Connect UniFi Protect cameras
BoatKit can discover a UniFi Protect console on the vessel network and make selected Protect cameras available in saved views. Discovery and authentication do not enable camera streams by themselves. BoatKit enables an RTSPS stream only after a vessel administrator adds an individual camera or confirms Add all cameras.
Before you start
You need:
- A UniFi OS console running Protect on the same reachable vessel LAN as the BoatKit host
- At least one camera managed by that Protect console
- BoatKit vessel administrator access
- Permission to create a local Integration API key on the UniFi OS console
- A dedicated local Protect Integration API key for BoatKit
A dedicated BoatKit vessel host is the normal choice when cameras must remain continuously available. You can use a phone or tablet with vessel administrator access to configure and view the integration when BoatKit is running on that dedicated host. App-hosted-vessel support for this integration is not currently documented.
BoatKit does not publish a fixed list of supported Protect software, camera models, or firmware releases. It inventories the cameras returned by the console's local Protect Integration API, but this does not mean every Protect camera and firmware combination has been tested. Initial local validation has included a UniFi UNVR Instant with UVC G5 Turret Ultra and UVC G6 Pro 360 cameras.
Add the integration
Use auto-discovery
BoatKit auto-discovery sends UniFi discovery probes over the vessel LAN and confirms that a discovered UniFi OS console is running Protect. It does not send credentials during discovery.
The broader integration discovery process explores attached networks and peripherals. Follow the on-screen instruction to stop the vessel and place connected equipment in a safe state before starting it.
- Open Settings, then Integrations.
- Select Add Integration.
- Select Auto-discover integrations.
- When the vessel and connected equipment are in a safe state, select Explore vessel.
- After discovery finishes, open the added UniFi Protect integration.
When BoatKit confidently identifies a Protect console, it adds and enables the integration. The integration remains incomplete and reports that an API key is required. No camera streams are enabled at this stage.
Add the integration manually
If auto-discovery does not find the console:
- Open Settings, then Integrations.
- Select Add Integration.
- Open Cameras & Security.
- Find UniFi Protect and select Add.
- Open the new UniFi Protect integration.
Create a Protect API key
- Sign in to the vessel's UniFi OS console with permission to manage Protect integrations.
- In Protect, open Settings, then Integrations.
- Create a dedicated local Integration API key for BoatKit.
- Copy the key so you can enter it in BoatKit.
Do not send the API key through support, chat, email, or documentation forms. BoatKit stores it as a write-only secret on the vessel host. Viewer pages cannot retrieve it, and portable backups do not include it.
Connect to the console
- In the BoatKit UniFi Protect integration, enter the console hostname or IP address in Protect console address. Enter only the hostname or address, without
https://or a path. - Paste the dedicated key into Protect API key.
- Wait for BoatKit to authenticate and refresh the camera inventory.
Before sending the API key, BoatKit records the exact TLS certificate fingerprint presented by the configured console. BoatKit then requires that same certificate for both the local Protect Integration API and the cameras' RTSPS connections.
If the console certificate later changes, BoatKit stops connecting. Do not select Trust current certificate until you have independently confirmed that the configured address still belongs to the intended Protect console. A legitimate console replacement or certificate change requires an administrator to trust the current certificate before BoatKit reconnects.
After the first successful authentication, BoatKit inventories the cameras and any existing RTSPS streams. It does not change camera stream settings until you explicitly select cameras.
Choose cameras to add
Review the camera inventory, then use either method:
- Add an individual camera with its add/remove control and confirm Add camera.
- Select Add all cameras and confirm Add cameras to add every camera currently shown.
Add all cameras is one consent action for the current inventory. It does not automatically approve cameras discovered later.
For each selected camera, BoatKit:
- Reuses existing low-, medium-, and high-quality RTSPS streams when they are available
- Asks Protect to create only the missing low-, medium-, or high-quality stream
- Records which stream qualities BoatKit created
All available main-camera qualities are exposed to BoatKit's shared camera transport. Remote viewing can move among those profiles as vessel upload conditions change instead of applying a Protect-specific fixed quality.
For direct onboard viewing, BoatKit prefers Protect's medium tier when it exists: it retains substantially more detail for dewarping than the low tier without assuming that every browser can comfortably decode a camera's maximum resolution. Exact dimensions are chosen by the camera and Protect firmware. For example, the tested G6 Pro 360 supplies 640×640 low, 1280×1280 medium, and 3504×3504 high streams.
When you remove a camera, BoatKit deletes only the stream qualities recorded as BoatKit-created. Streams that existed before BoatKit added the camera are preserved.
If BoatKit created streams that need cleanup, remove the integrated cameras before changing to a different Protect console. BoatKit prevents the console address from being changed while its stream-ownership records still require cleanup.
Selected cameras join BoatKit's common camera inventory and can be placed in saved views. BoatKit accepts both H.264 and H.265/HEVC Protect streams and remuxes them without transcoding.
Create saved views from a 360° camera
BoatKit labels supported 360-degree models as fisheye sources and dewarps them in the Viewer. Each camera item stores its own direction, distance from center, and field of view. One physical Cockpit camera can therefore supply several dashboard items—for example, port quarter, stern, and starboard quarter for docking—without creating more Protect streams.
