410,413,416,419,457,467,489,498,501,509,513,520,527,531,538,541,545,548,566,569,573,576,623],[12,13,14,15,20],"p",{},"In ",[16,17,19],"a",{"href":18},"\u002Fblog\u002F2026\u002F05\u002Fopc-ua-security-attack-vectors\u002F","Part 1",", we watched how threat actors actually exploit OPC UA. None of it was broken cryptography. It was disabled trust lists, anonymous logins, dead ciphers nobody removed, and servers Shodan finds on the open internet. The protocol shipped with the tools to stop every one. The attacks worked because the tools were switched off.",[12,22,23],{},"This is the part where we switch them on, not as a checklist, but as an architecture where each decision closes a specific vector from Part 1. The order matters, because the cheapest fixes close the widest holes.",[25,26,28],"h2",{"id":27},"the-model-that-decides-everything-else","The model that decides everything else",[12,30,31,32,36,37,40],{},"Part 1 named the trap that sinks more deployments than any zero-day: OPC UA splits ",[33,34,35],"em",{},"application"," authentication (does the server trust this client's certificate?) from ",[33,38,39],{},"user"," authentication (who is this operator, and what may they do?). Teams harden one, leave the other open, and believe they're covered.",[12,42,43,44,48],{},"The reason this confuses people is that OPC UA secures the ",[45,46,47],"strong",{},"messages themselves",", not just the transport beneath them. A transport-only scheme like TLS protects the pipe between two hosts; OPC UA signs and encrypts each message independently of the transport, so a receiver detects a tampered process value even on a hostile network and even if the transport is something other than TLS. Application authentication and message security are layers in their own right, sitting above whatever carries the bytes.",[12,50,51],{},"Two facts fall out of this, and both map straight to Part 1's attacks:",[53,54,55,66],"ul",{},[56,57,58,61,62,65],"li",{},[45,59,60],{},"Every application instance has its own certificate",", not every host, every ",[33,63,64],{},"running process",". A Node-RED client, a SCADA server, and a historian on the same box each carry their own.",[56,67,68,71,72,75],{},[45,69,70],{},"Authentication is mutual."," Both sides present a certificate, both sides decide whether to trust. There is no \"the server has a cert, the client just connects\" shortcut like HTTPS. The machine-in-the-middle attacks CISPA demonstrated work ",[33,73,74],{},"precisely"," when that mutual check is advertised but not enforced.",[12,77,78],{},"Hold onto the second point. Almost every control below is a way of making that mutual check real instead of decorative.",[12,80,81,86],{},[82,83],"img",{"alt":84,"src":85},"Application authentication and user authentication are two separate checks on the same OPC UA session.","\u002Fblog\u002F2026\u002F06\u002Fimages\u002Fopcua-application-vs-user-authentication.png",[33,87,88],{},"OPC UA authenticates the software and the operator as two separate checks, not one.",[25,90,92],{"id":91},"stop-accepting-inbound-connections-at-all","Stop accepting inbound connections at all",[12,94,95],{},"Part 1 opened with the worst number: 14,220 internet-exposed servers, more than half allowing unauthenticated access. The instinct is to bolt authentication onto an exposed server. The better move is to stop the server from accepting inbound connections in the first place.",[12,97,98,99,102,103,106,107,111],{},"OPC UA has a protocol feature built for exactly this, and most \"best practices\" posts never mention it: ",[45,100,101],{},"Reverse Connect",". Normally a client opens the TCP connection to a server. Reverse Connect inverts that, the ",[33,104,105],{},"server"," dials out to the client and sends a ",[108,109,110],"code",{},"ReverseHello"," message (OPC UA Part 6), and the client establishes the secure channel over that server-initiated socket. The handshake and all mutual authentication proceed exactly as before; only the direction of the initial TCP connection flips.",[12,113,114,118],{},[82,115],{"alt":116,"src":117},"Traditional connect requires an open inbound port; Reverse Connect has the server dial out so the firewall stays closed.","\u002Fblog\u002F2026\u002F06\u002Fimages\u002Fopcua-reverse-connect-vs-traditional.png",[33,119,120],{},"Reverse Connect inverts the initial TCP connection so the firewall stays closed. Only the socket origin flips, the client still drives the OPC UA session.",[12,122,123,124,127],{},"Why this matters architecturally: the server sits in the production zone behind a firewall with ",[45,125,126],{},"no inbound ports open",". From the firewall's perspective the traffic is outbound, the one direction it already permits. A SCADA client or edge gateway in the DMZ listens on a single port; each downstream server connects out to it. You get bidirectional OPC UA communication while the production-network firewall stays completely closed to the outside.",[12,129,130],{},"This is the structural fix that makes Part 1's exposure problem disappear rather than merely guarding it. Layer it inside normal defense in depth, the zone-and-conduit segmentation IEC 62443 calls for:",[53,132,133,143,149],{},[56,134,135,138,139,142],{},[45,136,137],{},"Segment the network."," Control network separate from enterprise, firewalls between zones. A typical layout: ",[108,140,141],{},"SignAndEncrypt"," from the enterprise zone (historians, MES, ERP), through a DMZ of edge gateways and protocol bridges, down to a plant floor where PLCs and HMIs sit on isolated VLANs.",[56,144,145,148],{},[45,146,147],{},"Put a security gateway in the DMZ."," A gateway can terminate Reverse Connect on both sides and act as the single, aggregating access point to the plant, the only door, and one you control.",[56,150,151,154,155,158],{},[45,152,153],{},"Keep the single-port design as leverage, not a license."," OPC UA's standard TCP 4840 keeps firewall rules clean. Clean rules are what let you ",[33,156,157],{},"not"," expose the server, not an excuse to.",[12,160,161],{},"Vendors agree on the bottom line. Siemens, Schneider, and Rockwell all explicitly advise against putting these servers on the open internet. Reverse Connect is how you comply without losing IT\u002FOT data flow.",[12,163,164,168],{},[82,165],{"alt":166,"src":167},"A segmented network with Enterprise, DMZ, and Plant Floor zones separated by firewalls, with SignAndEncrypt links between them.","\u002Fblog\u002F2026\u002F06\u002Fimages\u002Fopcua-defense-in-depth-network-zones.png",[33,169,170],{},"OPC UA security sits inside a segmented, defense-in-depth network.",[25,172,174],{"id":173},"make-the-trust-list-actually-enforce","Make the trust list actually enforce",[12,176,177,178,181],{},"This was Part 1's ugliest vector, because the servers ",[33,179,180],{},"look"," secure, they advertise certificate authentication, they just don't enforce it. CISPA tested 48 products and found the failures clustered in trust list handling: missing support, disabled by default, insecure configuration. Here is how the trust check works, and the two settings that quietly defeat it.",[12,183,184],{},"When a peer presents a certificate, a correct implementation validates it against three local stores:",[53,186,187,193,199],{},[56,188,189,192],{},[45,190,191],{},"Trusted store",", certificates (or a CA root) you've explicitly chosen to trust.",[56,194,195,198],{},[45,196,197],{},"Issuer store",", intermediate and root CA certificates plus their Certificate Revocation Lists (CRLs), used to walk and verify the chain.",[56,200,201,204,205,208],{},[45,202,203],{},"Rejected store",", where unknown certificates land on first contact, ",[33,206,207],{},"pending an administrator's decision",". Nothing here is trusted.",[12,210,211,212,215],{},"The intended workflow is deliberate friction: an unknown peer's certificate drops into the rejected store, an administrator inspects it, and only then moves it to trusted. That manual approval ",[33,213,214],{},"is"," the security. Two things destroy it:",[12,217,218,222],{},[82,219],{"alt":220,"src":221},"Flowchart: a presented certificate is checked for trust, its chain validated, and accepted or refused, with admin approval promoting rejected certificates for the next connection.","\u002Fblog\u002F2026\u002F06\u002Fimages\u002Fopcua-certificate-trust-validation-flow.png",[33,223,224],{},"Trust nothing by default: certificates enter the trusted store only by explicit approval.",[226,227,228,234],"ol",{},[56,229,230,233],{},[45,231,232],{},"\"Automatically accept all certificates.