# RTMP authentication from URL ?

**URL:** <https://community.wowza.com/t/rtmp-authentication-from-url/34481>\
**Category:** Wowza Streaming Engine\
**Created:** [October 8, 2012, 10:46am UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481 "2012-10-08T10:46:39Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roman\_Pekarek](https://avatars.discourse-cdn.com/v4/letter/r/ac8455/32.png) [@Roman\_Pekarek](https://community.wowza.com/u/Roman_Pekarek)\
**Post date:** [October 8, 2012, 10:46am UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/1 "2012-10-08T10:46:39Z")

</div>

Is exist any module , whitch can enable RTMP publish authentication from URL ? like

```auto
rtmp://user:pass@wowza_adress:1935/application ?

```

or the same for rtsp authentication ?

```auto
rtsp://user:pass@wowza_adress/application

```

---

<div class="post-metadata">

**Author:** ![Randall\_Auriemma](https://avatars.discourse-cdn.com/v4/letter/r/85e7bf/32.png) [@Randall\_Auriemma](https://community.wowza.com/u/Randall_Auriemma)\
**Post date:** [October 8, 2012, 12:40am UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/2 "2012-10-08T00:40:41Z")

</div>

You can use URL params as shown in this [example](https://www.wowza.com/docs/how-to-secure-publishing-from-an-rtmp-encoder-that-does-not-support-authentication-modulesecureurlparams%28moduleSecureURLParams%29).

You’d put the credentials on the end of the URL.

---

<div class="post-metadata">

**Author:** ![Richard\_Lanham](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@Richard\_Lanham](https://community.wowza.com/u/Richard_Lanham)\
**Post date:** [October 12, 2012, 11:46am UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/3 "2012-10-12T11:46:53Z")

</div>

Add the querystring to the connection part, like this:

rtmp://wowza/application?user&pass/streamname

Richard

---

<div class="post-metadata">

**Author:** ![Richard\_Lanham](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@Richard\_Lanham](https://community.wowza.com/u/Richard_Lanham)\
**Post date:** [October 22, 2012, 11:48pm UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/4 "2012-10-22T23:48:39Z")

</div>

What are you trying to do, secure RTMP publishing? If so, take a look at the the MediasSecurity Addon’s ModuleRTMPAuthenticate

[https://www.wowza.com/docs/media-security-overview](https://www.wowza.com/docs/media-security-overview)

Otherwise, explain in detail what you are doing and what you are trying to prevent, exactly.

Richard

---

<div class="post-metadata">

**Author:** ![Richard\_Lanham](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@Richard\_Lanham](https://community.wowza.com/u/Richard_Lanham)\
**Post date:** [October 26, 2012, 10:33am UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/5 "2012-10-26T10:33:33Z")

</div>

Use this:

[https://www.wowza.com/docs/how-to-secure-publishing-from-an-rtmp-encoder-that-does-not-support-authentication-modulesecureurlparams](https://www.wowza.com/docs/how-to-secure-publishing-from-an-rtmp-encoder-that-does-not-support-authentication-modulesecureurlparams)

Richard

---

<div class="post-metadata">

**Author:** ![Richard\_Lanham](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@Richard\_Lanham](https://community.wowza.com/u/Richard_Lanham)\
**Post date:** [January 30, 2013, 6:26pm UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/6 "2013-01-30T18:26:51Z")

</div>

This only works with Flash RTMP client

Richard

---

<div class="post-metadata">

**Author:** ![Richard\_Lanham](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@Richard\_Lanham](https://community.wowza.com/u/Richard_Lanham)\
**Post date:** [February 3, 2013, 12:17am UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/7 "2013-02-03T00:17:16Z")

</div>

If you are using RTSP playback you can use onRTSPStreamCreate

[https://www.wowza.com/docs/how-to-control-access-to-rtsp-rtp-streams](https://www.wowza.com/docs/how-to-control-access-to-rtsp-rtp-streams)

Richard

---

<div class="post-metadata">

**Author:** ![Roman\_Pekarek](https://avatars.discourse-cdn.com/v4/letter/r/ac8455/32.png) [@Roman\_Pekarek](https://community.wowza.com/u/Roman_Pekarek)\
**Post date:** [October 8, 2012, 5:23pm UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/8 "2012-10-08T17:23:49Z")

