Skip to content

How it works

Xtream Codes, explained without the marketing

If your provider gave you a host, a username and a password instead of a single link, you are dealing with Xtream Codes. Here is what those three fields do once you press connect.

Last checked: September 2026

Where the name actually comes from

Xtream Codes was a PHP panel that IPTV resellers ran on their own servers to manage subscribers, channel lists and billing. The company behind it was shut down in 2019, but the API it defined never went anywhere β€” dozens of panel systems still speak the exact same protocol today because every existing app and every existing customer already understood it. "Xtream Codes" now means the format, not the company.

That matters for one practical reason: the panel your provider runs might be called something completely different. If it answers on player_api.php with the same three fields, it counts.

The three fields, and what each one is doing

Host, username, password look like a login form, and functionally that is exactly what they are. The app sends all three to a single endpoint and gets back one JSON reply describing the account: whether it is active, when it expires, how many connections it allows, and which categories of live channels, films and series it can see.

That single request is also the whole reason activation feels instant. There is no separate "checking your subscription" step β€” the same call that logs you in also answers the question.

Why the port is the part that actually breaks

Almost every support ticket that looks like a "wrong password" turns out to be a port problem. Xtream panels commonly answer on 80, 8080, or a specific number the provider assigns per account β€” 25461 shows up a lot for historical reasons nobody remembers anymore. Type the host without it and the connection times out silently instead of failing with a clear message, because there is nothing on the default port to say no.

A quick way to tell the two failures apart: "connection refused" or a spinner that never resolves is a port or address problem β€” nothing is listening where you are asking. An immediate, fast rejection with an actual error is a credentials problem β€” something is listening, and it read the request.

http versus https is the second most common one. Panels running plain http will not load at all from a device that quietly upgrades every request to https, which some Android network configurations do without telling you.

Live, movies and series are three different questions

A live channel, a film and an episode are not the same kind of object to the panel, even though they all end up as one row on a home screen. Live channels come back as a flat list with a stream ID and a category. Films look almost the same. A series is a different shape entirely: the initial reply only lists the show itself, and the app has to make a second request per series to learn what seasons and episodes exist.

That second request is why a series-heavy account can feel slower to browse than a movie-heavy one of the same size β€” it genuinely is doing more round trips, not just rendering more artwork.

What a player can fix, and what it cannot

A good client can retry a stream on a second decoder if the first one refuses the format, cache the guide so it does not refetch on every channel change, and tell you plainly when an account has actually expired instead of just going blank. All of that is real and worth having.

None of it does anything if the panel itself is down, oversold, or the account lapsed. "The app is broken" and "the account is broken" produce the same black screen, and the only way to tell them apart is to check the account status the panel itself reports β€” which is the one thing every Xtream-compatible app can always show you, because it is sitting right there in that first login reply.

Already have the three fields?

BOSS IPTV connects to any Xtream-compatible panel on Android TV, Fire TV and Android β€” nothing bundled, nothing to browse before you add your own.

Try it on your device