\""," Almost every server has this toggle, Siemens TIA Portal, node tooling, test harnesses. It's there to get you past the handshake during commissioning, and it is the single most common reason a \"secure\" connection is actually wide open. A server set to auto-accept has, in effect, the disabled trust list from Part 1. This default is common enough that even purpose-built Node-RED OPC UA clients often ship with server certificates auto-accepted out of the box, convenient for testing, dangerous in production. Turn it off before production. Every time.",[56,235,236,239,240,243],{},[45,237,238],{},"Trusting a commercial public CA's root."," If you drop a public CA into your trusted store, that CA, not you, decides which applications your systems trust. For OPC UA you want a ",[45,241,242],{},"company-specific CA"," whose root you control, or explicit per-application trust. Never a public one.",[12,245,246,247,249,250,253,254,257,258,261],{},"The concrete mechanic trips up everyone the first time, so it's worth being literal. To let a Node-RED OPC UA client talk to a Siemens S7 server over ",[108,248,141],{},", you copy the client's certificate (in node-based tooling it's typically ",[108,251,252],{},"PKI\u002Fown\u002Fcerts\u002Fclient_certificate.pem",") into the ",[33,255,256],{},"server's"," trusted folder, and copy the server's certificate into the ",[33,259,260],{},"client's"," trusted store. Both ends, both directions, because authentication is mutual. Miss one side and you get the \"connection could not be established\" error that fills the Node-RED forums, almost always because one party doesn't yet trust the other.",[12,263,264,265,268],{},"The governing rule: ",[45,266,267],{},"trust nothing by default."," A certificate enters the trusted store only through explicit, human approval. That is the control CISPA kept finding switched off.",[25,270,272],{"id":271},"force-signandencrypt-and-rip-the-deprecated-ciphers-out","Force SignAndEncrypt, and rip the deprecated ciphers out",[12,274,275],{},"Part 1's Secura research and the CVEs behind it all traced to one root cause: known-weak crypto left switched on in non-default configurations. You close this by removing the option, not by hoping nobody selects it.",[12,277,278,281,282,285,286,289],{},[45,279,280],{},"Set the security mode deliberately."," Endpoints advertise a ",[33,283,284],{},"mode"," and a ",[33,287,288],{},"policy",". The mode is one of three:",[53,291,292,298,304],{},[56,293,294,297],{},[108,295,296],{},"None",", no signing, no encryption, everything in plaintext. This is the \"None\" mode 80% of Part 1's exposed servers still offered. Disable it, or bind it to localhost-only diagnostics.",[56,299,300,303],{},[108,301,302],{},"Sign",", every message signed but not encrypted. Integrity and authenticity without confidentiality. Use only where you've consciously decided the data is non-sensitive but you still must detect a forged value.",[56,305,306,308,309,312],{},[108,307,141],{},", signed ",[33,310,311],{},"and"," encrypted: integrity, authenticity, and confidentiality together. The answer for anything carrying process data or accepting commands.",[12,314,315,318,319,322,323,326,327,329,330,333],{},[45,316,317],{},"Then remove the dead policies."," ",[108,320,321],{},"Basic128Rsa15"," and ",[108,324,325],{},"Basic256"," are deprecated, the OPC Foundation retired them in spec 1.04 because they lean on SHA-1 and RSA key lengths that no longer meet NIST or BSI guidance, and IEC 62443 and the NIST CSF explicitly flag them. ",[108,328,321],{}," is the exact policy behind Part 1's CVE-2024-42512 and CODESYS's CVE-2025-1468 Bleichenbacher oracle. If a server ",[33,331,332],{},"only"," offers these, that's a firmware-update conversation, not a config tweak.",[12,335,336,337,340,341,344,345,348,349,351],{},"For anything new, ",[108,338,339],{},"Basic256Sha256"," is the floor; the modern policies ",[108,342,343],{},"Aes128_Sha256_RsaOaep"," (faster) and ",[108,346,347],{},"Aes256_Sha256_RsaPss"," (strongest available) are better. The trade-off is backward compatibility, older devices won't speak the newer suites, so the realistic migration is ",[108,350,339],{}," as the enforced minimum while you push the fleet forward and decommission the deprecated suites as you go. The point is that an attacker can't downgrade to a broken cipher you've physically removed.",[25,353,355],{"id":354},"separate-who-the-software-is-from-who-the-operator-is","Separate who-the-software-is from who-the-operator-is",[12,357,358,359,362,363,366,367,369,370,372],{},"Application authentication, handled above, proves ",[33,360,361],{},"which software"," connected. It says nothing about ",[33,364,365],{},"who"," is driving the session. Part 1's anonymous-access vector only fully closes when you enforce both layers, and as Part 1 noted, anonymous ",[33,368,39],{}," access is far less dangerous when ",[33,371,35],{}," authentication is genuinely enforced, and far more dangerous when it isn't.",[12,374,375],{},"User authentication options, weakest to strongest:",[53,377,378,384,393],{},[56,379,380,383],{},[45,381,382],{},"Anonymous",", acceptable only for read-only, non-sensitive dashboards. Never write access, never diagnostics.",[56,385,386,389,390,392],{},[45,387,388],{},"Username \u002F password",", fine, but only over a ",[108,391,141],{}," endpoint, or you've just shipped credentials in plaintext.",[56,394,395,398],{},[45,396,397],{},"User X.509 certificate",", strongest, and the natural fit for machine-to-machine.",[12,400,401,402,405],{},"Then constrain what an authenticated identity can do. Implement ",[45,403,404],{},"role-based access control from day one."," Running every application with administrator rights is the oversized blast radius Part 1 warned about, one compromise and the attacker owns the read-and-write path to the process. Assign read, write, and browse separately, per role, least privilege. If a server can't enforce granular access itself, put a gateway in front that can.",[25,407,409],{"id":408},"manage-certificates-like-infrastructure-not-a-one-time-chore","Manage certificates like infrastructure, not a one-time chore",[12,411,412],{},"The trust mechanics above assume certificates that are valid, unique, and revocable. At one connection, manual exchange is fine. At a hundred it collapses, and that collapse is what produces the 20-year self-signed certs and shared keys Part 1 punished.",[12,414,415],{},"Every instance holds an X.509 v3 Application Instance Certificate (IEC 62541 Part 2): application URI as a globally unique ID, public key, issuer identity, validity window, issuer signature. The private key stays secret on the instance, leak it and that certificate must be revoked and replaced, the precise consequence CODESYS described for the Bleichenbacher oracle.",[12,417,418],{},"Non-negotiables regardless of scale:",[53,420,421,427,433,439,445,451],{},[56,422,423,426],{},[45,424,425],{},"One certificate per instance."," Share a certificate and revoking it after one compromise takes down every instance that shared it.",[56,428,429,432],{},[45,430,431],{},"2048-bit RSA minimum",", 4096-bit for long-lived (5+ year) certificates.",[56,434,435,438],{},[45,436,437],{},"SAN must match the application URI exactly",", or validation fails in maddening, hard-to-diagnose ways.",[56,440,441,444],{},[45,442,443],{},"Track expiry like any operational asset."," Field certs carry absurd multi-decade lifetimes precisely because nobody wants to renew. That's deferral, not security. Reminder 60 days out.",[56,446,447,450],{},[45,448,449],{},"Handle CRLs."," A trust store without working revocation can't respond to a compromise.",[56,452,453,456],{},[45,454,455],{},"Protect the private-key store",", read\u002Fwrite to an administrator or the application only.",[12,458,459,462,463,466],{},[45,460,461],{},"Automate before it hurts."," A ",[45,464,465],{},"Global Discovery Server (GDS)"," with certificate management acts as your CA and directory, issuing, renewing, and revoking across the fleet over standard PKI protocols (CMP, EST) so you're not vendor-locked. It works two ways:",[53,468,469,475],{},[56,470,471,474],{},[45,472,473],{},"Pull management",", the application (usually a client) calls the GDS to request and refresh its own certificate and trust list. It owns keeping itself current.",[56,476,477,480,481,484,485,488],{},[45,478,479],{},"Push