Skip to content

Latest commit

 

History

55 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Wait for Wolt

Wait for Wolt is an unofficial Home Assistant custom integration for tracking active Wolt deliveries. It creates automation-friendly sensors for an order's normalized status and estimated arrival time, refreshes browser-derived Wolt credentials when needed, and can optionally monitor selected venues for availability and delivery estimates.

The integration deliberately does not expose item lists, payment details, addresses, order identifiers, or raw Wolt responses as entity attributes. It is not affiliated with or endorsed by Wolt and relies on Wolt's private consumer web API, which may change without notice.

What it provides

  • A device for each active purchase, with a stable status sensor and timestamp ETA sensor suitable for dashboards, notifications, and automations.

  • Automatic discovery of orders placed while Home Assistant is running.

  • Durable access-token refresh and Home Assistant reauthentication when saved Wolt credentials stop working.

  • Optional venue sensors for open/closed status, delivery fees, and delivery estimates when Wolt provides them.

  • Conservative shared polling and privacy-preserving diagnostics.

  • A typed delivery minutes sensor for each active order, retaining legacy automation targets rather than converting them into text status sensors.

  • Opt-in courier and pickup locations, refreshed through the shared coordinator.

  • Product quantity count (excluding modifiers), plus optional per-order total, delivery fee and service fee sensors. Financial sensors are disabled by default; enable them individually from the entity settings if wanted.

Location history is sensitive. Under Configure, enable locations only if you want them stored in Home Assistant history. Existing locations are grandfathered only for their original order; a future order requires explicit opt-in. Disabled entities remain disabled. Exclude location sensors from Recorder if you do not want a permanent history.

The destination marker uses Wolt's actual delivery coordinates when provided and location permission allows it (coordinate_source: wolt_dropoff). It never substitutes zone.home. Courier positions and explicit dropoff events depend on Wolt returning them; this is 30-second polling, not websocket-level tracking.

Amounts require an explicit recognized currency and integer minor units. The order total additionally cross-checks Wolt's displayed total against its numeric summary amount; ambiguous formats remain unknown. Quantities describe products, not modifier counts or weights. Payment time is a status attribute only when Wolt supplies an explicit timestamp; localized display dates are not guessed. See the source audit for provenance and remaining limits.

Installation via HACS

Requires Home Assistant 2026.7.0 or newer.

  1. Add this repository as a custom repository in HACS.
  2. Install the latest Wait for Wolt GitHub release and restart Home Assistant.

Release builds use versioned tags such as v0.1.0b2. Beta versions are opt-in validation builds and are not promoted to production without the canary matrix. HACS 2.0.5 can construct an incorrect release-asset URL for these ZIP releases; see installation troubleshooting for the verified manual fallback. Repository validation and container canaries do not prove HACS download success.

Authentication

The integration needs a Wolt refresh token. The short-lived access token and analytics session ID are optional: when the access token is blank, the integration uses the refresh token once to obtain and persist a current token pair. Setup tests the credentials before saving the config entry.

Wolt's web phone and email sign-in flows are private and protected by hCaptcha; Wolt does not provide a public consumer OAuth/device authorization flow for Home Assistant. Wait for Wolt therefore does not collect your phone number, email, password, SMS code, or email magic link. Implementing those private endpoints in a headless config flow would bypass the browser's anti-abuse step and could lock an account. See Authentication design for the researched browser-mediated direction. Sign in on the official Wolt site, then copy the refresh credential locally:

  1. Log in to wolt.com and open the developer tools (usually F12 or Ctrl+Shift+I).

  2. Under the Application (or Storage) tab, open the cookies for https://wolt.com.

  3. In the Console paste the snippet below to print the needed values without digging through the storage menus:

    (() => {
      const getCookie = (name) => document.cookie.split('; ').find(row => row.startsWith(name + '='))?.split('=')[1];
      const decode = (name) => {
        const raw = getCookie(name);
        if (!raw) return undefined;
        try { return JSON.parse(decodeURIComponent(raw)); }
        catch { return decodeURIComponent(raw); }
      };
      const access = decode('__wtoken');
      const refresh = decode('__wrtoken');
      console.log('SESSION_ID (optional):', getCookie('__woltUid'));
      console.log('ACCESS_TOKEN:', access?.accessToken ?? access?.access_token ?? access);
      console.log('REFRESH_TOKEN:', refresh?.refreshToken ?? refresh?.refresh_token ?? refresh);
    })();

    Copy the refresh token. The access token can reduce the first setup request but is optional. SESSION_ID is also optional: accounts without analytics consent may not have __woltUid, and authenticated order requests work without that header. If a token is not printed, inspect an authenticated Wolt network request instead.

