MQTT endpoints
Configure listeners, protocol versions, WebSockets and limits.

We install, integrate and operate Eclipse Mosquitto as an MQTT broker - including TLS, ACLs, WebSockets, bridges, persistence, monitoring and updates.
Companies worldwide trust WZ-IT
The following are trademarks of their respective owners: Eclipse Mosquitto (Eclipse Foundation, Inc.). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.

Mosquitto implements MQTT 5.0, 3.1.1 and 3.1 and suits lightweight broker instances. Production use still needs clean topic structures, identities, ACLs, certificates, QoS decisions and controlled client limits.
We install and operate Mosquitto, connect devices, gateways and applications and design TLS, WebSockets, bridges, persistence and monitoring. The broker can form part of a complete IoT platform with Node-RED, ThingsBoard, Grafana or custom APIs.
The open-source edition is a lightweight broker, not an automatically highly available cluster platform. Failover, bridge topologies and commercial Mosquitto variants are assessed against RTO, RPO and device behaviour.
WZ-IT does not define device protocols or topic meaning without business input. Telemetry, commands and safety-critical actions are scoped with device and application teams.
Listeners, identities, topics, persistence and client behaviour are documented together so the broker does not become an uncontrolled integration hub.
Configure listeners, protocol versions, WebSockets and limits.
Structure clients and topic rights around least privilege.
Connect devices, gateways, applications and bridges.
Own updates, monitoring, persistence, backup and recovery.
WZ-IT operates the MQTT service; topic model, device firmware and business command logic are agreed with the customer.
| Area | Responsibility | Scope and boundaries |
|---|---|---|
| Mosquitto and infrastructure | WZ-IT | Installation, configuration, hardening, updates and monitoring. |
| TLS, identities and ACLs | WZ-IT | Technical implementation of the approved client and permissions model. |
| Topic and QoS model | Shared | WZ-IT advises; device and application teams confirm semantics and behaviour. |
| Devices and firmware | Customer | Client implementation, local security and rollout remain with the device owner. |
| Application processing | Customer | Validation, business logic and domain response to messages. |
| HA and platform integration | Optional WZ-IT service | Failover, bridges, rule engines and IoT platforms are designed separately. |
Connect devices and applications through established MQTT versions and defined listeners.
Design namespaces, retained messages, sessions and QoS for the data flow.
Implement transport encryption, client certificates and secure credential rotation.
Restrict publish and subscribe rights to topics and client identities.
Connect browsers, sites and brokers through controlled interfaces.
Observe connections, message rates, errors, persistence, resources and certificates.
Assess existing data and configuration, migrate them in a test run and move to managed operations through a controlled cutover.
Secure SSO, roles, administrative paths and external access for the application and existing infrastructure.
Back up all stateful components consistently and document the recovery path for the agreed scope.
Monitor and update the application and its technical dependencies and operate them under the agreed service level.
A clearly defined operating scope instead of an opaque hosting flat fee.
We set up a test instance for you, usually on the next business day. No payment details required. After seven days it is deleted unless you continue.
We combine the right compute size with ongoing operations, backups, monitoring and a service level appropriate for the criticality of Eclipse Mosquitto. High availability and recovery targets are designed separately where needed.
We also design custom hosting architectures, integrations and migrations around Eclipse Mosquitto. Contact us for a technical assessment.
One managed standard Eclipse Mosquitto application is included in the Starter workload. Business and higher levels add a flexible operations allowance for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€79.90 per started TB and month, including daily encrypted offsite backup with 7-day retention.
Enquiry
Briefly describe the current state and objective for Eclipse Mosquitto. We assess infrastructure, integration, and ongoing operations.
Concurrent connections, messages per second, payload, QoS, retained messages, sessions and bridge traffic determine requirements.
| Usage scenario | Technical starting point | Key factors |
|---|---|---|
| Small device estate | S | A few hundred clients and predictable telemetry. |
| Multiple sites or applications | M or separate brokers | Failure domains, bridges and maintenance are considered. |
| High message rate | MQTT load assessment | Connections, messages/s, payload, QoS and persistence are tested. |
| Critical control or HA | Architecture assessment | Client failover, RTO/RPO and edition are reviewed. |
The calculator covers a manageable single Mosquitto broker. High load, many certificates, bridges, high availability and higher response tiers are added after technical discovery.
Brokers can run centrally, close to a site or in an edge/cloud topology according to latency and offline requirements.
Dedicated MQTT instance with secured endpoints and monitoring.
Broker close to APIs, data platforms and applications.
Local messaging near machines, gateways and equipment.
Connect site brokers and a central platform in a controlled way.
Clients receive only required topic rights; the broker routes messages to defined applications and data platforms.
Publishers and subscribers with unique client identities.
Separate endpoints, certificates, WebSockets and connection boundaries.
Restrict publish and subscribe by device, tenant and topic.
MQTT routing, sessions, retained messages, persistence and bridges.
Sensors, machines, PLC gateways and site services.
Rule engines, dashboards, databases and business logic.
Broker health, clients, errors, certificates and capacity.
MQTT is a transport protocol. Validation, plausibility checks and authorisation of safety-critical commands are additionally implemented in the gateway or application.
Answers about MQTT, security, high availability, bridges and IoT integration.
Yes. Eclipse Mosquitto supports MQTT 5.0 as well as MQTT 3.1.1 and 3.1. The approved versions and features depend on your clients.
We can integrate PKI, issuance, distribution and rotation technically. Device identity, provisioning and secure storage on endpoints must be designed end to end.
The open-source edition is not automatically an HA cluster. We assess client reconnect, bridges, standby or alternative broker designs from your failure targets.
Yes. We integrate Mosquitto with ThingsBoard, Node-RED, databases, APIs and custom applications and document topics and ownership.
We review listeners, users, ACLs, certificates, topic use, clients, QoS, persistence, bridges and workload and plan migration with client test groups.
As an alternative to managed hosting in the data centre, WZ-IT provides the hardware, configures Eclipse Mosquitto, and handles hardening, monitoring, updates, backup and technical support. Access can be limited to the internal network or enabled through VPN and existing identities.
from EUR 349 excl. VAT / month · plus one-time provisioning and initial setup

These solutions are often used together with Eclipse Mosquitto
These solutions offer similar functionalities and can be evaluated together
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.