Skip to content
IPTV Subscription 8K - 8K TV Subscription

Xtream Codes

The Xtream Codes API: what your player asks the server

When you add an Xtream Codes login to an app, the app doesn’t download one big playlist. It talks to the server’s API: first to check your account, then to fetch categories, channels, films, series and guide data, each on request. Knowing what those requests are helps you understand what your app shows, why some parts load and others don’t, and why your login details must stay private.

Updated · 2 min read

Also available in Dansk · Norsk · Svenska

The first request: your account

Every session starts with the server address, player_api.php and your login:

http://example.com:8080/player_api.php?username=YOURNAME&password=YOURPASS

The reply describes your account and the server. Documented examples include auth, status, exp_date (the expiry date as a timestamp), is_trial, active_cons, max_connections and allowed_output_formats. That’s where an app gets your expiry date and connection limit. See account expired and too many connections.

The lists: one action at a time

Each part of the app is a separate request, adding &action= and a name to the same address. The open-source py-xtream-codes library builds these:

ActionReturns
get_live_categoriesThe live TV groups
get_live_streamsLive channels (add &category_id= for one group)
get_vod_categoriesThe film categories
get_vod_streamsFilms (optionally by category)
get_vod_infoDetails of one film (&vod_id=)
get_series_categoriesThe series categories
get_seriesSeries (optionally by category)
get_series_infoSeasons and episodes of one series (&series_id=)
get_short_epgThe next few guide entries for a channel (&stream_id=, optional &limit=)
get_simple_data_tableAll guide entries for a channel

The full guide for every channel comes from a separate address, xmltv.php, with the same username and password. The library’s notes add that some servers accept offset and items_per_page parameters to page through long lists.

How stream addresses are built

The API returns lists with stream ids, not ready-made links; the app builds each address:

ContentAddress formatExtension comes from
Live channel/live/username/password/streamID.extallowed_output_formats (for example ts or m3u8)
Film/movie/username/password/streamID.extThe film’s target_container
Episode/series/username/password/streamID.extThe episode’s target_container

That’s why your app can offer a choice of stream format: the server lists which formats your account may use. See HLS vs MPEG-TS.

What this explains in practice

  • Sections load separately. Live TV, films and series are different requests, so one can be empty or slow while others work. See films and series not playing.
  • The guide can come from two places. Some apps show short guide data per channel; others load the whole xmltv.php file. A guide that works in one app but not another is often this difference. See XMLTV explained.
  • An M3U link is a snapshot. Many servers can also produce an M3U playlist from the same login, with get.php; it bundles the live list into one file, without the API’s separate sections. See convert an Xtream Codes login to M3U.

Keep your login private

Every one of these addresses contains your username and password in plain text. Don’t paste them into forums, screenshots or support chats with strangers, and don’t install apps that ask you to share them with a third-party service you don’t trust. Anyone with the link can use your account.

FAQ

Xtream Codes API questions

What is player_api.php?

The address on Xtream Codes-style servers that apps call with your username and password. Called alone it returns your account and server details; with an action such as get_live_streams, it returns that list.

Why do my channels load but films don’t?

Live channels, films and series are separate requests to the API, and separate sections on the server. One can fail or be empty while the others work. Refresh the playlist; if one section stays empty, ask your provider.

Is it safe to share an API or playlist link?

No. These addresses contain your username and password in plain text. Anyone with the link can use your account and your connections.

Sources

Facts on this page were checked against these sources. Details were correct when checked; apps and devices change, so we review this page regularly.

  1. py-xtream-codes: xtream.py (API URL builders and stream formats), GitHub (2026-10-02)
  2. py-xtream-codes: authentication response example, GitHub (2026-10-02)

Start watching on your own screen

Plans from £5.83 a month on the 12-month plan, no contract and no auto-renewal. Test it first with a 24-hour free trial.