# Common method for client authentication with live MPEG-DASH

**URL:** <https://community.wowza.com/t/common-method-for-client-authentication-with-live-mpeg-dash/41730>\
**Category:** Wowza Streaming Engine\
**Created:** [March 29, 2016, 3:28pm UTC](https://community.wowza.com/t/common-method-for-client-authentication-with-live-mpeg-dash/41730 "2016-03-29T15:28:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![David\_Shimamoto](https://avatars.discourse-cdn.com/v4/letter/d/b77776/32.png) [@David\_Shimamoto](https://community.wowza.com/u/David_Shimamoto)\
**Post date:** [March 29, 2016, 3:28pm UTC](https://community.wowza.com/t/common-method-for-client-authentication-with-live-mpeg-dash/41730/1 "2016-03-29T15:28:48Z")

</div>

Hi,

Please advise if there is a common way to do client authentication when live streaming MPEG-DASH.

* * *

With RTMP, this was rather straight forward; Override Modulebase.play as described here,

[https://www.wowza.com/docs/how-to-override-play-to-control-access](https://www.wowza.com/docs/how-to-override-play-to-control-access)

…and check that the requested URL contains a valid token string.

Eventually, I am aiming to replace an existing system with H.264+RTMP to use HEVC+MPEG-DASH instead, stream to a remote Android box with Kodi.

The stream not need to be encrypted, but client authentication on connecting is mandatory.

Please also advise if there is a transport besides MPEG-DASH thought to be suitable for such application.

Thank you.

---

<div class="post-metadata">

**Author:** ![Paul\_Shields](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/paul_shields/32/390_2.png) [@Paul\_Shields](https://community.wowza.com/u/Paul_Shields)\
**Post date:** [April 7, 2016, 6:50pm UTC](https://community.wowza.com/t/common-method-for-client-authentication-with-live-mpeg-dash/41730/2 "2016-04-07T18:50:31Z")

</div>

Hi David,

With regards to token-based security, have you considered Wowza’s built-in [Secure Token](https://www.wowza.com/docs/how-to-configure-security-using-wowza-streaming-engine-manager#secure_token)? This can work well with MPEG-DASH streams and a suitable player.

Paul

---

<div class="post-metadata">

**Author:** ![David\_Shimamoto](https://avatars.discourse-cdn.com/v4/letter/d/b77776/32.png) [@David\_Shimamoto](https://community.wowza.com/u/David_Shimamoto)\
**Post date:** [April 12, 2016, 9:25am UTC](https://community.wowza.com/t/common-method-for-client-authentication-with-live-mpeg-dash/41730/3 "2016-04-12T09:25:21Z")

</div>

Thank you Paul,

Unfortunately, for my application all clients cannot share the same token. (Please correct me if that is indeed possible with “Secure Token”)

There are 10s of clients connecting from random remote locations, each with a unique token which also allows the server to log activity.

A mechanism to disable individual clients by updating their token stored on server side without affecting others is necessary.

---

<div class="post-metadata">

**Author:** ![Paul\_Shields](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/paul_shields/32/390_2.png) [@Paul\_Shields](https://community.wowza.com/u/Paul_Shields)\
**Post date:** [April 25, 2016, 8:56am UTC](https://community.wowza.com/t/common-method-for-client-authentication-with-live-mpeg-dash/41730/4 "2016-04-25T08:56:09Z")

</div>

Hi,

Secure token does let you define custom parameters as part of the hash which may help you with regards to unique hashes per client? See the [section on query parameters](https://www.wowza.com/docs/how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine#parameters).

Paul