management",", the GDS pushes new certificates and trust lists ",[33,482,483],{},"to"," the application (usually a server), which exposes the methods for it. Push requires an encrypted channel and a client holding the ",[108,486,487],{},"SecurityAdmin"," role, and the GDS will only deliver an update over a channel at least as strong as the certificate being updated, it won't push a 4096-bit cert down a 2048-bit channel.",[12,490,491,495],{},[82,492],{"alt":493,"src":494},"A Global Discovery Server issuing certificates two ways: applications pull their own, or the GDS pushes certificates and trust lists to servers.","\u002Fblog\u002F2026\u002F06\u002Fimages\u002Fopcua-gds-push-pull-certificate-management.png",[33,496,497],{},"A GDS automates certificate issuance, renewal, and revocation across the fleet.",[12,499,500],{},"One field tip even with a GDS: keep a local rejected-certificate store on each application, so you can still see and reason about what tried to connect.",[12,502,503,504,508],{},"If you're building this on FlowFuse, the OPC UA connectivity is available as one of the Certified Nodes introduced in ",[16,505,507],{"href":506},"\u002Fblog\u002F2026\u002F06\u002Fflowfuse-release-2-31\u002F","FlowFuse 2.31",", vetted and FlowFuse-supported rather than pulled unmaintained from the community registry, which is the supply-chain point above made concrete. As with any OPC UA client, confirm it's set to reject untrusted server certificates before you go to production rather than auto-accepting them.",[25,510,512],{"id":511},"keep-the-audit-trail-on-and-watched","Keep the audit trail on, and watched",[12,514,515,516,519],{},"Part 1's quietest, most damning detail: most anonymously reachable servers also had auditing ",[33,517,518],{},"disabled",", so an attacker connected, read the plant, and left no trace. A silent denial-of-service and a client-side compromise both get worse when nothing is watching.",[12,521,522,523,526],{},"OPC UA emits rich audit events for security-relevant operations. Turn them on, then make sure something ",[33,524,525],{},"collects and watches"," them, events nobody reads are theatre. This is what turns an undetected man-in-the-middle into an alert and a silent DoS into an incident with a timeline.",[25,528,530],{"id":529},"patch-the-stack-and-especially-the-gateways","Patch the stack, and especially the gateways",[12,532,533,534,537],{},"Part 1 closed on a supply-chain truth: one flaw in a shared OPC UA library or sample propagates into every product built on it, and integration servers are rich targets because vulnerabilities ",[33,535,536],{},"chain",", Team82 strung five bugs together to own a Softing gateway.",[12,539,540],{},"So architecture doesn't end at configuration. Track CVEs for your specific stack and gateways. Subscribe to the OPC Foundation security bulletins and your vendors' advisories. Patch the integration servers stitching systems together with the same urgency as the servers themselves, owning one reaches everything behind it. And because the client trusts the server, a client fed bad data by a rogue server is its own vector (Part 1's client-side RCE): client-side updates matter as much as server-side.",[25,542,544],{"id":543},"test-what-you-think-you-built","Test what you think you built",[12,546,547],{},"The step everyone skips. Verify configuration matches policy:",[53,549,550,557,563],{},[56,551,552,553,556],{},"Connect ",[33,554,555],{},"without"," a valid certificate, does the server actually reject it, or is auto-accept still on?",[56,558,559,560,562],{},"Read and write ",[33,561,555],{}," authorization, does RBAC actually deny it?",[56,564,565],{},"Point a security testing tool at your endpoints and confirm the advertised modes match the enforced ones.",[12,567,568],{},"A trust store you've never tested is a hypothesis, not a control, and Part 1 is a catalogue of deployments where the hypothesis was wrong.",[25,570,572],{"id":571},"the-blueprint-in-one-breath","The blueprint, in one breath",[12,574,575],{},"Every vector in Part 1 had the same root cause: a tool OPC UA handed you that nobody switched on. The architecture is switching them on, in the order of biggest hole for least effort:",[226,577,578,584,590,596,602,608,613,618],{},[56,579,580,583],{},[45,581,582],{},"Reverse Connect + segmentation",", the server stops accepting inbound connections; the firewall stays closed.",[56,585,586,589],{},[45,587,588],{},"Enforcing trust list, auto-accept off, company CA",", the mutual check becomes real instead of decorative.",[56,591,592,595],{},[45,593,594],{},"SignAndEncrypt, deprecated ciphers removed",", no cipher to downgrade to.",[56,597,598,601],{},[45,599,600],{},"User auth + RBAC on top of application auth",", both layers, least privilege.",[56,603,604,607],{},[45,605,606],{},"One cert per instance, GDS-managed lifecycle",", valid, unique, revocable, at scale.",[56,609,610],{},[45,611,612],{},"Auditing on and watched.",[56,614,615],{},[45,616,617],{},"Stack and gateways patched.",[56,619,620],{},[45,621,622],{},"Tested against the policy, not the assumption.",[12,624,625],{},"OPC UA shipped with the strongest security model in industrial protocols. Part 1 showed what it looks like switched off. This is what it looks like switched on, and where FlowFuse fits is making it the default rather than the project: data pulled off exposed, internet-facing servers into a managed, segmented architecture where Reverse Connect, enforced trust, and least-privilege access are how the system is built, not a hardening pass you hope someone remembers to run.",{"title":627,"searchDepth":628,"depth":628,"links":629},"",4,[630,632,633,634,635,636,637,638,639,640],{"id":27,"depth":631,"text":28},2,{"id":91,"depth":631,"text":92},{"id":173,"depth":631,"text":174},{"id":271,"depth":631,"text":272},{"id":354,"depth":631,"text":355},{"id":408,"depth":631,"text":409},{"id":511,"depth":631,"text":512},{"id":529,"depth":631,"text":530},{"id":543,"depth":631,"text":544},{"id":571,"depth":631,"text":572},{"type":642,"title":643,"description":644},"contact","Make the secure setup the default, not the project","Everything above is an architecture you can configure by hand, but it's easier when the platform starts you in the right place. FlowFuse connects your OPC UA servers and lets you build dashboards and logic on that data with low-code, with an AI copilot that builds the flows for you from a prompt. Its OPC UA connectivity ships as a Certified Node, vetted and supported rather than pulled unmaintained from the community registry, with secure trust handling built in rather than bolted on. Talk to our team about your OT connectivity.","2026-06-05","Turn every OPC UA attack vector into a configuration decision you control: Reverse Connect to keep the firewall closed, enforced trust lists, SignAndEncrypt, GDS certificate management, RBAC, and the field anti-patterns that quietly undo all of it.","md",null,"\u002Fblog\u002F2026\u002F06\u002Fimages\u002Fopc-ua-security.png",{"keywords":651},"opc ua security, opc ua security architecture, opc ua reverse connect, opc ua certificate management, opc ua trust list, opc ua gds, opc ua signandencrypt, opc ua rbac, defensible opc ua, opc ua best practices, industrial security, iiot security",true,"\u002Fblog\u002F2026\u002F06\u002Fopc-ua-security-best-practices",{"title":5,"description":646},{"loc":653},"blog\u002F2026\u002F06\u002Fopc-ua-security-best-practices","Part 1 showed how attackers walk in. This is the blueprint that locks every door behind them.",[659,660,661],"post","opcua","security","A defensible OPC UA architecture is a handful of decisions, each closing a known attack vector. Use Reverse Connect and network segmentation so the server accepts no inbound connections and the firewall stays closed. Force SignAndEncrypt with a modern policy and remove the deprecated Basic128Rsa15 and Basic256 ciphers. Make the trust list enforce and turn off 'auto-accept all certificates.' Issue one certificate per instance from a company CA, automated through a GDS at scale. Layer user authentication and RBAC on top of application authentication. Keep auditing on and watched, patch the stack and gateways, then test that what you configured is what is actually running.","V3qlONMo7nIzratdqNwExplofos0ozYWcxG6-CAb8Tk",{"id":665,"extension":666,"meta":667,"sections":668,"stem":1057,"__hash__":1058},"featureCatalog\u002Ffeature-catalog.yml","yml",{},[669,720,821,883,960,1039],{"id":670,"title":671,"features":672},"ai-automation","AI & Automation",[673,683,693,703,709,715],{"id":674,"title":675,"description":676,"docsLink":677,"changelog":678,"tiers":682},"flowfuse-expert-ai","FlowFuse Expert AI","Build industrial apps with agents, and query the state of the factory with an agent. Adapt your current hardware and machines so agentic work can be done against them, without ripping and replacing what's already on the plant floor.","\u002Fdocs\u002Fuser\u002Fexpert\u002F",[679],{"url":680,"release":681},"\u002Fchangelog\u002F2026\u002F02\u002Fff-expert-update-banner\u002F","2.28",{"edge":652,"hub":652,"fleet":652},{"id":684,"title":685,"description":686,"docsLink":687,"changelog":688,"subfeature":652,"showOnPricing":691,"tiers":692},"flowfuse-expert-support-mode","Support Mode","Chat-based assistance for FlowFuse and Node-RED, including Node-RED instance management through natural language.","\u002Fdocs\u002Fuser\u002Fexpert\u002Fchat\u002F#support-mode",[689],{"url":690,"release":681},"\u002Fchangelog\u002F2026\u002F02\u002Fff-expert-debug-log-context\u002F",false,{"edge":652,"hub":652,"fleet":652},{"id":694,"title":695,"description":696,"docsLink":697,"changelog":698,"subfeature":652,"showOnPricing":691,"tiers":702},"flowfuse-expert-application-building","Application Building","Describe what you want to build and FlowFuse Expert assembles it on your workspace, adding tabs, wiring nodes, and configuring properties.","\u002Fdocs\u002Fuser\u002Fexpert\u002Fchat\u002F",[699],{"url":700,"release":701},"\u002Fchangelog\u002F2026\u002F05\u002Fexpert-application-building\u002F","2.30",{"edge":652,"hub":652,"fleet":652},{"id":704,"title":705,"description":706,"docsLink":707,"subfeature":652,"beta":652,"showOnPricing":691,"tiers":708},"flowfuse-expert-insights-mode","Insights Mode","Connects FlowFuse Expert to MCP servers in your Node-RED instances, enabling real-time data queries and actions through a single chat interface.","\u002Fdocs\u002Fuser\u002Fexpert\u002Fchat\u002F#insights-mode",{"edge":652,"hub":652,"fleet":652},{"id":710,"title":711,"description":712,"docsLink":713,"tiers":714},"mcp-servers","Agentic Operations","Expose your Node-RED flows as tools an AI agent can call directly, so agents can query the state of the factory or trigger actions without custom integration work.","\u002Fnode-red\u002Fflowfuse\u002Fmcp\u002F",{"edge":652,"hub":652,"fleet":652},{"id":716,"title":717,"description":718,"tiers":719},"onnx-integration","ONNX Integration","Run trained machine learning models directly in your flows, including on edge hardware, without sending data out to an external inference service.",{"edge":652,"hub":652,"fleet":652},{"id":721,"title":722,"features":723},"build","Build",[724,730,736,746,752,758,762,768,774,782,788,792,796,805,813],{"id":725,"title":726,"description":727,"docsLink":728,"tiers":729},"edge-development","Edge Development","Develop and test Node-RED flows directly on edge devices with a remote editor proxy.","\u002Fdocs\u002Fdevice-agent\u002Fquickstart\u002F",{"edge":652,"hub":691,"fleet":652},{"id":731,"title":732,"description":733,"docsLink":734,"tiers":735},"private-npm-registry","Custom Node-RED Nodes","Create and manage your own private npm registry for Node-RED nodes, so you can share custom nodes across your team and devices without publishing them publicly.","\u002Fdocs\u002Fuser\u002Fcustom-npm-packages\u002F",{"edge":652,"hub":652,"fleet":652},{"id":737,"title":738,"description":739,"docsLink":740,"changelog":741,"tiers":745},"flowfuse-tables","FlowFuse Tables","A managed PostgreSQL database for every application, so you can store and query structured data without standing up and maintaining your own database.","\u002Fdocs\u002Fuser\u002Fff-tables\u002F",[742],{"url":743,"release":744},"\u002Fchangelog\u002F2026\u002F07\u002Fexpert-tables-automation\u002F","2.33",{"edge":652,"hub":652,"fleet":652},{"id":747,"title":748,"description":749,"docsLink":750,"tiers":751},"persistent-files","File Storage","Store and retrieve files from your Node-RED flows, with automatic replication and backup across your devices and hosted instances.","\u002Fdocs\u002Finstall\u002Ffile-storage\u002F",{"edge":652,"hub":652,"fleet":652},{"id":753,"title":754,"description":755,"docsLink":756,"showOnPricing":691,"tiers":757},"persistent-context","Persistent Context","In-memory values defined in a Node-RED flow persist across project restarts and upgrades.","\u002Fdocs\u002Fuser\u002Fpersistent-context\u002F",{"edge":652,"hub":652,"fleet":652},{"id":759,"title":760,"showOnPricing":691,"tiers":761},"static-assets","Static Assets",{"edge":652,"hub":652,"fleet":652},{"id":763,"title":764,"description":765,"docsLink":766,"tiers":767},"team-library","Team Library","Set up standard nodes and flows that can be shared with all team members across your organisation.","\u002Fdocs\u002Fuser\u002Fshared-library\u002F",{"edge":652,"hub":652,"fleet":652},{"id":769,"title":770,"description":771,"docsLink":772,"tiers":773},"personalised-multi-user-dashboards","Personalised Multi-User Dashboards","Build applications that provide unique data to each logged-in user using personalised multi-user dashboards.","https:\u002F\u002Fdashboard.flowfuse.com\u002Fuser\u002Fmulti-tenancy.html",{"edge":652,"hub":652,"fleet":652},{"id":775,"title":776,"description":777,"changelog":778,"subfeature":652,"showOnPricing":691,"tiers":781},"dashboards-view","Dashboards View","Browse and open every dashboard across your team from a dedicated Dashboards view, at both team and application level, without leaving FlowFuse.",[779],{"url":780,"release":744},"\u002Fchangelog\u002F2026\u002F07\u002Fteam-and-application-dashboards\u002F",{"edge":652,"hub":652,"fleet":652},{"id":783,"title":784,"description":785,"docsLink":786,"tiers":787},"blueprints-converge","Blueprints","Ready-made starting points for your apps, from cross-team Converge templates to OT and IT specific blueprints.","\u002Fdocs\u002Fuser\u002Fconcepts\u002F#blueprint",{"edge":652,"hub":652,"fleet":652},{"id":789,"title":790,"subfeature":652,"showOnPricing":691,"tiers":791},"blueprints-ot-apps","Blueprints - OT APPS",{"edge":652,"hub":691,"fleet":652},{"id":793,"title":794,"subfeature":652,"showOnPricing":691,"tiers":795},"blueprints-it-apps","Blueprints - IT APPS",{"edge":691,"hub":652,"fleet":691},{"id":797,"title":798,"description":799,"changelog":800,"showOnPricing":691,"tiers":804},"immersive-editor-snapshots","Snapshot Details in Immersive Editor","View and manage snapshot details directly inside the immersive editor without leaving your editing session.",[801],{"url":802,"release":803},"\u002Fchangelog\u002F2026\u002F03\u002Fsnapshot-detail-modal-immersive-editor\u002F","2.29",{"edge":652,"hub":652,"fleet":652},{"id":806,"title":807,"description":808,"changelog":809,"showOnPricing":691,"tiers":812},"immersive-editor-drawer","Customisable Immersive Editor Drawer","Pin, move, resize, or full-screen the immersive editor drawer. Your preferences are remembered between sessions.",[810],{"url":811,"release":701},"\u002Fchangelog\u002F2026\u002F04\u002Fimmersive-editor-drawer\u002F",{"edge":652,"hub":652,"fleet":652},{"id":814,"title":815,"description":816,"changelog":817,"showOnPricing":691,"tiers":820},"embedded-editor-tab-title","Embedded Editor Browser Tab Title","The browser tab title updates to reflect the active Node-RED canvas tab when working in the embedded editor.",[818],{"url":819,"release":803},"\u002Fchangelog\u002F2026\u002F03\u002Fembedded-editor-tab-title\u002F",{"edge":652,"hub":652,"fleet":652},{"id":822,"title":823,"features":824},"deploy","Deploy",[825,831,840,846,852,858,864,870,875],{"id":826,"title":827,"description":828,"docsLink":829,"tiers":830},"hosted-instances","Cloud Instances","Run Node-RED instances managed and hosted by FlowFuse.","\u002Fdocs\u002Fuser\u002Fintroduction\u002F#creating-a-node-red-instance",{"edge":652,"hub":652,"fleet":652},{"id":832,"title":833,"description":834,"docsLink":835,"changelog":836,"tiers":839},"edge-devices","Edge Instances","Deploy and mange your Node-RED instances on edge PLCs and gateways, with full visibility and control from the cloud.","\u002Fdocs\u002Fdevice-agent\u002Fintroduction\u002F",[837],{"url":838,"release":681},"\u002Fchangelog\u002F2026\u002F02\u002Fdevice-agent-nodejs-options\u002F",{"edge":652,"hub":691,"fleet":652},{"id":841,"title":842,"description":843,"docsLink":844,"tiers":845},"custom-hostnames","Custom Hostnames","Access your Node-RED application via your own