Home Assistant folds HACS into an official Marketplace and absorbs existing installs
Home Assistant has merged HACS, the community store that has distributed integrations, cards and themes for years, into an official system integration called Marketplace. Existing HACS installs are taken over automatically, but the trust model — no signatures, admin-only — does not change.
September 28, 2026. A pull request titled “Add Marketplace integration” lands in the Home Assistant core. October 1, 2026. It is merged: HACS, the Home Assistant Community Store, becomes an official integration named Marketplace. October 1, 2026. The merge is backward-compatible — existing HACS installs are taken over on first start, with no reinstallation. Why it matters: the largest self-hosted smart-home ecosystem absorbs its extension store into the product itself, and hundreds of thousands of installs shift from a third-party tool to a core component.
The end of a decade-old anomaly
For years, HACS played a paradoxical role: it was the most popular doorway for installing custom integrations, dashboard cards, themes and templates in Home Assistant, while remaining an unofficial extension maintained outside the project. You installed it yourself, it lived in custom_components, and you needed a GitHub account to browse its catalog.
Pull request #183502, opened on September 28 and merged on October 1, ends that oddity. The HACS code enters Home Assistant under the name Marketplace, with the stated goal of bringing it in “with the least effort possible, and as much as possible as it is,” before any future evolution.
The result is a system integration: it is on by default, with no manual install, and its panel appears under Settings. For the user, the store stops being a bolted-on layer and becomes part of the platform.
What changes for the user
The most visible change is the removal of the GitHub account requirement. Browsing, installing and updating from the catalog now work without a GitHub account: a catalog version installs straight from its archive or release asset, without touching the GitHub API. Only other versions and custom repositories still require a GitHub connection, established through the device flow from the panel.
Every download receives an update entity, so extension updates appear alongside the rest of Home Assistant in the standard update mechanism. It is a comfort detail, but it aligns the lifecycle of extensions with that of official integrations.
A first-run warning is shown to each user, not each install. It warns about the risks of community content. Until it is accepted, nothing installs or updates — however, browsing the catalog remains possible before acceptance.
Migration: everything is carried over, nothing is lost
For existing installs, the transition is designed to be painless. On first start, Marketplace takes over the HACS install: the config entry is converted in place, and storage, entities, devices, dashboard resources and custom repositories carry over as they are.
The familiar paths survive. The /hacs and /hacsfiles routes keep working, preserving references already baked into dashboards and templates. The HACS integration itself, along with its files, is removed — the loader now blocks the old HACS custom integration and names Marketplace as its replacement.
One deliberate loss: AppDaemon apps and Python scripts are no longer managed by Marketplace. A repair notification tells affected users which ones are concerned.
For users coming from HACS, the transition is effectively invisible: the same custom integrations, cards and themes keep working, now managed through a native panel under Settings. The main behavioral change is the first-run warning, which makes explicit a consent that was previously implicit — a small but meaningful shift for a platform whose community code has always run with full privileges.
The trust model does not move
This is the part one would have liked to see evolve: Marketplace introduces no signatures and no checksums on what it installs. The catalog is served by data-v2.hacs.xyz — the same one HACS used — and files travel over GitHub HTTPS, with no cryptographic verification on arrival.
What is actually protected is documented with care: every command is admin-only; writes and removals stay confined to their folders; downloads and archives carry size and member limits; themes are read without YAML tags; READMEs go through the markdown sanitizer; and the GitHub token is kept out of download URLs and diagnostics. Replacing a built-in integration with an extension requires explicit confirmation.
The catalog is still served by data-v2.hacs.xyz, the same distribution point HACS used, and it decides which repositories and versions are offered, removed or flagged critical. The merge therefore changes neither the source of extensions nor their content: it changes only how Home Assistant installs and updates them. For custom repositories, the GitHub connection remains required, established through the device flow from the panel — a deliberate compromise between the convenience of the official catalog and the freedom of third-party sources.
But the core remains: an installed integration runs inside Home Assistant, and an installed card runs in every user’s browser. Accepting the warning means granting community code the same privileges it has today, with no extra cryptographic safety net.
Why this absorption matters
HACS is not just any store: it is, by far, the most-used distribution in the Home Assistant ecosystem. Tens of thousands of installs rely on it to add custom integrations that have not yet joined the official core — energy-management panels, local brand integrations, sophisticated dashboard cards. By absorbing it, Home Assistant acknowledges that the line between “official” and “community” has grown porous: a large share of the platform’s value comes from code the project does not maintain itself.
The risk of that dependency fraying was real. HACS lived in custom_components, a folder Home Assistant could treat differently at any time — one loader change, and the whole store would stop working. By folding the code into core, the project secures continuity for the install mechanism, even though the catalog’s content remains unsigned community code.
The automatic migration is the clearest signal of that intent: rather than asking users to reinstall, Marketplace takes over existing installs, including custom repositories and dashboard resources. That is the kind of decision a vendor makes when it knows that breaking the migration would break hundreds of thousands of connected homes.
Preparing is straightforward. Before the migration lands, note which custom repositories you rely on and confirm you can still reach them through the device flow, since those still need a GitHub connection. Review any AppDaemon or Python scripts you still run, because they will not carry over. And decide, once, who in your household or team is allowed to accept the first-run warning — that single click is now the formal consent boundary for running community code.
Verdict
If you use HACS, you have nothing to do: Marketplace will take over your install on the next Home Assistant update, and your integrations, cards and themes will keep working through /hacs. When the switch happens, read the first-run warning: it formalizes what you were already accepting implicitly — community code running with administrator privileges. If you manage installs for other people, this is the moment to set the rule: who is allowed to accept that warning, and which custom sources are permitted. The risk does not change in kind; it simply becomes more visible, at the center of a product that is now official.