Quick Summary: What Is the Xtream Codes Format?
In modern IPTV, Xtream Codes refers to a structured client-server login format that uses a Server URL, Username, and Password to connect your player app to an IPTV service.
Instead of reading a single static text playlist, an Xtream-compatible player issues lightweight HTTP/HTTPS requests to retrieve structured JSON data—allowing it to fetch categories, channel lists, on-demand movies, and TV guide (EPG) schedules dynamically. It is not a formal standards body specification, but rather a de facto compatibility convention adopted across third-party IPTV software.
The main alternative is an M3U playlist: M3U gives the player a list of stream URLs, while Xtream Codes gives it separate login fields and an API-style way to request organized data. The M3U vs Xtream Codes guide compares the two methods without replacing this definition.
Origins and Evolution of the Format
To understand why Xtream Codes exists, it helps to look at its history. In the mid-2010s, a software company named Xtream Codes Ltd created a popular commercial streaming management panel. The panel featured an internal Application Programming Interface (API) that enabled mobile and TV apps to authenticate users, check subscription validity, and fetch channel lineups.
Although the original company ceased operations in September 2019 following European legal enforcement actions, the client-server API architecture it popularized had already become the unspoken standard for third-party media players. Today, alternative IPTV middleware platforms and open-source panels emulate the identical API endpoints so that popular applications (including TiviMate, IPTV Smarters, Televizo, and XCIPTV) continue to work seamlessly.
Important Distinction: Xtream Codes is not an official Internet standard ratified by the IETF, W3C, ISO, or ITU. It is a de facto protocol convention that gained widespread adoption because its structured API allows compatible apps to query categories and account data on demand rather than relying only on a static playlist file.
What Information Does the User Enter?
When you configure an IPTV player using an Xtream Codes login option, the application typically presents a login dialog requesting three primary credentials:
Server URL
The base web address of the streaming server (e.g., http://tv.example.com:8080). It points your player to the provider's API endpoint.
Username
Your unique account identifier assigned by your IPTV service provider to track your subscription profile.
Password
The secret authentication token or passphrase associated with your account username.
Port Handling Varies by App: Some older tutorials claim that four separate fields are universally mandatory: Server, Port, Username, and Password. In reality, field layout depends on the specific app interface. Modern players frequently expect the port to be included directly inside the Server URL (e.g., http://example.com:8080). When a service operates over standard HTTP (port 80) or standard HTTPS (port 443), no port number is required at all.
How Common Xtream-Compatible APIs Function
While implementations vary across different server panels, common Xtream-compatible systems expose a core API endpoint—traditionally named /player_api.php.
When a player launches or synchronizes content, it initiates an HTTP or HTTPS request to this endpoint, supplying the user's credentials as URL query parameters.
Illustrative Request Example
In a standard initial handshake, the player sends an authentication request structured similarly to this conceptual example:
GET /player_api.php?username=EXAMPLE_USER&password=EXAMPLE_PASS HTTP/1.1
Host: example.comNote: The URL above is a sanitized illustrative example. Never share your active provider credentials publicly.
Structured JSON Response
If authentication succeeds, the server returns a structured JSON payload rather than a raw video stream. Common responses include:
- User Information (
user_info): Account status (active/expired), subscription expiration timestamp, created date, and maximum concurrent connections allowed. - Server Information (
server_info): Server timezone, active protocol, supported container formats (such as MPEG-TS or HLS), and server port.
On-Demand Content Queries
Once authenticated, the player can request specific subsets of content using dedicated query actions:
action=get_live_categories: Retrieves live TV genre groupings (e.g., Sports, News).action=get_live_streams&category_id=...: Retrieves channels within a selected category.action=get_vod_categories: Retrieves video-on-demand movie categories.action=get_series: Retrieves organized TV series with seasons and episode metadata.action=get_short_epg&stream_id=...: Fetches program guide data for specific channels.
How Xtream Codes Organizes Content
The primary practical benefit of an API-based system like Xtream Codes is structured content organization. Because the server groups content into discrete categories, player applications can display clean, interactive menus:
- Hierarchical Navigation: Live channels, movies, and TV series are separated into dedicated application sections rather than lumped into an unorganized list.
- Metadata Integration: Movie and series entries can include poster artwork, plot summaries, cast lists, release years, and episodic structures directly from the API.
- Dynamic EPG Association: Program guide information is linked directly to internal stream IDs, minimizing the need for users to manually configure third-party XMLTV guide URLs.
Security and Privacy Considerations
Understanding how Xtream Codes handles security is essential for keeping your account protected:
1. Query String Credentials (RFC 9110 Considerations)
The legacy Xtream Codes design transmits the username and password directly within the URL query string. In standard web security architectures (such as those outlined in RFC 9110 Section 4.3), sending sensitive secrets in URLs is discouraged because query strings can be recorded in server access logs, browser histories, and proxy caches.
To minimize exposure, always ensure your provider supports connection via encrypted HTTPS rather than plain HTTP, and never share full API query URLs in public forums or support threads.
2. Concurrent Connection Limits
Because the API server tracks active sessions, IPTV providers typically enforce strict concurrent connection caps (for example, two or three active devices simultaneously). If you attempt to stream on more devices than your subscription allows, the server will either drop the oldest stream or return an authentication refusal on the new device.
Player Compatibility: Players That Support Xtream Codes
Almost all major dedicated IPTV applications feature native support for Xtream-style API logins:
- TiviMate: Supports adding multiple Xtream Codes accounts with full category selection and automated guide sync.
- IPTV Smarters Pro: Built around the Xtream interface, offering dedicated Live, VOD, and Series dashboards.
- Televizo: Lightweight and responsive player for Android that supports both Xtream API logins and M3U playlists.
- XCIPTV: A feature-rich player designed for Android TV and Firestick with customizable home screens based on Xtream API categories.
General Media Players: General-purpose media players like VLC or Kodi can play individual stream URLs generated by an Xtream server, but they do not natively parse the multi-category API menus without specialized third-party add-ons.
What Xtream Codes Does Not Do
A common misconception among new IPTV users is that Xtream Codes is a provider or service. It is important to distinguish the connection protocol from content:
Having an Xtream-compatible player does not provide any video content on its own. You must have an active subscription with an IPTV service provider to supply valid server, username, and password details.
Summary: What Xtream Codes Is and Is Not
| Xtream Codes Is: | Xtream Codes Is NOT: |
|---|---|
| A widely supported client-server API format | An official IETF, W3C, or ISO standard |
| A login method using Server, Username, and Password | A standalone IPTV player application |
| A way to query categorized JSON channel and EPG data | An IPTV subscription or media content provider |
| Protected in transit only when configured with HTTPS | Inherently encrypted or self-securing by default |
Connecting Your IPTV Service
Whether you prefer the structured navigation of an Xtream-compatible login or the simplicity of an M3U playlist, TryIPTV supports both connection methods. You can choose whichever format best matches your preferred player application, operating system, and streaming hardware.