domain name.","\u002Fdocs\u002Fuser\u002Fcustom-hostnames\u002F",{"edge":691,"hub":652,"fleet":691},{"id":847,"title":848,"description":849,"docsLink":850,"tiers":851},"mqtt-broker","MQTT Broker","Manage and create MQTT clients to transport data for efficient messaging and communication within your applications.","\u002Fdocs\u002Fuser\u002Fteambroker\u002F",{"edge":652,"hub":691,"fleet":652},{"id":853,"title":854,"description":855,"docsLink":856,"showOnPricing":691,"tiers":857},"project-nodes","Project Nodes aka seamless project comms","FlowFuse Project Nodes enable the passing of data and messages between your Node-RED projects.","\u002Fdocs\u002Fuser\u002Fprojectnodes\u002F",{"edge":652,"hub":652,"fleet":652},{"id":859,"title":860,"description":861,"docsLink":862,"tiers":863},"devops-pipelines","DevOps Pipelines","Set up different environments for development, testing, and production Node-RED instances to support a full software delivery lifecycle.","\u002Fdocs\u002Fuser\u002Fdevops-pipelines\u002F",{"edge":652,"hub":652,"fleet":652},{"id":865,"title":866,"description":867,"docsLink":868,"tiers":869},"git-integration","Git Integration","Back up your flows to a remote Git repository through a DevOps Pipeline. Supports GitHub and Azure DevOps repositories.","\u002Fdocs\u002Fuser\u002Fdevops-pipelines\u002F#git-repository-stage",{"edge":691,"hub":652,"fleet":691},{"id":871,"title":872,"description":873,"docsLink":868,"subfeature":652,"showOnPricing":691,"tiers":874},"git-integration-github","GitHub","Push and pull snapshots to GitHub repositories through DevOps Pipeline Git Stages.",{"edge":691,"hub":652,"fleet":691},{"id":876,"title":877,"description":878,"docsLink":868,"changelog":879,"subfeature":652,"showOnPricing":691,"tiers":882},"git-integration-azure","Azure DevOps","Push and pull snapshots to Azure DevOps repositories through DevOps Pipeline Git Stages.",[880],{"url":881,"release":803},"\u002Fchangelog\u002F2026\u002F03\u002Fazure-dev-ops-gitops\u002F",{"edge":691,"hub":652,"fleet":691},{"id":884,"title":885,"features":886},"operate-maintain","Operate & Maintain",[887,893,899,904,912,916,920,925,931,937,942,948,952,956],{"id":888,"title":889,"description":890,"docsLink":891,"tiers":892},"snapshots","Snapshots & Version History","Automatic snapshots on remote devices and hosted instances, plus a full version history timeline so you can roll back to any prior state.","\u002Fdocs\u002Fuser\u002Fsnapshots\u002F",{"edge":652,"hub":652,"fleet":652},{"id":894,"title":895,"description":896,"docsLink":897,"subfeature":652,"showOnPricing":691,"tiers":898},"auto-snapshot-remote","Auto Snapshot (Remote)","Automatically capture a snapshot every time a remote instance is deployed, so you always have a recoverable history of what was running on each device.","\u002Fdocs\u002Fuser\u002Fsnapshots\u002F#auto-snapshots",{"edge":652,"hub":652,"fleet":652},{"id":900,"title":901,"description":902,"docsLink":897,"subfeature":652,"showOnPricing":691,"tiers":903},"auto-snapshot-hosted","Auto Snapshot (Hosted)","Automatically capture a snapshot every time a hosted instance is deployed, so you always have a recoverable history of what was running.",{"edge":652,"hub":652,"fleet":652},{"id":905,"title":906,"description":907,"changelog":908,"subfeature":652,"showOnPricing":691,"tiers":911},"snapshot-comparison","Snapshot Comparison","Compare two snapshots side-by-side with a navigable diff view. Step through every changed, added, or deleted node and see property and code diffs.",[909],{"url":910,"release":803},"\u002Fchangelog\u002F2026\u002F04\u002Fsnapshot-diff-viewer\u002F",{"edge":652,"hub":652,"fleet":652},{"id":913,"title":914,"subfeature":652,"showOnPricing":691,"tiers":915},"version-history-timeline","Version History Timeline",{"edge":652,"hub":652,"fleet":652},{"id":917,"title":918,"tiers":919},"unlimited-workflow-executions","Unlimited Workflow Executions",{"edge":652,"hub":652,"fleet":652},{"id":921,"title":922,"description":923,"tiers":924},"device-fleet-updates","Device Fleet Updates","Connect to edge devices to quickly assess and update logic. Debug one device and roll out improvements to your fleet in minutes, securely without requiring full device access for your whole organisation.",{"edge":652,"hub":691,"fleet":652},{"id":926,"title":927,"description":928,"docsLink":929,"tiers":930},"device-group-management","Device Group Management","Logically group devices assigned to an application and integrate device groups into your DevOps Pipeline for coordinated fleet updates.","\u002Fdocs\u002Fuser\u002Fdevice-groups\u002F",{"edge":652,"hub":691,"fleet":652},{"id":932,"title":933,"description":934,"docsLink":935,"tiers":936},"high-availability","High Availability","Leverage horizontal scaling for reliable and scalable processing of your data through Node-RED.","\u002Fdocs\u002Fuser\u002Fhigh-availability\u002F",{"edge":691,"hub":652,"fleet":691},{"id":938,"title":939,"description":940,"tiers":941},"performance-monitoring","Performance Monitoring & Alerts","Track CPU, memory, and event loop performance across your instances and devices, with email alerts when something needs your attention.",{"edge":652,"hub":652,"fleet":652},{"id":943,"title":944,"description":945,"docsLink":946,"subfeature":652,"showOnPricing":691,"tiers":947},"instance-monitoring","Instance Monitoring","Enable alerts to be sent via email when your Node-RED instances encounter issues.","\u002Fdocs\u002Fuser\u002Finstance-settings\u002F#alerts",{"edge":652,"hub":652,"fleet":652},{"id":949,"title":950,"subfeature":652,"showOnPricing":691,"tiers":951},"email-alerts","Email Alerts",{"edge":652,"hub":652,"fleet":652},{"id":953,"title":954,"showOnPricing":691,"tiers":955},"api-debug-length-limit","API\u002FDebug Length Limit",{"edge":652,"hub":652,"fleet":652},{"id":957,"title":958,"tiers":959},"protected-instances","Protected Instances",{"edge":691,"hub":652,"fleet":691},{"id":961,"title":962,"features":963},"govern-secure","Govern and Secure",[964,973,979,985,990,996,1002,1008,1016,1022,1028,1034],{"id":965,"title":966,"description":967,"docsLink":968,"changelog":969,"tiers":972},"single-sign-on","Single Sign-On (SSO)","Configure FlowFuse to work with your own SSO provider, allowing users to access FlowFuse with a single set of login credentials.","\u002Fdocs\u002Fadmin\u002Fsso\u002F",[970],{"url":971,"release":744},"\u002Fchangelog\u002F2026\u002F07\u002Fapplication-sso-groups\u002F",{"edge":652,"hub":652,"fleet":652},{"id":974,"title":975,"description":976,"docsLink":977,"tiers":978},"two-factor-authentication","Two-Factor Authentication","Two-factor authentication adds an extra layer of security to your FlowFuse account.","\u002Fdocs\u002Fuser\u002Fuser-settings\u002F#two-factor-authentication",{"edge":652,"hub":652,"fleet":652},{"id":980,"title":981,"description":982,"docsLink":983,"tiers":984},"certified-nodes-it","Certified Nodes - IT","IT certified node bundle includes: Redis, MQTT, HTTP Request, AI nodes (Gemini, Claude, ChatGPT, Ollama), MCP Server","\u002Fblog\u002F2025\u002F07\u002Fcertified-nodes-v2\u002F",{"edge":691,"hub":652,"fleet":652},{"id":986,"title":987,"description":988,"tiers":989},"certified-nodes-ot","Certified OT Connections - OPC-UA, Modbus, etc.","OT certified node bundle includes: OPC-UA, Modbus TCP & RTU, RTSP, EtherNet\u002FIP, AI nodes (Gemini, Claude, ChatGPT, Ollama), MCP Server",{"edge":652,"hub":691,"fleet":691},{"id":991,"title":992,"description":993,"docsLink":994,"tiers":995},"audit-log","Audit Log","Keep track of everything going on in your Node-RED instances and FlowFuse. Audit Logs provide details on what actions have taken place, when they happened, and who did them.","\u002Fdocs\u002Fuser\u002Flogs\u002F#audit-log",{"edge":652,"hub":652,"fleet":652},{"id":997,"title":998,"description":999,"docsLink":1000,"tiers":1001},"role-based-access-control","Role-Based Access Control","Control who can do what at both the team and application level, from viewers to admins.","\u002Fdocs\u002Fuser\u002Frole-based-access-control\u002F",{"edge":652,"hub":652,"fleet":652},{"id":1003,"title":1004,"description":1005,"docsLink":1006,"subfeature":652,"showOnPricing":691,"tiers":1007},"application-level-rbac","Application-Level RBAC","Fine-grained access control per application, allowing team members to have different permission levels across different applications without requiring separate