- Add a Camera item while editing a dashboard or responsive view.
- Select the 360° camera.
- Under Saved 360° view, adjust Direction, Distance from center, and Field of view while watching the camera item.
- Save the view.
- Add or duplicate more camera items that select the same camera, then give each item a different saved angle.
While watching a view, drag the dewarped image to look around, use the zoom controls, or switch temporarily to the original fisheye image. Those viewing controls do not replace the angle stored in the item; edit the view item when you want to change its remembered angle.
Confirm it is working
- Confirm that the integration reports Connected and shows the expected Protect console name.
- Confirm that the Protect camera inventory appears and that each camera has the expected connection and RTSPS status.
- Add at least one camera and confirm that it appears with the other BoatKit cameras.
- Place the camera in a saved view.
- Open the saved view and confirm that the camera tile displays video.
A camera can appear in the Protect inventory while disconnected. Check its connection state before treating its presence as confirmation that video is available.
Security and stream ownership
RTSPS encrypts the local camera stream between the Protect console and the BoatKit host. The raw stream URL and its access token remain on the BoatKit host and are not returned through ordinary Viewer camera or integration data.
BoatKit pins the same console certificate for Integration API and RTSPS connections. This prevents BoatKit from silently sending the API key or accepting camera streams from a different endpoint after a certificate change.
The API key is stored separately as a write-only device secret. Replacing the configured console clears the saved API key and certificate trust so the credential cannot be sent to a different console accidentally.
Local, offline, and remote operation
Local discovery, camera inventory, and local viewing do not use BoatKit Cloud. After normal vessel registration, they can continue without an internet connection while all of the following remain true:
- The BoatKit host is powered and running.
- The Protect console and camera are powered.
- The BoatKit host, console, and camera can still reach one another over the vessel LAN.
Remote camera viewing uses BoatKit's separate BoatKit Cloud camera path. It requires an internet connection, permission under the vessel's configured camera-stream access policy, and enough vessel upload and viewer download bandwidth. If remote video fails, confirm local playback first so you can distinguish a camera or LAN problem from an internet, access, or bandwidth problem.
Backups and restore
Portable backups include:
- The nonsecret Protect console identity
- Your camera selections
- Records of which RTSPS stream qualities BoatKit created
Portable backups omit the Protect API key and device-local certificate trust. After restoring a backup, confirm that the configured address identifies the intended console, then enter a new dedicated API key. BoatKit records the console's current certificate before it sends the new key and can then inventory the cameras again.
Troubleshooting
No Protect console is found
- Confirm that the UniFi OS console is powered, running Protect, and reachable from the vessel LAN.
- Confirm that BoatKit and the console are on networks that permit local discovery traffic. Discovery broadcasts may not cross an isolated network segment.
- If the console is reachable but not discovered, add UniFi Protect manually and enter its hostname or IP address.
Protect was found, but setup is not finished
This is the expected state after credential-free discovery. Create a dedicated local key under Protect Settings, Integrations, then enter it in Protect API key. Discovery alone does not inventory cameras or enable streams.
Protect rejects the API key
The key may be invalid or revoked. Create a new dedicated local Integration API key in Protect and enter the replacement in BoatKit. Do not share the rejected or replacement key when requesting assistance.
The console certificate changed
BoatKit stops both Integration API and RTSPS connections when the certificate no longer matches its saved fingerprint. Independently confirm that the configured address still belongs to the intended console. If the change is expected, select Trust current certificate and refresh the camera inventory.
No cameras are returned
- Confirm that the expected cameras are managed by the same Protect console.
- Check their status in Protect.
- In BoatKit, select Refresh cameras.
- Remember that BoatKit does not claim compatibility with every Protect camera or firmware release.
A camera is disconnected
Check the camera's status in Protect first. Restore its power or network connection there, then select Refresh cameras in BoatKit. A disconnected Protect camera may remain listed even though it cannot provide video.
BoatKit cannot create an RTSPS stream
This occurs when a selected camera is missing a low-, medium-, or high-quality RTSPS stream and Protect rejects or cannot complete the request. Confirm that Protect is operational and still accepts the configured Integration API key. Refresh the inventory, then try adding that camera again. If the failure continues, retain the error message but do not share the API key, stream URL, or stream token.
Local video does not play
- Confirm that the camera was explicitly added to BoatKit.
- Confirm that the integration reports Connected and the camera is connected in Protect.
- Confirm that the BoatKit host can still reach the Protect console over the vessel LAN.
- Select Refresh cameras, then reopen the camera tile.
- H.265/HEVC playback also requires support from the Viewer device's browser and hardware video decoder. Try a current BoatKit app or browser on a device that supports HEVC.
Remote video does not play or is unreliable
Confirm that local playback works first. Then check the vessel and viewer internet connections, the configured BoatKit Cloud camera-stream access policy, and available upload and download bandwidth. Remote playback problems with working local video usually point to the cloud path, access settings, or internet capacity rather than Protect discovery.
UniFi and Ubiquiti are trademarks of Ubiquiti Inc. BoatKit and this integration are not affiliated with, certified by, or endorsed by Ubiquiti.