Skip to content

Xtream Codes API Explained: How IPTV Logins Actually Work

Xtream Codes is the login method behind most IPTV players. Understanding what it does makes setup and troubleshooting far simpler.

By UK Prime IPTV Editorial TeamPublished Updated 10 min read
Dark server room corridor with glowing status lights receding into perspective, illustrating the Xtream Codes API used by IPTV players

Direct answer: the Xtream Codes API is a standard way for an IPTV player to talk to a provider's server. You supply a server address, a username and a password, and the player requests the channel list, programme guide and stream links directly from the server rather than downloading one large playlist file.

It is the most common login method in modern IPTV players, and understanding what it does makes both setup and troubleshooting considerably easier.

The two ways an IPTV player can log in

There are two established methods, and knowing which one you have been given determines how you set up your player.

Xtream Codes APIM3U playlist
What you are givenServer address, username, passwordOne long playlist URL
Channel listRequested from the serverDownloaded as a single file
Guide dataRequested separately by the playerA separate XMLTV URL
Large channel listsHandles wellCan be slow to parse
Player supportMost modern playersUniversal
Kodi supportNoYes

The practical difference: with Xtream Codes, the player asks the server for what it needs, when it needs it. With an M3U playlist, the player downloads everything up front, which is simpler but heavier.

What the three login fields actually are

Server address. The provider's hostname, usually including a port number, for example http://server.example.com:8080. Some providers use a DNS name that resolves to whichever server is least loaded.

Username. The account identifier, which may be a name or a numeric string.

Password. The account password, which is often a long random string rather than something memorable.

A common pitfall: the server address and the playlist URL are different things. If your provider sent you something ending in .m3u, that is a playlist link, not an Xtream Codes server address. The server address is the part before any path.

What happens when you log in

  1. The player contacts the server at the address you supplied, sending the username and password.
  2. The server validates the account and returns an authorisation token.
  3. The player requests the channel list, usually in categories, and displays them.
  4. The player requests guide data for the channels you can see.
  5. When you select a channel, the player requests the stream link for that channel and plays it.

The token issued at step two expires, which is why a session occasionally needs re-establishing. Our guide to channels not loading covers that symptom.

How to set it up

  1. Open your player and choose Login with Xtream Codes API rather than M3U URL.
  2. Enter the server address, including the port if one was supplied.
  3. Enter the username exactly as given.
  4. Enter the password exactly as given.
  5. Give the connection a name, such as the provider's name.
  6. Save and wait for the channel list to build.
  7. Open the EPG settings and confirm guide data is loading.

On typing the fields: type them rather than pasting where practical, and watch for a trailing space. A single stray space at the end of the password is one of the most common causes of a failed login. Our login failure guide covers the error messages.

Which players support it

PlayerXtream Codes support
IPTV SmartersYes — see our setup guide
TiviMateYes — see our setup guide
Windows playersMost, see our Windows guide
Kodi PVR IPTV Simple ClientNo — requires an M3U URL, see our Kodi guide
MAG boxesNo — these use portal URLs and MAC addresses, see our MAG guide

If your player does not support Xtream Codes, ask your provider for the M3U playlist URL instead. Most providers supply both. If the playlist will not load, our M3U errors guide works through the causes.

Common login problems

ErrorLikely causeFix
Invalid username or passwordTrailing space, or typoRe-type both fields by hand
Connection failedWrong server address or missing portRe-check against what was supplied
Login works, no channelsAccount not yet active, or list still buildingWait five minutes, then re-check
Channels load, guide emptyGuide data not requested or not suppliedCheck EPG settings
Logged out unexpectedlyToken expiredRe-enter credentials, or refresh the playlist
Works on one device onlyDevice limit reachedCheck how many connections your plan allows

A note on the name

Xtream Codes is the name of the API standard that many providers' servers implement. It describes the way the player and server communicate, not a particular service, brand or channel line-up.

You will also see the term Xtream UI and similar, referring to server software that implements the same interface. From a viewer's point of view, the distinction does not matter — what matters is that your player and your provider's server can speak the same protocol, and almost all of them can.

The bottom line

Xtream Codes is simply a login method: three fields instead of one long link, with the player requesting what it needs from the server. If your player supports it, use it — it loads faster and copes better with large channel lists. If it does not, ask for the M3U URL instead.

For the wider picture, see our pillar guide to IPTV in the UK and the guide to the best IPTV apps.

Frequently asked questions

Related guides

London at night with light trails along the Thames

Ready when you are.

Pick a package, tell us your device, and we'll help you get set up for the evening.