teams.","\u002Fdocs\u002Fuser\u002Frole-based-access-control\u002F#application-level-rbac",{"edge":652,"hub":652,"fleet":652},{"id":1009,"title":1010,"description":1011,"changelog":1012,"subfeature":652,"showOnPricing":691,"tiers":1015},"scoped-personal-access-tokens","Scoped Personal Access Tokens","Restrict a Personal Access Token to specific teams, limit it to read-only operations, or control whether it carries admin privileges.",[1013],{"url":1014,"release":744},"\u002Fchangelog\u002F2026\u002F07\u002Fscoped-pats\u002F",{"edge":652,"hub":652,"fleet":652},{"id":1017,"title":1018,"description":1019,"docsLink":1020,"showOnPricing":691,"tiers":1021},"team-members","Team Members","Invite multiple team members to collaborate on the same Node-RED flows.","\u002Fdocs\u002Fuser\u002Fteam\u002F#teams",{"edge":652,"hub":652,"fleet":652},{"id":1023,"title":1024,"description":1025,"docsLink":1026,"showOnPricing":691,"tiers":1027},"endpoint-security","Endpoint Security","Secure HTTP endpoints for hosted Node-RED instances using FlowFuse credentials.","\u002Fdocs\u002Fuser\u002Finstance-settings\u002F#security",{"edge":652,"hub":652,"fleet":652},{"id":1029,"title":1030,"description":1031,"docsLink":1032,"tiers":1033},"baa-for-hipaa","BAA for HIPAA","FlowFuse can sign a Business Associate Agreement to ensure proper safeguarding of protected health information handled on your behalf.","\u002Fhandbook\u002Fsales\u002Fsubscription-agreement-1.5\u002F",{"edge":691,"hub":652,"fleet":691},{"id":1035,"title":1036,"description":1037,"tiers":1038},"sbom","Software Bill of Materials","A complete list of all software components used in your Node-RED instances and hosted applications, including version numbers and license information.",{"edge":691,"hub":652,"fleet":691},{"id":1040,"title":1041,"features":1042},"support","Support",[1043,1048,1052],{"id":1044,"title":1045,"docsLink":1046,"tiers":1047},"installation-support","Installation Support","\u002Fdocs\u002Finstall\u002Fintroduction\u002F#do-you-need-help-installation-service",{"edge":652,"hub":652,"fleet":652},{"id":1049,"title":1050,"showOnPricing":691,"tiers":1051},"live-chat-support","Live Chat Support",{"edge":652,"hub":652,"fleet":652},{"id":1053,"title":1054,"docsLink":1055,"tiers":1056},"enterprise-support","Enterprise Support","\u002Fdocs\u002Fpremium-support\u002F",{"edge":652,"hub":652,"fleet":652},"feature-catalog","0AnkhTIPCECCwP9NmbTWP5HvRYx4FTSao4lG93-HaWM",[1060,1063,1066,1069,1072,1075,1077,1080,1083,1086,1089,1091,1094,1097,1100,1103,1106,1109,1112,1115,1118,1121,1124,1127,1130,1133,1136,1139,1142,1145,1148,1151,1154,1157,1160,1163,1166,1169,1172,1175,1178,1181,1184,1187,1190,1193,1196,1199,1202,1204,1207,1210,1213,1216,1219,1222,1225,1227,1230,1233,1236,1239,1242,1244,1247,1250,1253,1256,1259,1262,1265,1268,1271,1274,1276,1279,1282,1285,1288,1291,1294,1297,1300,1303,1306,1309,1312,1315,1318,1320,1323,1326,1329,1332,1335,1338,1341,1344,1347,1350,1353,1356,1359,1362,1365,1368,1371,1374,1376,1379,1382,1385,1388,1391,1394,1397,1399,1402,1405,1408,1411,1414,1417,1420,1423,1426,1429,1432,1435,1438,1441,1444,1447,1450,1453,1456,1459,1462,1465,1468,1471,1474,1477,1480,1483,1486,1489,1492,1495,1498,1501,1504,1507,1510,1513,1516,1519,1522,1525,1528,1531,1534,1537,1540,1543,1546,1549,1551,1554,1557,1560,1563,1566,1569,1572,1575,1578,1581,1584,1587,1590],{"path":1061,"title":1062},"\u002Fchangelog\u002F2023\u002F09\u002Fcustom-node-support","Custom Node Support",{"path":1064,"title":1065},"\u002Fchangelog\u002F2023\u002F09\u002Fdevops-actions","DevOps Pipeline with action selection",{"path":1067,"title":1068},"\u002Fchangelog\u002F2023\u002F09\u002Fintroduction-enterprise-tier","Introducing the Enterprise Tier",{"path":1070,"title":1071},"\u002Fchangelog\u002F2023\u002F09\u002Fpipeline-api","API Endpoint for DevOps Pipeline",{"path":1073,"title":1074},"\u002Fchangelog\u002F2023\u002F09\u002Fsnapshots-devices","Usability improvements to Device Management",{"path":1076,"title":784},"\u002Fchangelog\u002F2023\u002F10\u002Fblueprints",{"path":1078,"title":1079},"\u002Fchangelog\u002F2023\u002F10\u002Fcertified-nodes","Certified Nodes",{"path":1081,"title":1082},"\u002Fchangelog\u002F2023\u002F10\u002Fdevice-snapshot-selection","Enhanced Snapshot Selection",{"path":1084,"title":1085},"\u002Fchangelog\u002F2023\u002F10\u002Fpath-bug-fix","Device Agent path bug fix",{"path":1087,"title":1088},"\u002Fchangelog\u002F2023\u002F10\u002Fresource-alerts","Resource Monitoring in Audit Log",{"path":1090,"title":975},"\u002Fchangelog\u002F2023\u002F11\u002F2fa",{"path":1092,"title":1093},"\u002Fchangelog\u002F2023\u002F11\u002Fdefault-editor","Device Editor enabled by default",{"path":1095,"title":1096},"\u002Fchangelog\u002F2023\u002F11\u002Fdevices-in-pipelines","Devices in DevOps Pipelines",{"path":1098,"title":1099},"\u002Fchangelog\u002F2023\u002F11\u002Fproject-nodes-devices","Project Nodes for Devices",{"path":1101,"title":1102},"\u002Fchangelog\u002F2023\u002F12\u002Fbilling","No Credit Card required for billing",{"path":1104,"title":1105},"\u002Fchangelog\u002F2023\u002F12\u002Fblueprint-selection","Blueprint Selection Update",{"path":1107,"title":1108},"\u002Fchangelog\u002F2023\u002F12\u002Fdevice-groups","Device Groups",{"path":1110,"title":1111},"\u002Fchangelog\u002F2023\u002F12\u002Femail-alerting-node-red-crash","Email Alerts for Audit Log Events",{"path":1113,"title":1114},"\u002Fchangelog\u002F2023\u002F12\u002Fnode-red-updated","Node-RED 3.1.3 now available",{"path":1116,"title":1117},"\u002Fchangelog\u002F2024\u002F01\u002Fdevice-audit-log","Introducing the Device Auditlog Feature",{"path":1119,"title":1120},"\u002Fchangelog\u002F2024\u002F01\u002Fdevice-groups-snapshot","Device Groups - Automatic snapshot assignment",{"path":1122,"title":1123},"\u002Fchangelog\u002F2024\u002F01\u002Ffleet-mode","Renaming \"Default Device Mode\" to \"Fleet Mode\"",{"path":1125,"title":1126},"\u002Fchangelog\u002F2024\u002F01\u002Fhelm-v2","Helm Chart v2.0",{"path":1128,"title":1129},"\u002Fchangelog\u002F2024\u002F01\u002Fnew-blueprints","New Blueprints added",{"path":1131,"title":1132},"\u002Fchangelog\u002F2024\u002F01\u002Fsecurity-updates","Security Updates",{"path":1134,"title":1135},"\u002Fchangelog\u002F2024\u002F01\u002Fsso-team-membership","Managing Team Membership via SSO",{"path":1137,"title":1138},"\u002Fchangelog\u002F2024\u002F01\u002Fstreamlined-device-assignment","Streamlined Device assignment",{"path":1140,"title":1141},"\u002Fchangelog\u002F2024\u002F02\u002Fdevice-auto-snapshot","Device Auto Snapshots",{"path":1143,"title":1144},"\u002Fchangelog\u002F2024\u002F02\u002Fdevice-instance-audit-logs","Device Instance Audit Logging",{"path":1146,"title":1147},"\u002Fchangelog\u002F2024\u002F02\u002Fdevice-onboarding-improvements","Device Onboarding Improvements",{"path":1149,"title":1150},"\u002Fchangelog\u002F2024\u002F02\u002Fdevice-pricing-change","Pricing change for Devices",{"path":1152,"title":1153},"\u002Fchangelog\u002F2024\u002F02\u002Finstance-auto-snapshots","Instance Auto Snapshots",{"path":1155,"title":1156},"\u002Fchangelog\u002F2024\u002F02\u002Fpostgresql-upgrade","PostgreSQL Version update",{"path":1158,"title":1159},"\u002Fchangelog\u002F2024\u002F03\u002Fbearer-token-authentication","Bearer Token Authentication for Node-RED Instances",{"path":1161,"title":1162},"\u002Fchangelog\u002F2024\u002F03\u002Finstance-protection-mode","Instance Protection Mode",{"path":1164,"title":1165},"\u002Fchangelog\u002F2024\u002F03\u002Flimits-debug-payload","Configure HTTP Payload and Debug Message size",{"path":1167,"title":1168},"\u002Fchangelog\u002F2024\u002F03\u002Frestart-devices-remotly","Remote Device Restart",{"path":1170,"title":1171},"\u002Fchangelog\u002F2024\u002F04\u002Fcustom-nodes-on-devices","Custom Nodes Support on Devices",{"path":1173,"title":1174},"\u002Fchangelog\u002F2024\u002F04\u002Fdevice-auto-snapshot","Direct Dashboard Access",{"path":1176,"title":1177},"\u002Fchangelog\u002F2024\u002F04\u002Fimproving-device-groups","Improving Device Groups",{"path":1179,"title":1180},"\u002Fchangelog\u002F2024\u002F04\u002Fpricing-change","Pricing change Enterprise & Teams Tier",{"path":1182,"title":1183},"\u002Fchangelog\u002F2024\u002F04\u002Ftougher-rate-limiting","Tougher Rate Limiting on Public Routes",{"path":1185,"title":1186},"\u002Fchangelog\u002F2024\u002F05\u002Finstance-healthcheck","Customizing instance health-check settings",{"path":1188,"title":1189},"\u002Fchangelog\u002F2024\u002F05\u002Flibrary-blueprints","Blueprints added to Library",{"path":1191,"title":1192},"\u002Fchangelog\u002F2024\u002F05\u002Flibrary-flowviewer","Team