  4. Paste the refresh token into Home Assistant. Treat it like a password; the integration stores it in the config entry, rotates it when Wolt does, and never logs it.

This is still a browser-derived private credential, not supported Wolt OAuth. It is the least-privileged practical flow currently available. The project will adopt a first-party consumer OAuth/device flow if Wolt publishes one.

Configuration

Add the integration from Home Assistant's Add Integration menu. This is the supported configuration path and keeps rotated Wolt credentials durable across Home Assistant restarts.

Legacy YAML is imported once for migration. If you already have the following sensor entry, restart Home Assistant, confirm that the UI integration was created, then remove the YAML block:

sensor:
  - platform: wait_for_wolt
    name: My Wolt Account
    # Optional; omit if Wolt does not expose __woltUid.
    session_id: YOUR_SESSION_ID
    bearer_token: YOUR_ACCESS_TOKEN
    refresh_token: YOUR_REFRESH_TOKEN
    venue_ids:
      - mententen
      - another-venue

Do not keep YAML as a credential backup: Wolt may rotate refresh tokens, and the imported config entry becomes the authoritative credential store.

venue_ids should be the slug from the venue URL on wolt.com. For example, https://wolt.com/en/isr/tel-aviv/restaurant/mententen uses mententen as the ID. Enter one ID per line or list entry. When configuring from the UI, type each ID on a new line.

The integration masks credential fields in setup, options, and reauthentication forms. In Configure, leave the access and refresh token fields blank to keep their saved values. Entering a new refresh token while leaving access blank safely bootstraps a new access token. If Wolt rejects the saved credentials, Home Assistant opens a reauthentication flow.

How it works

  • The integration refreshes the bearer token automatically.
  • The coordinator polls every 30 seconds while an order is active and every minute while idle. Each authenticated endpoint is fetched at most once per cycle. Optional rich tracking failures fall back to the order summary and retry with bounded exponential backoff. Completed, cancelled, malformed-status, and vanished orders clear arrival flags, ETA, minutes and courier coordinates.
  • Each in-progress purchase gets a device with a stable enum status sensor and a timestamp ETA sensor, plus a numeric delivery-minutes sensor. Legacy wolt_<id> identities migrate to delivery/minutes, never status. New unique IDs are scoped to the config entry. Order identifiers, venue labels, item lists, payment values, addresses, and raw API payloads are intentionally not exposed in user-facing device names or entity attributes.
  • New orders placed while Home Assistant is running are discovered automatically within the polling interval.
  • If you configure venue_ids, sensors poll the public venue endpoint every five minutes, report whether it is open, and expose delivery price and estimates when available.

Limitations

  • This is an unofficial integration and is not affiliated with or endorsed by Wolt.
  • It relies on Wolt's private consumer web API, which can change without notice.
  • If both the access and refresh tokens become invalid, you will need to capture new ones.
  • Treat every cookie and token as a password. Never post them in an issue, log, screenshot, or test fixture.
  • Wolt operates in multiple countries, and the integration has no Israel-only code; hacs.json intentionally does not restrict installation by country.

Development

See Development and verification for locked setup commands, sanitized-fixture rules, CI validation, and exact-commit review artifacts. Upgrade users should read the migration notes; maintainers use the canary matrix and release process. Contributions must follow the contributor guide and security policy. Release-facing changes are recorded in the changelog.

About

🛵 Home Assistant integration to track Wolt order status and delivery availability for specific venues

Topics

Resources

Contributing

Security policy

Stars

7 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages