# Protecting a stream with AllowDomains

**URL:** <https://community.wowza.com/t/protecting-a-stream-with-allowdomains/41992>\
**Category:** Wowza Streaming Engine\
**Created:** [February 25, 2014, 11:29am UTC](https://community.wowza.com/t/protecting-a-stream-with-allowdomains/41992 "2014-02-25T11:29:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_Pals](https://avatars.discourse-cdn.com/v4/letter/j/c0e974/32.png) [@John\_Pals](https://community.wowza.com/u/John_Pals)\
**Post date:** [February 25, 2014, 11:29am UTC](https://community.wowza.com/t/protecting-a-stream-with-allowdomains/41992/1 "2014-02-25T11:29:51Z")

</div>

Hi,

I tried to protect a stream with in Application.xml. This works for RTMP streams, but it won’t work the HLS / HTML5 streams. How can I protect a HLS stream?

Regards, John

---

<div class="post-metadata">

**Author:** ![Jason\_Hilton](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/jason_hilton/32/437_2.png) [@Jason\_Hilton](https://community.wowza.com/u/Jason_Hilton)\
**Post date:** [February 25, 2014, 1:51pm UTC](https://community.wowza.com/t/protecting-a-stream-with-allowdomains/41992/2 "2014-02-25T13:51:39Z")

</div>

Hi,

Please see our [Media security overview](https://www.wowza.com/docs/media-security-overview) for your security options.

Jason

---

<div class="post-metadata">

**Author:** ![Thomas\_Gires](https://avatars.discourse-cdn.com/v4/letter/t/e480ec/32.png) [@Thomas\_Gires](https://community.wowza.com/u/Thomas_Gires)\
**Post date:** [February 26, 2014, 9:51am UTC](https://community.wowza.com/t/protecting-a-stream-with-allowdomains/41992/3 "2014-02-26T09:51:19Z")

</div>

The only proper free, “built-in” way to protect HLS streams from Wowza is AES encryption:

[https://www.wowza.com/docs/how-to-secure-apple-http-live-streaming-aes-128-external-method](https://www.wowza.com/docs/how-to-secure-apple-http-live-streaming-aes-128-external-method)

This does require you to set up a key server and add your own logic to verify the request

Simplest way, when on your website someone opens the video player page, generate a random token and save it to a database table, along with the IP address of the user. Pass this token in the stream URL [[http://myserver.com/live/stream/playlist.m3u8?token=xxxxxx]](http://myserver.com/live/stream/playlist.m3u8?token=xxxxxx%5D) . Then, have your authentication script compare the token to the database, if the IP of the auth request matches, allow playback, otherwise reject it.

You can make things fancier from there, the script sample on the page linked above are good starting point. But do keep in mind this system may not be compatible with some players (Android 4.0’s video system for instance, you’ll need 4.1 and above)

Otherwise, there are third-party solutions which make this a bit easier, such as [wmspanel.com](http://wmspanel.com) which I highly recommend.

Hope this helps!

---

<div class="post-metadata">

**Author:** ![John\_Pals](https://avatars.discourse-cdn.com/v4/letter/j/c0e974/32.png) [@John\_Pals](https://community.wowza.com/u/John_Pals)\
**Post date:** [February 26, 2014, 7:50am UTC](https://community.wowza.com/t/protecting-a-stream-with-allowdomains/41992/4 "2014-02-26T07:50:31Z")

</div>

Thanks a lot! It does help a lot!