</div>

randall : thanx … i will test ist tomorow …

---

<div class="post-metadata">

**Author:** ![Roman\_Pekarek](https://avatars.discourse-cdn.com/v4/letter/r/ac8455/32.png) [@Roman\_Pekarek](https://community.wowza.com/u/Roman_Pekarek)\
**Post date:** [October 11, 2012, 3:57pm UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/9 "2012-10-11T15:57:42Z")

</div>

Randall : Yes … it works OK … on FMLE … Where server/application and stream\_name are 2 fields … How to use it on FFMPEG , where is only one line ?

this not works :

```auto
rtmp://wowza_adress:1935/application/streamname/_definst_/doPublish=12345

```

---

<div class="post-metadata">

**Author:** ![Roman\_Pekarek](https://avatars.discourse-cdn.com/v4/letter/r/ac8455/32.png) [@Roman\_Pekarek](https://community.wowza.com/u/Roman_Pekarek)\
**Post date:** [October 11, 2012, 5:37pm UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/10 "2012-10-11T17:37:47Z")

</div>

I see same problem … I setup ModuleOnConnectAuthenticate2 by guide … It works in FMLE in two fields (rtmp://wowza/application?user&pass , and second field is streamname) … But not works in single field rtmp://wowza/application/streamname?user&pass

---

<div class="post-metadata">

**Author:** ![Roman\_Pekarek](https://avatars.discourse-cdn.com/v4/letter/r/ac8455/32.png) [@Roman\_Pekarek](https://community.wowza.com/u/Roman_Pekarek)\
**Post date:** [October 12, 2012, 8:21am UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/11 "2012-10-12T08:21:07Z")

</div>

both not works …

---

<div class="post-metadata">

**Author:** ![Roman\_Pekarek](https://avatars.discourse-cdn.com/v4/letter/r/ac8455/32.png) [@Roman\_Pekarek](https://community.wowza.com/u/Roman_Pekarek)\
**Post date:** [October 12, 2012, 8:23am UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/12 "2012-10-12T08:23:57Z")

</div>

ffmpeg say : [rtmp @ 0x3408a20] Server error: Connection failed: Application rejected connection.

rtmp://wowza\_IP/live/_definst_/streamtest?user&pass: Operation not permitted

on WOWZA console I see :

INFO server comment - ModuleStreamRecord.onAppStart

INFO server comment - ModuleOnConnectAuthenticate: Authorization password file: /usr/local/WowzaMediaServer/conf/connect.password

INFO application app-start _definst_ live/_definst_

INFO session connect-pending **IP** -

INFO server comment - size: 3

ERROR server comment - ModuleOnConnectAuthenticate.onConnect: java.lang.ArrayIndexOutOfBoundsException: 1

INFO session connect _ **IP** _ -

INFO session disconnect 987715802 -

INFO application app-stop _definst_ live/_definst_

INFO server comment - ModuleStreamRecord.onAppStop

---

<div class="post-metadata">

**Author:** ![Roman\_Pekarek](https://avatars.discourse-cdn.com/v4/letter/r/ac8455/32.png) [@Roman\_Pekarek](https://community.wowza.com/u/Roman_Pekarek)\
**Post date:** [October 12, 2012, 12:59pm UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/13 "2012-10-12T12:59:33Z")

</div>

YES ! great … THIS ONE WORKS 🙂

thanx a lot …

---

<div class="post-metadata">

**Author:** ![Roman\_Pekarek](https://avatars.discourse-cdn.com/v4/letter/r/ac8455/32.png) [@Roman\_Pekarek](https://community.wowza.com/u/Roman_Pekarek)\
**Post date:** [October 22, 2012, 5:39pm UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/14 "2012-10-22T17:39:47Z")

</div>

> Note that the onConnect method runs for both Flash publishers and Clients. There are other examples in the Security section of the Tutorials to overide onPlay (for clients only) or onPublish (for publishers only).