Library - Flow Viewer",{"path":1194,"title":1195},"\u002Fchangelog\u002F2024\u002F05\u002Fmanaging-node-red-version-on-devices","Managing Node-RED versions on Devices",{"path":1197,"title":1198},"\u002Fchangelog\u002F2024\u002F05\u002Fsnapshot-improvements","Snapshot Improvements",{"path":1200,"title":1201},"\u002Fchangelog\u002F2024\u002F05\u002Fsnapshot-improvements-pt3","Snapshot Upload",{"path":1203,"title":1201},"\u002Fchangelog\u002F2024\u002F05\u002Fsnapshot-upload",{"path":1205,"title":1206},"\u002Fchangelog\u002F2024\u002F06\u002Fdevice-agent-proxy-support","Running the Device Agent behind an HTTP proxy",{"path":1208,"title":1209},"\u002Fchangelog\u002F2024\u002F06\u002Flibrary-blueprints","Custom hostnames for your instances",{"path":1211,"title":1212},"\u002Fchangelog\u002F2024\u002F06\u002Fmultiline-env-vars","Multi-line Environment Variables",{"path":1214,"title":1215},"\u002Fchangelog\u002F2024\u002F06\u002Fsnapshot-flow-compare","Compare Snapshots flows",{"path":1217,"title":1218},"\u002Fchangelog\u002F2024\u002F07\u002Fapplications-search","Applications Search",{"path":1220,"title":1221},"\u002Fchangelog\u002F2024\u002F07\u002Fdevice-group-clear-snapshot","Device Groups Snapshots",{"path":1223,"title":1224},"\u002Fchangelog\u002F2024\u002F07\u002Fdevice-management-bulk-delete","Managing devices",{"path":1226,"title":1224},"\u002Fchangelog\u002F2024\u002F07\u002Fdevice-management-bulk-move",{"path":1228,"title":1229},"\u002Fchangelog\u002F2024\u002F07\u002Fedit-snapshots","Edit Snapshots",{"path":1231,"title":1232},"\u002Fchangelog\u002F2024\u002F07\u002Fflowfuse-assistant","The FlowFuse Expert",{"path":1234,"title":1235},"\u002Fchangelog\u002F2024\u002F07\u002Fflowfuse-assistant-json","FlowFuse Expert Writes JSON",{"path":1237,"title":1238},"\u002Fchangelog\u002F2024\u002F07\u002Fimmersive-editor","Immersive Editor Experience",{"path":1240,"title":1241},"\u002Fchangelog\u002F2024\u002F07\u002Fnotifications-inbox","Notifications Inbox",{"path":1243,"title":1241},"\u002Fchangelog\u002F2024\u002F07\u002Fnotifications-update",{"path":1245,"title":1246},"\u002Fchangelog\u002F2024\u002F07\u002Fpersistent-storage","Persistent Storage on FlowFuse Cloud",{"path":1248,"title":1249},"\u002Fchangelog\u002F2024\u002F07\u002Fsso","Single Sign On Updates",{"path":1251,"title":1252},"\u002Fchangelog\u002F2024\u002F08\u002Fbill-of-materials","Bill of Materials",{"path":1254,"title":1255},"\u002Fchangelog\u002F2024\u002F08\u002Fenterprise-license-update","Enforcing Enterprise Restrictions",{"path":1257,"title":1258},"\u002Fchangelog\u002F2024\u002F08\u002Fldap-sso-groups","LDAP Single Sign On Updates",{"path":1260,"title":1261},"\u002Fchangelog\u002F2024\u002F08\u002Fstatic-file-service-navigation-visibility","Static File Service Navigation and Visibility",{"path":1263,"title":1264},"\u002Fchangelog\u002F2024\u002F10\u002Fdevice-group-env-vars","Environment Variables for your Device Groups",{"path":1266,"title":1267},"\u002Fchangelog\u002F2024\u002F10\u002Fmqtt-service","MQTT Broker Service",{"path":1269,"title":1270},"\u002Fchangelog\u002F2024\u002F10\u002Fnotifications-bulk-actions","Managing Notifications",{"path":1272,"title":1273},"\u002Fchangelog\u002F2024\u002F10\u002Fsnapshot-download-upload-options","Snapshot Upload and Download Improvements",{"path":1275,"title":914},"\u002Fchangelog\u002F2024\u002F10\u002Fversion-history-timeline",{"path":1277,"title":1278},"\u002Fchangelog\u002F2024\u002F11\u002Faudit-log-hierarchy","Audit logs show hierarchical events",{"path":1280,"title":1281},"\u002Fchangelog\u002F2024\u002F11\u002Fdevice-agent-release","Device Agent 3.0 released",{"path":1283,"title":1284},"\u002Fchangelog\u002F2024\u002F11\u002Fmqtt-topic-hierarchy","MQTT Topic Hierarchy view",{"path":1286,"title":1287},"\u002Fchangelog\u002F2024\u002F11\u002Fteam-search","Team-wide search",{"path":1289,"title":1290},"\u002Fchangelog\u002F2024\u002F12\u002Fdashboad-iframe","Allow Dashboards to be embedded in iFrames",{"path":1292,"title":1293},"\u002Fchangelog\u002F2024\u002F12\u002Fdevice-editor-cache","Device Editor Access Speed Up",{"path":1295,"title":1296},"\u002Fchangelog\u002F2024\u002F12\u002Fteam-bom-timeline","Team BOM and Pipeline Views",{"path":1298,"title":1299},"\u002Fchangelog\u002F2025\u002F01\u002Ffree-tier-onboarding","New Onboarding Tour for Free Tier Users",{"path":1301,"title":1302},"\u002Fchangelog\u002F2025\u002F01\u002Fhidden-env-vars","Hidden Environment Variables",{"path":1304,"title":1305},"\u002Fchangelog\u002F2025\u002F01\u002Fimproved-diagnostics","Improved Diagnostics",{"path":1307,"title":1308},"\u002Fchangelog\u002F2025\u002F01\u002Fteam-level-groups","Team level view of Groups",{"path":1310,"title":1311},"\u002Fchangelog\u002F2025\u002F02\u002Fadditional-device-version-history-events","New Remote Instances Version History Events",{"path":1313,"title":1314},"\u002Fchangelog\u002F2025\u002F02\u002Fbroker-error-feedback","Improved Broker Connection Feedback",{"path":1316,"title":1317},"\u002Fchangelog\u002F2025\u002F02\u002Fdevice-agent-updates","FlowFuse User Authentication on Remote Instances",{"path":1319,"title":914},"\u002Fchangelog\u002F2025\u002F02\u002Fdevice-version-history-timeline",{"path":1321,"title":1322},"\u002Fchangelog\u002F2025\u002F02\u002Fexternal-brokers","External MQTT Brokers",{"path":1324,"title":1325},"\u002Fchangelog\u002F2025\u002F02\u002Fmqtt-schema-suggestions","MQTT Smart Schema Suggestions",{"path":1327,"title":1328},"\u002Fchangelog\u002F2025\u002F02\u002Fresend-and-extend-team-invitation-expiration","Re-send Team Invitations",{"path":1330,"title":1331},"\u002Fchangelog\u002F2025\u002F02\u002Fschema-docs","Personalized Schema Documentation",{"path":1333,"title":1334},"\u002Fchangelog\u002F2025\u002F02\u002Ftopic-hierarchy-search","Search & Filter for Topic Hierarchy List",{"path":1336,"title":1337},"\u002Fchangelog\u002F2025\u002F03\u002Fcontainer-tags","Changes to tags for flowfuse\u002Fnode-red",{"path":1339,"title":1340},"\u002Fchangelog\u002F2025\u002F03\u002Fdevice-groups","Multiple Device Groups in a pipeline",{"path":1342,"title":1343},"\u002Fchangelog\u002F2025\u002F03\u002Fdevice-local-login","Local Login for Remote Instances",{"path":1345,"title":1346},"\u002Fchangelog\u002F2025\u002F03\u002Ffree-tier","Free Tier now more accessible to all",{"path":1348,"title":1349},"\u002Fchangelog\u002F2025\u002F03\u002Fresource-notifications","Resource Alerts",{"path":1351,"title":1352},"\u002Fchangelog\u002F2025\u002F03\u002Fsnapshot-filter","Filtering Snapshots",{"path":1354,"title":1355},"\u002Fchangelog\u002F2025\u002F03\u002Fteam-npm-registry","NPM Package Hosting",{"path":1357,"title":1358},"\u002Fchangelog\u002F2025\u002F03\u002Ftopic-deletion","MQTT Topic Management",{"path":1360,"title":1361},"\u002Fchangelog\u002F2025\u002F04\u002Fdevice-provisioning","Remote Instance Provisioning",{"path":1363,"title":1364},"\u002Fchangelog\u002F2025\u002F04\u002Fgit-integration","Git Integration with Pipelines",{"path":1366,"title":1367},"\u002Fchangelog\u002F2025\u002F04\u002Finstance-log-browsing","Better Node-RED log handling",{"path":1369,"title":1370},"\u002Fchangelog\u002F2025\u002F05\u002Fimport-node-red-flows","Import Node-RED Flows During Remote Instance Setup",{"path":1372,"title":1373},"\u002Fchangelog\u002F2025\u002F06\u002Fflowfuse-assistant","FlowFuse Expert just got smarter",{"path":1375,"title":1373},"\u002Fchangelog\u002F2025\u002F06\u002Fflowfuse-assistant-2",{"path":1377,"title":1378},"\u002Fchangelog\u002F2025\u002F06\u002Fgit-integration","Pulling snapshots from Git with Pipelines",{"path":1380,"title":1381},"\u002Fchangelog\u002F2025\u002F06\u002Finstance-performance-memory","Memory Metrics in Instance Performance View",{"path":1383,"title":1384},"\u002Fchangelog\u002F2025\u002F06\u002Fnew-home-page","Introducing the New Home Page Experience",{"path":1386,"title":1387},"\u002Fchangelog\u002F2025\u002F06\u002Fteam-performance","Team Performance Feature",{"path":1389,"title":1390},"\u002Fchangelog\u002F2025\u002F06\u002Fteam-performance-view","Instance Performance View",{"path":1392,"title":1393},"\u002Fchangelog\u002F2025\u002F06\u002Fui-refresh","Navigation UI Refresh",{"path":1395,"title":1396},"\u002Fchangelog\u002F2025\u002F07\u002Fbrowse-node-red-flows","Browse for Node-RED Flows During Remote Instance Setup",{"path":1398,"title":738},"\u002Fchangelog\u002F2025\u002F07\u002Fflowfuse-tables",{"path":1400,"title":1401},"\u002Fchangelog\u002F2025\u002F07\u002Fimport-blueprints","Import