The first request: your account
Every session starts with the server address, player_api.php and your login:
http://example.com:8080/player_api.php?username=YOURNAME&password=YOURPASS
The reply describes your account and the server. Documented examples include auth, status, exp_date (the expiry date as a timestamp), is_trial, active_cons, max_connections and allowed_output_formats. That’s where an app gets your expiry date and connection limit. See account expired and too many connections.
The lists: one action at a time
Each part of the app is a separate request, adding &action= and a name to the same address. The open-source py-xtream-codes library builds these:
| Action | Returns |
|---|---|
get_live_categories | The live TV groups |
get_live_streams | Live channels (add &category_id= for one group) |
get_vod_categories | The film categories |
get_vod_streams | Films (optionally by category) |
get_vod_info | Details of one film (&vod_id=) |
get_series_categories | The series categories |
get_series | Series (optionally by category) |
get_series_info | Seasons and episodes of one series (&series_id=) |
get_short_epg | The next few guide entries for a channel (&stream_id=, optional &limit=) |
get_simple_data_table | All guide entries for a channel |
The full guide for every channel comes from a separate address, xmltv.php, with the same username and password. The library’s notes add that some servers accept offset and items_per_page parameters to page through long lists.
How stream addresses are built
The API returns lists with stream ids, not ready-made links; the app builds each address:
| Content | Address format | Extension comes from |
|---|---|---|
| Live channel | /live/username/password/streamID.ext | allowed_output_formats (for example ts or m3u8) |
| Film | /movie/username/password/streamID.ext | The film’s target_container |
| Episode | /series/username/password/streamID.ext | The episode’s target_container |
That’s why your app can offer a choice of stream format: the server lists which formats your account may use. See HLS vs MPEG-TS.
What this explains in practice
- Sections load separately. Live TV, films and series are different requests, so one can be empty or slow while others work. See films and series not playing.
- The guide can come from two places. Some apps show short guide data per channel; others load the whole
xmltv.phpfile. A guide that works in one app but not another is often this difference. See XMLTV explained. - An M3U link is a snapshot. Many servers can also produce an M3U playlist from the same login, with
get.php; it bundles the live list into one file, without the API’s separate sections. See convert an Xtream Codes login to M3U.
Keep your login private
Every one of these addresses contains your username and password in plain text. Don’t paste them into forums, screenshots or support chats with strangers, and don’t install apps that ask you to share them with a third-party service you don’t trust. Anyone with the link can use your account.