Does ModuleOnConnectAuthenticate2 support onPlay and onPublish methods ? or just onConnect ? I cant see it in Tutorials … I need only onPublish … onPlay will be without authentication …

---

<div class="post-metadata">

**Author:** ![Roman\_Pekarek](https://avatars.discourse-cdn.com/v4/letter/r/ac8455/32.png) [@Roman\_Pekarek](https://community.wowza.com/u/Roman_Pekarek)\
**Post date:** [October 26, 2012, 10:09am UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/15 "2012-10-26T10:09:05Z")

</div>

its explained in first post here … [RTMP authentication from URL ?](http://community.wowza.com/t/-/34481)

i need publish authentication from URL … for ffmpeg …

---

<div class="post-metadata">

**Author:** ![Roman\_Pekarek](https://avatars.discourse-cdn.com/v4/letter/r/ac8455/32.png) [@Roman\_Pekarek](https://community.wowza.com/u/Roman_Pekarek)\
**Post date:** [January 21, 2013, 10:51pm UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/16 "2013-01-21T22:51:20Z")

</div>

briand123 : it works … use -f flv “rtmp://wowzaIP:1935/application?doPublish=YOUR\_DEFINED\_KEY/streamname”

im using it for transcoding streams … ffmpeg is really great …

---

<div class="post-metadata">

**Author:** ![Randall\_Auriemma](https://avatars.discourse-cdn.com/v4/letter/r/85e7bf/32.png) [@Randall\_Auriemma](https://community.wowza.com/u/Randall_Auriemma)\
**Post date:** [October 11, 2012, 6:02am UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/17 "2012-10-11T06:02:18Z")

</div>

Pytkin,

Sorry I mixed up “QueryString” and “URLParms”. I meant to give you a different module the first time. Here is a module that parses the URL for the QueryString, so that you can use encoders that don’t support RTMP authentication: [ModuleOnConnectAuthenticate2](https://www.wowza.com/docs/how-to-do-file-based-rtmp-authentication-with-url-query-strings-onconnectauthenticate2).

Note that the onConnect method runs for both Flash publishers and Clients. There are other examples in the Security section of the Tutorials to overide onPlay (for clients only) or onPublish (for publishers only).

---

<div class="post-metadata">

**Author:** ![Randall\_Auriemma](https://avatars.discourse-cdn.com/v4/letter/r/85e7bf/32.png) [@Randall\_Auriemma](https://community.wowza.com/u/Randall_Auriemma)\
**Post date:** [October 11, 2012, 11:06am UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/18 "2012-10-11T11:06:28Z")

</div>

try:

```auto
rtmp://wowza_adress:1935/application/_definst_/streamname/doPublish=12345
rtmp://wowza/application/_definst_/streamname?user&pass

```

---

<div class="post-metadata">

**Author:** ![Brian\_Dombrowski](https://avatars.discourse-cdn.com/v4/letter/b/b5ac83/32.png) [@Brian\_Dombrowski](https://community.wowza.com/u/Brian_Dombrowski)\
**Post date:** [December 17, 2012, 11:40pm UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/19 "2012-12-17T23:40:05Z")

</div>

secureURLParams doesn’t work with ffmpeg. I’ve tried everything I can think of to refactor the rtmp URL form to get Wowza to pick up the stream name and the ‘doPublish’ and nothing works.

---

<div class="post-metadata">

**Author:** ![kakaza\_Frilini](https://avatars.discourse-cdn.com/v4/letter/k/f4b2a3/32.png) [@kakaza\_Frilini](https://community.wowza.com/u/kakaza_Frilini)\
**Post date:** [January 31, 2013, 1:13am UTC](https://community.wowza.com/t/rtmp-authentication-from-url/34481/20 "2013-01-31T01:13:16Z")

</div>

> Add the querystring to the connection part, like this:
> 
> rtmp://wowza/application?user&pass/streamname
> 
> Richard

This is work with module “moduleOnConnectAuthenticate2”.

If I use module moduleOnConnectAuthenticate

moduleOnConnectAuthenticate

ModuleOnConnectAuthenticate

com.wowza.wms.plugin.collection.module.ModuleOnConnectAuthenticate

How put link same rtmp://wowza/application?user,pass/streamname ?

Becuase some STB unknown “&”

Best Regards

[Next page](https://community.wowza.com/t/rtmp-authentication-from-url/34481.md?page=2)