blueprints directly into your existing instances",{"path":1403,"title":1404},"\u002Fchangelog\u002F2025\u002F07\u002Fsimplified-applications-overview","Simplified Applications Page with Summary Tiles",{"path":1406,"title":1407},"\u002Fchangelog\u002F2025\u002F07\u002Fsmart-suggestions","Smart Suggestions",{"path":1409,"title":1410},"\u002Fchangelog\u002F2025\u002F07\u002Fteam-to-pro-plan-rename","Team Plan Renamed to Pro Plan",{"path":1412,"title":1413},"\u002Fchangelog\u002F2025\u002F08\u002Fai-generated-snapshot-descriptions-hosted","Generate snapshot descriptions with AI",{"path":1415,"title":1416},"\u002Fchangelog\u002F2025\u002F08\u002Fai-generated-snapshot-descriptions-remote","AI Snapshot Descriptions Now Work with Remote Instances",{"path":1418,"title":1419},"\u002Fchangelog\u002F2025\u002F08\u002Fdevice-performance","FlowFuse Remote Instance Performance Data",{"path":1421,"title":1422},"\u002Fchangelog\u002F2025\u002F08\u002Fdirect-sso","Direct SSO Login",{"path":1424,"title":1425},"\u002Fchangelog\u002F2025\u002F08\u002Fflowfuse-assistant","FlowFuse Expert documents your flows",{"path":1427,"title":1428},"\u002Fchangelog\u002F2025\u002F08\u002Fflowfuse-mqtt","FlowFuse MQTT",{"path":1430,"title":1431},"\u002Fchangelog\u002F2025\u002F08\u002Fhttp-cors","Configure HTTP CORS",{"path":1433,"title":1434},"\u002Fchangelog\u002F2025\u002F08\u002Fsubflow-export","Export SubFlow as Node-RED module",{"path":1436,"title":1437},"\u002Fchangelog\u002F2025\u002F08\u002Ftables-assistant","FlowFuse Tables with a little help from the Assistant",{"path":1439,"title":1440},"\u002Fchangelog\u002F2025\u002F09\u002Fexpose-saml-groups-to-dashboard","Allow SSO groups to be shared with the Node-RED Dashboard",{"path":1442,"title":1443},"\u002Fchangelog\u002F2025\u002F09\u002Finline-assist","FlowFuse Expert can help you write code",{"path":1445,"title":1446},"\u002Fchangelog\u002F2025\u002F09\u002Fretiring-flowforge-device-agent","No more @flowforge\u002Fflowforge-device-agent releases",{"path":1448,"title":1449},"\u002Fchangelog\u002F2025\u002F09\u002Frevised-instance-snapshot-ui","Streamlined Snapshot Management",{"path":1451,"title":1452},"\u002Fchangelog\u002F2025\u002F09\u002Fteam-broker-async-api","Capture Async API data from FlowFuse Team Broker",{"path":1454,"title":1455},"\u002Fchangelog\u002F2025\u002F10\u002Fapplication-level-rbac","Application-level access control for Enterprise teams",{"path":1457,"title":1458},"\u002Fchangelog\u002F2025\u002F10\u002Fbulk-device-group-assignment","Easier Access to Bulk Device Group Management",{"path":1460,"title":1461},"\u002Fchangelog\u002F2025\u002F10\u002Fduplicate-instances-across-applications","Duplicate Instances Across Different Applications",{"path":1463,"title":1464},"\u002Fchangelog\u002F2025\u002F10\u002Fimport-flows-on-instance-creation","Import flows during instance creation",{"path":1466,"title":1467},"\u002Fchangelog\u002F2025\u002F10\u002Fmcp-nodes","FlowFuse MCP Server Nodes",{"path":1469,"title":1470},"\u002Fchangelog\u002F2025\u002F10\u002Fonnx-nodes","FlowFuse AI Nodes",{"path":1472,"title":1473},"\u002Fchangelog\u002F2025\u002F10\u002Fsettings-page-device-group-management","Device Group Management from Settings Page",{"path":1475,"title":1476},"\u002Fchangelog\u002F2025\u002F11\u002Fff-expert-update","FlowFuse Expert Update",{"path":1478,"title":1479},"\u002Fchangelog\u002F2025\u002F11\u002Fminimum-nodejs-version","Node.js v20 Minimum Version Requirement",{"path":1481,"title":1482},"\u002Fchangelog\u002F2025\u002F11\u002Fsso-session","SSO control over Session life",{"path":1484,"title":1485},"\u002Fchangelog\u002F2025\u002F12\u002Fff-expert-mcp-insights","FlowFuse Expert: Now with MCP-Powered Insights",{"path":1487,"title":1488},"\u002Fchangelog\u002F2025\u002F12\u002Fscheduled-maintenance","Scheduled Maintenance Mode",{"path":1490,"title":1491},"\u002Fchangelog\u002F2026\u002F01\u002Fdevice-agent-containers","Device Agent Docker Containers updated",{"path":1493,"title":1494},"\u002Fchangelog\u002F2026\u002F01\u002Fff-expert-manage-palette","FlowFuse Expert: Enhanced Palette Integration",{"path":1496,"title":1497},"\u002Fchangelog\u002F2026\u002F01\u002Fff-expert-nr-actions","FlowFuse Expert: Integration with Node-RED",{"path":1499,"title":1500},"\u002Fchangelog\u002F2026\u002F01\u002Fff-expert-palette-queries","FlowFuse Expert: Palette Queries",{"path":1502,"title":1503},"\u002Fchangelog\u002F2026\u002F01\u002Fff-expert-select-flows","FlowFuse Expert: Ask about your flows",{"path":1505,"title":1506},"\u002Fchangelog\u002F2026\u002F01\u002Fmcp-rbacs","FlowFuse Expert: MCP-Powered Insights with RBACs",{"path":1508,"title":1509},"\u002Fchangelog\u002F2026\u002F01\u002Fmcp-security","FlowFuse Expert: MCP-Powered Insights",{"path":1511,"title":1512},"\u002Fchangelog\u002F2026\u002F02\u002Fdevice-agent-nodejs-options","Set Node.js Options for Remote Instances",{"path":1514,"title":1515},"\u002Fchangelog\u002F2026\u002F02\u002Fff-expert-debug-log-context","FlowFuse Expert: Helping you make sense of your debug log",{"path":1517,"title":1518},"\u002Fchangelog\u002F2026\u002F02\u002Fff-expert-update-banner","FlowFuse Expert: Never Miss an Update",{"path":1520,"title":1521},"\u002Fchangelog\u002F2026\u002F02\u002Fha-instance-rolling-restart","HA Hosted Instance Rolling Restart",{"path":1523,"title":1524},"\u002Fchangelog\u002F2026\u002F02\u002Fremote-instances-immersive-editor","Immersive Mode for Remote Instances",{"path":1526,"title":1527},"\u002Fchangelog\u002F2026\u002F02\u002Frestoring-snapshots-to-remote-instances","Restoring snapshots to developer-mode Remote Instances",{"path":1529,"title":1530},"\u002Fchangelog\u002F2026\u002F03\u002Fazure-dev-ops-gitops","Azure DevOps Pipeline support",{"path":1532,"title":1533},"\u002Fchangelog\u002F2026\u002F03\u002Fdeveloper-mode-in-immersive-editor","Developer Mode Now Accessible from the Immersive Editor",{"path":1535,"title":1536},"\u002Fchangelog\u002F2026\u002F03\u002Fembedded-editor-tab-title","Embedded Editor Now Shows Active Tab",{"path":1538,"title":1539},"\u002Fchangelog\u002F2026\u002F03\u002Fmarch-scheduled-maintenance","Updated: Upcoming Scheduled Server Maintenance on March 28th, 2026",{"path":1541,"title":1542},"\u002Fchangelog\u002F2026\u002F03\u002Fsnapshot-detail-modal-immersive-editor","View Snapshot Details in the Immersive Editor",{"path":1544,"title":1545},"\u002Fchangelog\u002F2026\u002F04\u002Fexpert-action-links","FlowFuse expert action links",{"path":1547,"title":1548},"\u002Fchangelog\u002F2026\u002F04\u002Fhosted-instance-url-env-var","Hosted Instances know their own URL",{"path":1550,"title":807},"\u002Fchangelog\u002F2026\u002F04\u002Fimmersive-editor-drawer",{"path":1552,"title":1553},"\u002Fchangelog\u002F2026\u002F04\u002Fsnapshot-diff-viewer","Richer snapshot comparison view",{"path":1555,"title":1556},"\u002Fchangelog\u002F2026\u002F05\u002Fai-opt-out","AI Feature Opt-Out for Teams",{"path":1558,"title":1559},"\u002Fchangelog\u002F2026\u002F05\u002Fexpert-application-building","FlowFuse Expert Builds Your Application",{"path":1561,"title":1562},"\u002Fchangelog\u002F2026\u002F05\u002Fsingle-sso-provider","Single SSO provider for all users",{"path":1564,"title":1565},"\u002Fchangelog\u002F2026\u002F06\u002Fdark-mode","Dark Mode",{"path":1567,"title":1568},"\u002Fchangelog\u002F2026\u002F06\u002Fdevice-agent-v4-released","Device Agent v4 released",{"path":1570,"title":1571},"\u002Fchangelog\u002F2026\u002F06\u002Fgeneric-git-server-support","Connect Pipelines to Any Git Server",{"path":1573,"title":1574},"\u002Fchangelog\u002F2026\u002F06\u002Fjuly-scheduled-maintenance","Updated: Upcoming Scheduled Server Maintenance on July 11th, 2026",{"path":1576,"title":1577},"\u002Fchangelog\u002F2026\u002F07\u002Fapplication-sso-groups","Application Roles from SSO Groups",{"path":1579,"title":1580},"\u002Fchangelog\u002F2026\u002F07\u002Fdevice-agent-onboarding","Getting started with FlowFuse straight from the terminal",{"path":1582,"title":1583},"\u002Fchangelog\u002F2026\u002F07\u002Fexpert-enhancements","FlowFuse Expert Enhancements",{"path":1585,"title":1586},"\u002Fchangelog\u002F2026\u002F07\u002Fexpert-tables-automation","FlowFuse Expert Can Now Work With Your Tables",{"path":1588,"title":1589},"\u002Fchangelog\u002F2026\u002F07\u002Fscoped-pats","Team Scoped Personal Access Tokens",{"path":1591,"title":1592},"\u002Fchangelog\u002F2026\u002F07\u002Fteam-and-application-dashboards","A Dedicated Home for Your Dashboards",[],1786105902198]